Who's Online
There are currently, 75 guest(s) and 13 member(s) that are online.
You are Anonymous user. You can register for free by clicking here
Training Classes Calendar
|  |
The Top 20 Critical Security Controls Posted on Monday, 14 December 2009 @ 07:12:18 EST Contributed by cdupuis
| Topic: SANS
20 Critical Security Controls
Twenty Critical Security Controls for Effective Cyber Defense: Consensus Audit Guidelines
The Twenty Critical Security Controls have already begun to transform security in government agencies and other large enterprises by focusing their spending on the key controls that block known attacks and find the ones that get through. These controls allow those responsible for compliance and those responsible for security to agree, for the first time, on what needs to be done to make systems safer. No development in security is having a more profound and far reaching impact.
These Top 20 Controls were agreed upon by a powerful consortium brought together by John Gilligan (previously CIO of the US Department of Energy and the US Air Force) under the auspices of the Center for Strategic and International Studies. Members of the Consortium include NSA, US Cert, DoD JTF-GNO, the Department of Energy Nuclear Laboratories, Department of State, DoD Cyber Crime Center plus the top commercial forensics experts and pen testers that serve the banking and critical infrastructure communities.
The automation of these Top 20 Controls will radically lower the cost of security while improving its effectiveness. The US State Department, under CISO John Streufert, has already demonstrated more than 80% reduction in "measured" security risk through the rigorous automation and measurement of the Top 20 Controls.
Click here to view the user vetted tools... What the 20 Critical Security Controls Critics say... 20 Critical Security Controls - Version 2.3
Additional Security Controls
The following sections identify additional controls that are important but cannot be fully automatically or continuously monitored to the same degree as the controls covered earlier in this document.
PDF Version
|  |
Login
Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.
|
|
No Comments Allowed for Anonymous, please register |
|
five fingers shoes (Score: 1) by shopping on Tuesday, 22 June 2010 @ 21:22:13 EDT (User Info | Send a Message) | 003】https://www.cccure.org/modules.php?name=News&file=article&sid=1449&mode=thread&order=0&thold=0[网址]https://www.cccure.org/modules.php?name=News&file=article&sid=1449&mode=thread&order=0&thold=0 【004】cissp CISSP training Certified Information Systems Security Professional - MONTREAL - CANADA : Concordia University[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=54&mode=thread&order=0&thold=0 【005】cissp CISSP training Certified Information Systems Security Professional - Information Security Handbook: A Guide for Managers (NIST SP800-100)[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1045&mode=thread&order=0&thold=0 【006】cissp CISSP training Certified Information Systems Security Professional - CPE = CONTINUOUS PAYMENT EXPECTED[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1444&mode=thread&order=0&thold=0 【007】cissp CISSP training Certified Information Systems Security Professional - Cisco VPN Tutorial in Spanish[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=979&mode=thread&order=0&thold=0 【008】cissp CISSP training Certified Information Systems Security Professional - ISSEP Project Leader[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=927&mode=thread&order=0&thold=0 【009】cissp CISSP training Certified Information Systems Security Professional - CISSP study group forum in Plano, TX[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1096&mode=thread&order=0&thold=0 【010】cissp CISSP training Certified Information Systems Security Professional - Study Group HOWTO[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=525&mode=thread&order=0&thold=0 【011】cissp CISSP training Certified Information Systems Security Professional - New auditing Checklist has been released[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1115&mode=thread&order=0&thold=0 【012】cissp CISSP training Certified Information Systems Security Professional - NATO CISSP Study Group in Brussels[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1460&mode=thread&order=0&thold=0 【013】cissp CISSP training Certified Information Systems Security Professional - New logo for the CCCure Family of Portals[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1447&mode=thread&order=0&thold=0 【014】cissp CISSP training Certified Information Systems Security Professional - ISC2 first exam to be delivered by VUE testing[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1472&mode=thread&order=0&thold=0 【015】cissp CISSP training Certified Information Systems Security Professional - NIST Security Configuration Checklists Repository Vista Checklist[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1128&mode=thread&order=0&thold=0 【016】cissp CISSP training Certified Information Systems Security Professional - Researchers criticise 3D Secure credit card authentication[网址]http://www.cccure.org/modules.php?name=News&file=article&sid=1448&mode=thread&order=0&thold=0 【017】cissp CISSP training Certified Information Systems Security Professional - Join SecurityVibes and exchange information with your peers![网址]http://www.cccure.org/modules.ph
Read the rest of this comment... |
|
|
|