ISSEP

Information Systems Security Engineering Professional (ISSEP)

View the Project on GitHub chaffin/ISSEP

Domains | Tasks

1.2 Security Risk Management Principles

1.2.1 Align security risk management with enterprise risk management

In the article featured in the ISACA Journal Volume 2, 2014 entitled Aligning Information Security With Enterprise Risk Management Using ISO/IEC 27001:2013, Vimal Mani, CISA, CICA povides a three (3) page overview of the key changes in the updated ISO/IEC 27001:2013 Standard.

1.2.2 Integrate risk management throughout the lifecycle

This International Journal of Software and Web Sciences (IJSWS) paper goes through each phase of the SDLC and provides a minimum set of security steps that needs to be effectively incorporated into a system during its development.

According to The MITRE Corporation “all systems engineering models and processes are organized around the concept of a life cycle. Although the detailed views, implementations, and terminology used to articulate the SE life cycle differ across MITRE’s sponsors, they all share fundamental elements”.