In June of 2015 the FFIEC (Federal Financial Institutions Examination Council) released the first version of their Cybersecurity Assessment Tool (CAT). The FFIEC, for those not aware, is a formal interagency body empowered to prescribe uniform principles, standards, and report forms for the federal examination of financial institutions and is made up of 6 different agencies.
The FFIEC already has a set of works called the IT Examination Handbooks, about a dozen, which help set down standards for IT in several areas. One of interest would be the Information Security one that was finally updated in 2016.
Showing posts with label FFIEC CAT. Show all posts
Showing posts with label FFIEC CAT. Show all posts
Monday, June 19, 2017
Sunday, March 13, 2016
Resources for workshop on security standards/frameworks/regulations for information security professionals
At the 2016 Security BSides Orlando conference, I gave a workshop on security standards, frameworks, regulations for information security professionals. While not an exhaustive survey of such, I focused on the ones that seem the most known, and which I typically see on job descriptions.
Not covered were enterprise architecture models like Zachman or TOGAF. Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.
Covered were:
Not covered were enterprise architecture models like Zachman or TOGAF. Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.
Covered were:
- CIS CSC
- NIST CSF (plus FFIEC CAT)
- ISO/IEC 27001
- FISMA
- HIPAA
- GLBA
- SOX (plus COSO)
- PCI-DSS
- COBIT 5
- ITIL
Labels:
certification,
Cobit,
COSO,
Critical Security Controls,
CSC,
FFIEC,
FFIEC CAT,
FISMA,
frameworks,
GLBA,
HIPAA,
ITIL,
NIST,
NIST CSF,
PCI-DSS,
regulations,
SANS Top 20,
SoX,
training
Subscribe to:
Posts (Atom)