Information Security Forum: Difference between revisions
rm redundant see also link (MOS:NOTSEEAGAIN) |
|||
(23 intermediate revisions by 18 users not shown) | |||
Line 1: | Line 1: | ||
{{Short description|Organization in the United Kingdom}} |
|||
{{Multiple issues| |
|||
{{notability|Companies|date=February 2018}} |
|||
{{more footnotes|date=December 2016}} |
{{more footnotes|date=December 2016}} |
||
}} |
|||
{{Infobox company |
{{Infobox company |
||
| name = Information Security Forum |
| name = Information Security Forum |
||
| logo = |
| logo = Simplelowrez.png |
||
| foundation = [[London, United Kingdom]] (1989) |
| foundation = [[London, United Kingdom]] (1989) |
||
| industry = [[information security]] [[best practice]] research |
| industry = [[information security]] [[best practice]] research |
||
| homepage = [http://www.securityforum.org/ SecurityForum.org] |
| homepage = [http://www.securityforum.org/ SecurityForum.org] |
||
| twitter = @securityforum |
|||
}} |
}} |
||
The '''Information Security Forum''' ('''ISF''') is an independent information security body. |
|||
The Information Security Forum (ISF) is an independent, not-for-profit organisation with a Membership comprising many of the world’s leading organisations featured on the Fortune 500 and Forbes 2000 lists. The ISF are dedicated to investigating, clarifying and resolving key issues in information security and risk management, by developing best practice methodologies, processes and solutions that meet the business needs of Members. |
|||
Founded in 1989, the ISF provides Members with a trusted and confidential environment within which their in-depth knowledge and practical experience can be shared. These forums include the ISF member website (ISF Live), Regional Chapter Meetings and Solution Development Workshops. This approach enables the ISF to harness the collective insights and knowledge of its Members to deliver leading-edge solutions that are comprehensive, pragmatic and effective. By working together, Members avoid the major expenditure required to reach the same goals on their own. |
|||
The ISF has developed a model that shows how to address – via ISF Research, Knowledge Exchange and Tools & Methodologies – the fundamental elements of an information security programme. The ISF provide insights, best practice standards and tools which address every aspect of the model to aid organisations in enhancing their information risk environment, including organisations in their supply chain. |
|||
Consultancy Services from the ISF further provide Members and Non-Members with the opportunity to purchase short-term, professional support activities to supplement the implementation of ISF products including the ISF Protection Process and other resources in the ISF series. |
|||
==Primary deliverables== |
==Primary deliverables== |
||
Line 23: | Line 20: | ||
===''The Standard of Good Practice for Information Security''=== |
===''The Standard of Good Practice for Information Security''=== |
||
{{main|Standard of Good Practice}} |
{{main|Standard of Good Practice for Information Security}} |
||
The ISF released the updated ''Standard of Good Practice for Information Security'' in |
The ISF released the updated ''Standard of Good Practice for Information Security'' in 2018. The Standard is available to ISF members and non-members, who can purchase copies of the report. The 2018 Standard represents an update on the 2016 release of the Standard, and builds upon the previous release to include the most up-to-date controls, approaches and thought leadership in information security. |
||
The standard is a business-focused, practical and comprehensive guide available for identifying and managing information security risks in organizations.<ref>https://www.securityforum.org/tools/sogp/</ref> |
The standard is a business-focused, practical and comprehensive guide available for identifying and managing information security risks in organizations.<ref>{{cite web |url=https://www.securityforum.org/tools/sogp/ |title=Information Security Forum : The Standard of Good Practice for Information Security |accessdate=2014-10-13 |url-status=dead |archiveurl=https://web.archive.org/web/20141018220906/https://www.securityforum.org/tools/sogp/ |archivedate=2014-10-18 }}</ref> |
||
The 2016 standard covers current information security 'hot topics' such as Threat Intelligence, Cyber Attack Protection and Industrial Control Systems, as well as, significant enhancement of existing topics including |
The 2016 standard covers current information security 'hot topics' such as Threat Intelligence, Cyber Attack Protection and Industrial Control Systems, as well as, significant enhancement of existing topics including Information Risk Assessment, Security Architecture and Enterprise Mobility Management. It can be used to build a comprehensive and effective information security management system. In addition to covering information security-related standards such as [[COBIT]] 5 for Information Security, [[The CIS Critical Security Controls for Effective Cyber Defense]], the 2016 standard covers [[ISO/IEC 27002]] as well as [[PCI DSS]] 3.1 and the [[NIST Cybersecurity Framework]]. |
||
===Research projects=== |
===Research projects=== |
||
Line 37: | Line 34: | ||
===The Benchmark=== |
===The Benchmark=== |
||
The ISF's Benchmark (formerly called the 'Information Security Status Survey') has a well-established pedigree – harnessing the collective input of hundreds of the world's leading organizations for over 25 years. Organizations can participate in the Benchmark service at any time and can use the web-based tool to assess their security performance across a range of different environments, compare their security strengths and weaknesses against other organizations, and measure their performance against the ISF's 2016 Standard of Good Practice, ISO/IEC 27002:2013, and COBIT version 5 for information security. The Benchmark provides a variety of data export functionality that can be used for analyzing and presenting data for management reporting and the creation of security improvement programs. It is updated on a biennial basis to align with the latest thinking in information security and provide the ISF Members with improved user experiences and added value. |
The ISF's Benchmark (formerly called the 'Information Security Status Survey') has a well-established pedigree – harnessing the collective input of hundreds of the world's leading organizations for over 25 years. Organizations can participate in the Benchmark service at any time and can use the web-based tool to assess their security performance across a range of different environments, compare their security strengths and weaknesses against other organizations, and measure their performance against the ISF's 2016 Standard of Good Practice, ISO/IEC 27002:2013, and COBIT version 5 for information security. The Benchmark provides a variety of data export functionality that can be used for analyzing and presenting data for management reporting and the creation of security improvement programs. It is updated on a biennial basis to align with the latest thinking in information security and provide the ISF Members with improved user experiences and added value.<ref name=":0" /> |
||
===Face-to-face networking=== |
===Face-to-face networking=== |
||
Regional chapter meetings and other activities provide for face-to-face networking among individuals from ISF member organisations. The ISF encourages direct member-to-member contact to address individual questions and |
Regional chapter meetings and other activities provide for face-to-face networking among individuals from ISF member organisations. The ISF encourages direct member-to-member contact to address individual questions and strengthen relationships. Chapter meetings and other activities are conducted around the world and address local issues and language/cultural dimensions.{{citation needed|date=February 2014}} |
||
===Annual World Congress=== |
===Annual World Congress=== |
||
The ISF's annual global conference, the 'World Congress', takes place in a different city each year. The 2017 conference will take place in October in [[Cannes, France]]. The event offers an opportunity for attendees to discuss and find solutions to current security challenges, and gain practical advice from peers and leading industry experts from around the world. Over 1,000 global senior executives attend. The event includes a series of keynote presentations, workshops and networking sessions, best |
The ISF's annual global conference, the 'World Congress', takes place in a different city each year. The 2017 conference will take place in October in [[Cannes, France]]. The event offers an opportunity for attendees to discuss and find solutions to current security challenges, and gain practical advice from peers and leading industry experts from around the world. Over 1,000 global senior executives attend. The event includes a series of keynote presentations, workshops and networking sessions, best practices and thought leadership in a confidential peer-group environment.<ref name=":0">{{cite web |url=https://www.securityforum.org/events/isf-annual-world-congress/ |title=Information Security Forum : 25th ISF Annual World Congress |accessdate=2014-10-13 |url-status=dead |archiveurl=https://web.archive.org/web/20141018222734/https://www.securityforum.org/events/isf-annual-world-congress/ |archivedate=2014-10-18 }}</ref> |
||
===Web portal (ISF Live)=== |
===Web portal (ISF Live)=== |
||
The ISF's extranet portal, ISF Live, enables members to directly access all ISF materials, including member presentations, messaging forums, contact information, webcasts, online tools, and other data for member use.<ref>https://www.securityforum.org/membership/isflive/</ref> |
The ISF's extranet portal, ISF Live, enables members to directly access all ISF materials, including member presentations, messaging forums, contact information, webcasts, online tools, and other data for member use.<ref>{{cite web |url=https://www.securityforum.org/membership/isflive/ |title=Information Security Forum : ISF Live: Collaborate, Contribute and Participate |accessdate=2014-10-13 |url-status=dead |archiveurl=https://web.archive.org/web/20141018220958/https://www.securityforum.org/membership/isflive/ |archivedate=2014-10-18 }}</ref> |
||
===Leadership=== |
===Leadership=== |
||
Line 54: | Line 50: | ||
==See also== |
==See also== |
||
''See [[:Category:Computer security]] for a list of all computing and information-security related articles''. |
''See [[:Category:Computer security]] for a list of all computing and information-security related articles''. |
||
*[[Standard of Good Practice]] |
|||
*[[Information Systems Audit and Control Association]] |
*[[Information Systems Audit and Control Association]] |
||
*[[International Organization for Standardization]] |
*[[International Organization for Standardization]] |
||
Line 66: | Line 61: | ||
*[http://www.securityforum.org The Information Security Forum] |
*[http://www.securityforum.org The Information Security Forum] |
||
[[Category:Borough of Elmbridge]] |
|||
[[Category:Computer security organizations]] |
[[Category:Computer security organizations]] |
||
[[Category:Cybercrime in the United Kingdom]] |
|||
[[Category:Information technology organisations based in the United Kingdom]] |
|||
[[Category:Non-profit organisations based in London]] |
[[Category:Non-profit organisations based in London]] |
||
[[Category:Organisations based in Surrey]] |
|||
[[Category:Organizations established in 1989]] |
[[Category:Organizations established in 1989]] |
||
[[Category:Research organisations in the United Kingdom]] |
[[Category:Research organisations in the United Kingdom]] |
||
[[Category:Science and technology in Surrey]] |
|||
[[Category:Security companies of the United Kingdom]] |
[[Category:Security companies of the United Kingdom]] |
Latest revision as of 22:17, 24 December 2023
This article has multiple issues. Please help improve it or discuss these issues on the talk page. (Learn how and when to remove these messages)
|
Industry | information security best practice research |
---|---|
Founded | London, United Kingdom (1989) |
Website | SecurityForum.org |
The Information Security Forum (ISF) is an independent information security body.
Primary deliverables
[edit]The ISF delivers a range of content, activities, and tools. The ISF is a paid membership organisation: all its products and services are included in the membership fee. From time to time, the ISF makes research documents and other papers available to non-members.
The Standard of Good Practice for Information Security
[edit]The ISF released the updated Standard of Good Practice for Information Security in 2018. The Standard is available to ISF members and non-members, who can purchase copies of the report. The 2018 Standard represents an update on the 2016 release of the Standard, and builds upon the previous release to include the most up-to-date controls, approaches and thought leadership in information security.
The standard is a business-focused, practical and comprehensive guide available for identifying and managing information security risks in organizations.[1]
The 2016 standard covers current information security 'hot topics' such as Threat Intelligence, Cyber Attack Protection and Industrial Control Systems, as well as, significant enhancement of existing topics including Information Risk Assessment, Security Architecture and Enterprise Mobility Management. It can be used to build a comprehensive and effective information security management system. In addition to covering information security-related standards such as COBIT 5 for Information Security, The CIS Critical Security Controls for Effective Cyber Defense, the 2016 standard covers ISO/IEC 27002 as well as PCI DSS 3.1 and the NIST Cybersecurity Framework.
Research projects
[edit]Based on member input, the ISF selects a number of topics for research in a given year. The research includes interviewing member and non-member organizations and thought leaders, academic researchers, and other key individuals, as well as examining a range of approaches to the issue. The resulting reports typically go into depth describing the issue generally, outlining the key information security issues to be considered, and proposing a process to address the issue, based on best practices.
Methodologies and tools
[edit]For broad, fundamental areas, such as information risk assessment or return-on-investment calculations, the ISF develops comprehensive methodologies that formalize the approaches to these issues. Supporting the methodology, the ISF supplies web and spreadsheet-based tools to automate these functions.
The Benchmark
[edit]The ISF's Benchmark (formerly called the 'Information Security Status Survey') has a well-established pedigree – harnessing the collective input of hundreds of the world's leading organizations for over 25 years. Organizations can participate in the Benchmark service at any time and can use the web-based tool to assess their security performance across a range of different environments, compare their security strengths and weaknesses against other organizations, and measure their performance against the ISF's 2016 Standard of Good Practice, ISO/IEC 27002:2013, and COBIT version 5 for information security. The Benchmark provides a variety of data export functionality that can be used for analyzing and presenting data for management reporting and the creation of security improvement programs. It is updated on a biennial basis to align with the latest thinking in information security and provide the ISF Members with improved user experiences and added value.[2]
Face-to-face networking
[edit]Regional chapter meetings and other activities provide for face-to-face networking among individuals from ISF member organisations. The ISF encourages direct member-to-member contact to address individual questions and strengthen relationships. Chapter meetings and other activities are conducted around the world and address local issues and language/cultural dimensions.[citation needed]
Annual World Congress
[edit]The ISF's annual global conference, the 'World Congress', takes place in a different city each year. The 2017 conference will take place in October in Cannes, France. The event offers an opportunity for attendees to discuss and find solutions to current security challenges, and gain practical advice from peers and leading industry experts from around the world. Over 1,000 global senior executives attend. The event includes a series of keynote presentations, workshops and networking sessions, best practices and thought leadership in a confidential peer-group environment.[2]
Web portal (ISF Live)
[edit]The ISF's extranet portal, ISF Live, enables members to directly access all ISF materials, including member presentations, messaging forums, contact information, webcasts, online tools, and other data for member use.[3]
Leadership
[edit]The members of the ISF, through the regional chapters, elect a Council to develop its work program and generally to represent member interests. The Council elects an 'Executive' group which is responsible for financial and strategic objectives.
See also
[edit]See Category:Computer security for a list of all computing and information-security related articles.
- Information Systems Audit and Control Association
- International Organization for Standardization
- SANS Institute
- Gartner
References
[edit]- ^ "Information Security Forum : The Standard of Good Practice for Information Security". Archived from the original on 2014-10-18. Retrieved 2014-10-13.
- ^ a b "Information Security Forum : 25th ISF Annual World Congress". Archived from the original on 2014-10-18. Retrieved 2014-10-13.
- ^ "Information Security Forum : ISF Live: Collaborate, Contribute and Participate". Archived from the original on 2014-10-18. Retrieved 2014-10-13.
External links
[edit]- Borough of Elmbridge
- Computer security organizations
- Cybercrime in the United Kingdom
- Information technology organisations based in the United Kingdom
- Non-profit organisations based in London
- Organisations based in Surrey
- Organizations established in 1989
- Research organisations in the United Kingdom
- Science and technology in Surrey
- Security companies of the United Kingdom