INDUSTRY STANDARDS
InfoScreen applies several emerging industry standards for information
security best practice. Most notably, we apply ISO/IEC 17799:2000 and BS 7799-2:2002.
We also apply several open source standards, such as OWASP for web application
security. For clients that maintain military contracts, InfoScreen also applies
the NISPOM (DoD 5220.22-M)
Unless there is an overarching goal to achieve compliance with
a particular standard, InfoScreen only uses industry standards as a guide.
Unlike quality management or GAAP financials, information security risk management
can only be standardized to a point. Commercial pressures will evolve. A new
threat may emerge as the primary concern of the day. A major new business development
initiative can create its own host of information security challenges. InfoScreen
facilitates a healthy dialog within client organizations regarding the right
set of security controls.
|