02.07.2014 Views

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

State of the Practice of Computer Security Incident Response Teams ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Federal Trade Commission<br />

16 CFR Part 314 – Standards for Safeguarding Customer Information<br />

http://www.ftc.gov/os/2002/05/67fr36585.pdf<br />

Implements sections <strong>of</strong> <strong>the</strong> Gramm-Leach-Bliley Act and “sets forth standards for developing,<br />

implementing, and maintaining reasonable administrative, technical, and physical safeguards<br />

to protect <strong>the</strong> security, confidentiality, and integrity <strong>of</strong> customer information.” Financial<br />

institutions must implement an information security program.<br />

O<strong>the</strong>r Lists <strong>of</strong> U.S. IT Laws<br />

Chief Information Officers Council (CIOC) Documents – IT Related Laws and Legislation<br />

http://cio.gov/index.cfm?function=documents&section=it related laws and regulations<br />

FedCIRC – Library – Legislation<br />

http://www.fedcirc.gov/library/legislation/<br />

GSA Office <strong>of</strong> Electronic Government and Strategy – http://www.estrategy.gov/<br />

E-Government Laws, Regulations, and Policies<br />

http://www.estrategy.gov/it_policy_documents.cfm<br />

Key E-Government Related Laws – http://www.estrategy.gov/elaws.cfm<br />

All E-Government Related Laws Chronological By Congress –<br />

http://www.estrategy.gov/lawscongress.cfm<br />

GSA – Policies, Guidelines, Regulations, and Best <strong>Practice</strong>s<br />

http://www.gsa.gov/Portal/policies.jsp<br />

NIST – CSRC – Policies – Federal Requirements<br />

http://csrc.nist.gov/policies/<br />

U.S. Department <strong>of</strong> Education – Office <strong>of</strong> <strong>the</strong> Chief Information Officer – Legislation and<br />

Guidelines<br />

http://www.ed.gov/print/about/<strong>of</strong>fices/list/ocio/legislation.html<br />

O<strong>the</strong>r U.S. Industry Standards<br />

American Institute <strong>of</strong> Certified Public Accountants (AICPA) – http://www.aicpa.org/<br />

<strong>State</strong>ment on Auditing Standards (SAS) No. 70, Service Organizations<br />

Audit guide for reports on a service organization’s controls, and for financial statements <strong>of</strong><br />

entities that use service organizations<br />

http://www.sas70.com/<br />

United <strong>State</strong>s <strong>State</strong> Laws<br />

National <strong>Security</strong> Institute – <strong>Computer</strong> Crime Laws by <strong>State</strong><br />

http://nsi.org/Library/Compsec/computerlaw/statelaws.html<br />

CMU/SEI-2003-TR-001 175

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!