ISO/IEC 19770 (all parts), Information technology — IT asset management
ISO/IEC 19941, Information technology — Cloud computing — Interoperability and portability
ISO/IEC 20889, Privacy enhancing data de-identification terminology and classification of techniques
ISO 21500, Project, programme and portfolio management — Context and concepts
ISO 21502, Project, programme and portfolio management — Guidance on project management
ISO 22301, Security and resilience — Business continuity management systems — Requirements
ISO 22313, Security and resilience — Business continuity management systems — Guidance on the use of ISO 22301
ISO/TS 22317, Societal security — Business continuity management systems — Guidelines for business impact analysis (BIA)
ISO 22396, Security and resilience — Community resilience — Guidelines for information exchange between organizations
ISO/IEC TS 23167, Information technology — Cloud computing — Common technologies and techniques
ISO/IEC 23751:—2), Information technology — Cloud computing and distributed platforms — Data sharing agreement (DSA) framework
ISO/IEC 24760 (all parts), IT Security and Privacy — A framework for identity management
ISO/IEC 27001:2013, Information technology — Security techniques — Information security management systems — Requirements
ISO/IEC 27005, Information technology — Security techniques — Information security risk management
ISO/IEC 27007, Information security, cybersecurity and privacy protection — Guidelines for information security management systems auditing
ISO/IEC TS 27008, Information technology — Security techniques — Guidelines for the assessment of information security controls
ISO/IEC 27011, Information technology — Security techniques — Code of practice for Information security controls based on ISO/IEC 27002 for telecommunications organizations
ISO/IEC TR 27016, Information technology — Security techniques — Information security management — Organizational economics
ISO/IEC 27017, Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services
ISO/IEC 27018, Information technology — Security techniques — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
ISO/IEC 27019, Information technology — Security techniques — Information security controls for the energy utility industry
ISO/IEC 27031, Information technology — Security techniques — Guidelines for information and communication technology readiness for business continuity
ISO/IEC 27034 (all parts), Information technology — Application security
ISO/IEC 27035 (all parts), Information technology — Security techniques — Information security incident management
ISO/IEC 27036 (all parts), Information technology — Security techniques — Information security for supplier relationships
ISO/IEC 27037, Information technology — Security techniques — Guidelines for identification, collection, acquisition and preservation of digital evidence
ISO/IEC 27040, Information technology — Security techniques — Storage security
ISO/IEC 27050 (all parts), Information technology — Electronic discovery
ISO/IEC TS 27110, Information technology, cybersecurity and privacy protection — Cybersecurity framework development guidelines
ISO/IEC 27701, Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines
ISO 27799, Health informatics — Information security management in health using ISO/IEC 27002
ISO/IEC 29100, Information technology — Security techniques — Privacy framework
ISO/IEC 29134, Information technology — Security techniques — Guidelines for privacy impact assessment
ISO/IEC 29146, Information technology — Security techniques — A framework for access management
ISO/IEC 29147, Information technology — Security techniques — Vulnerability disclosure
ISO 30000, Ships and marine technology — Ship recycling management systems — Specifications for management systems for safe and environmentally sound ship recycling facilities
ISO/IEC 22123 (all parts), Information technology — Cloud computing
ISO/IEC 27555, Information security, cybersecurity and privacy protection — Guidelines on personally identifiable information deletion
Information Security Forum (ISF). The ISF Standard of Good Practice for Information Security 2020, August 2018. Available at ISF Standard
ITIL® Foundation, ITIL 4 edition, AXELOS, February 2019, ISBN: 9780113316076
National Institute of Standards and Technology (NIST), SP 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, Revision 2. December 2018 [viewed 2020-07-31]. Available at NIST.SP.800-37r2
Open Web Application Security Project (OWASP). OWASP Top Ten - 2017, The Ten Most Critical Web Application Security Risks, 2017 [viewed 2020-07-31]. Available at OWASP Top Ten 2017
Open Web Application Security Project (OWASP). OWASP Developer Guide, [online] [viewed 2020-10-22]. Available at OWASP Developer Guide
National Institute of Standards and Technology (NIST), SP 800-63B, Digital Identity Guidelines; Authentication and Lifecycle Management. February 2020 [viewed 2020-07-31]. Available at NIST.SP.800-63b
OASIS, Structured Threat Information Expression. Available at OASIS STIX 2.0
OASIS, Trusted Automated Exchange of Indicator Information. Available at OASIS TAXII 2.0