To address the need for cybersecurity resources, the global association for auditing and information technology, ISACA, has published its European Cybersecurity Implementation Series.
These cybersecurity directives for Europe are part of ISACA's Cybersecurity Nexus (CSX) program, a resource center where businesses and security professionals can find research, training, and a cybersecurity community. Furthermore, this series of directives provides guidance on practical implementation, aligned with the requirements and best practices of the European Network and Information Security Agency (ENISA). The published directives include four white papers and a program on auditing and assurance
• Implementing Cybersecurity in Europe: Overview—This white paper provides a high-level overview of the implementation of cybersecurity best practices, in line with existing legislation, standards, and other directives. It is complemented by three detailed white papers focusing on directives on cybersecurity risk, resilience, and assurance, as well as a European Programme on Cybersecurity Audit/Assurance.
• Implementing Cybersecurity in Europe: Assurance—Companies need assurance in their cybersecurity activities and initiatives as part of good corporate governance, risk management, and compliance (GRC). This deliverable addresses cybersecurity implementation from a European perspective, including the European Union and its associated countries, to help effectively contribute to protecting companies against cyberattacks and security breaches.
• Implementing Cybersecurity in Europe: Resilience— In cybersecurity, resilience is the ability to absorb internal and external shocks and recover to return to normal operations in a controlled manner. This white paper focuses on cybersecurity resilience from the perspective of European Union countries, using national and EU approaches to critical information infrastructure and its protection.
• Implementing Cybersecurity in Europe: Risks— Cybersecurity risk strategies must be aligned with the overall strategy and framework for enterprise risk management. Every identified cybersecurity-related risk requires in-depth analysis incorporating a range of components. This white paper will help companies determine a manageable set of risks based on risk scenarios that include known risks and future and emerging risk factors that may arise in the cybersecurity context.
• European Program on Cybersecurity Audit/Assurance (coming soon)—Based on ISACA’s IT Assurance Framework (ITAF), this program helps provide management with an assessment of the effectiveness of cybersecurity and related good governance, management, and assurance. This analysis focuses on cybersecurity standards, directives, and procedures aligned with ISACA’s COBIT 5 framework.
This and other topics on information security, auditing, and risk management will be addressed at the ISACA EuroCACS/ISRM 2014 Conference, which will take place in Barcelona from September 29 to October 1.
