Principles of Generally Accepted Information Security Principles (GAISP)
GAISP is based on a solid consensus-building process that is central to the success of this approach. Principles at all levels are developed by information security practitioners who fully understand the underlying issues of the
documented practices and their application in the real world. Then, these principles will be reviewed and vetted by
skilled information security experts and authorities who will ensure that each principle is:
• Accurate, complete, and consistent
• Compliant with its stated objective
• Technically reasonable
• Well-presented, grammatically and editorially correct
• Conforms to applicable standards and guideline
The principles are:
1. Computer security supports the mission of the organization
2. Computer security is an integral element of sound management
3. Computer security should be cost-effective
4. Systems owners have security responsibilities outside their own organization
5. Computer security responsibilities and accountability should be made explicit
6. Computer security requires a comprehensive and integrated approach
7. Computer security should be periodically reassessed
8. Computer security is constrained by societal factors
Trackback URL for this post:
- Add new comment
- 5559 reads













There are some interesting
There are some interesting points in time in this article however I dont know if I see all of them heart to heart. There's some validity however I will take hold opinion till I look into it further. Good article , thanks and we would like more! Added to FeedBurner as properly
testking 70-401//
testking JN0-632//
testking 70-448//
testking MB2-868//
testking MB2-867//
testking 70-686//
testking F50-532//
testking 70-685//