Talk With an Expert

Security Controls in Service Management

Security Controls in Service Management (PDF, 2.92MB)Published: 20 Dec, 2010
Created by
Katherine Warren

Integration of security best practices into service management best practices processes enables the organization to lower the overall cost of maintaining acceptable security levels, effectively manage risks and reduce overall risk levels. This document describes an integrated approach to implementing ISO 27001/2 security best practices in an Information Technology Infrastructure Library (ITIL) v3 based service management infrastructure by identifying specific security controls in the ITIL service management framework that meet the control objectives laid out in ISO 27001 and ISO 27002. To provide more specific guidance, recommendations identified in 'Twenty Critical Controls for Effective Cyber Defense: Consensus Audit' (CAG) v2.3 (SANS, 2009) are referenced in the description of each security control.