Information security assurance is a topic that has developed quickly over the
last few years. Drivers for its rapid development include the development of
computers at the pace of Moore's Law during the information revolution of the
last century. Motivation for interest in the topic stems from the more recent
Internet revolution, the focus on critical infrastructure related to Homeland
Security, the increased emphasis on corporate governance, and the increasing
awareness of privacy matters as society recognizes the dangers that accompany
IT advances.
No wonder we occasionally see confusion, and more disturbingly, inappropriate
use of standards, schemes, and activities in the security assurance arena.
Below is the information security ecosystem in a way that will clarify ... (more)