276 SOFTWARE QUALITY ASSURANCE
Security Standards
ISO 15408 ISO 15408, commonly known as common criteria, pro-
vides the framework for testing the effectiveness of most security sys-
tems. However, it is not intended to measure the effectiveness of an
organization’s security program.
COBIT Developed for IT auditors and made available through the
ISACA. It provides a framework for assessing a program, developing
a performance baseline, and measuring performance over time.
ISO 17799/BS7799 ISO 17799 Information Technology—Code of
Practice for Information Security Management began in the United
Kingdom as BS 7799 in 1995 as a comprehensive set of controls com-
prising best practices in information security. It was revised in May
1999 and fast-trac ...