Guidance on reducing risks and improving value in the acquisition and development of technology, including service-provider and outsourcing management.
Helps financial services companies address control weaknesses in outsourced IT services. Coverage includes information security controls and audits, disaster recovery, vendor management, and cross-border considerations.
Guidance on the IT outsourcing lifecycle and its management in the context of a general risk, control, compliance, and governance framework. Developed for audit executives, internal auditors, and management
A heavyweight framework for evaluation and communication of IT investment practices, aimed at US government agencies.
Common criteria against which agencies (or companies) can prioritize security activities into capital planning processes.
NIST SP 800-144 provides an overview of the security and privacy challenges for public cloud computing and gives recommendations that organizations should consider when outsourcing data, applications, and infrastructure to a public cloud environment. ...





