Standards and Framework Providers

ISACA
ISACA provides practical guidance, benchmarks and other effective tools for all enterprises that use information systems. Through its comprehensive guidance and services, ISACA defines the roles of information systems governance, security, audit and assurance professionals worldwide. The COBIT, Val IT and Risk IT governance frameworks and the CISA, CISM and CGEIT certifications are ISACA brands respected and used by these professionals for the benefit of their enterprises.
ISO
ISO (International Organization for Standardization) is the world's largest developer and publisher of International Standards. ISO is a network of the national standards institutes of 163 countries, one member per country, with a Central Secretariat in Geneva, Switzerland, that coordinates the system.
OSA
The Cloud Security Alliance is a non-profit organization formed to promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is comprised of many subject matter experts from a wide variety disciplines, united in our objectives: Promote a common level of understanding between the consumers and providers of cloud computing regarding the necessary security requirements and attestation of assurance; Promote independent research into best practices for cloud computing security; Launch awareness campaigns and educational programs on the appropriate uses of cloud computing and cloud security solutions; Create consensus lists of issues and guidance for cloud security assurance.
SANS
The SANS (SysAdmin, Audit, Network, Security) Institute was established in 1989 as a cooperative research and education organization. Its programs now reach more than 165,000 security professionals around the world. At the heart of SANS are the many security practitioners in varied global organizations from corporations to universities working together to help the entire information security community.
PCI
The PCI Security Standards Council is an open global forum for the ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protection. The PCI Security Standards Council's mission is to enhance payment account data security by driving education and awareness of the PCI Security Standards. The organization was founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa, Inc.
BITS
A division of The Financial Services Roundtable, BITS is a not-for-profit industry consortium whose members are 100 of the largest financial institutions in the United States. Created in 1996 by the CEOs of these institutions, BITS fosters the growth and development of electronic financial services and e-commerce for the benefit of financial institutions and their customers. Working to sustain consumer confidence and trust by ensuring the security, privacy and integrity of financial transactions, BITS provides intellectual capital and addresses emerging issues where financial services, technology and commerce intersect, acting quickly to address problems and galvanize the industry.
NVD
From automated teller machines and atomic clocks to mammograms and semiconductors, innumerable products and services rely in some way on technology, measurement, and standards provided by the National Institute of Standards and Technology. Founded in 1901, NIST is a non-regulatory federal agency within the U.S. Department of Commerce. NIST's mission is to promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve our quality of life.
SAS
Statement on Auditing Standards (SAS) No. 70, Service Organizations, is a widely recognized auditing standard developed by the American Institute of Certified Public Accountants (AICPA). A service auditor's examination performed in accordance with SAS No. 70 (also commonly referred to as a "SAS 70 Audit") is widely recognized, because it represents that a service organization has been through an in-depth audit of their control objectives and control activities, which often include controls over information technology and related processes.
NERC
Since 1968, the North American Electric Reliability Corporation (NERC) has been committed to ensuring the reliability of the bulk power system in North America. To achieve that, NERC develops and enforces reliability standards; assesses adequacy annually via a 10-year forecast and winter and summer forecasts; monitors the bulk power system; and educates, trains, and certifies industry personnel. NERC is a self-regulatory organization, subject to oversight by the U.S. Federal Energy Regulatory Commission and governmental authorities in Canada.
RMA
Founded in 1914, The Risk Management Association (RMA), is a not-for-profit, member-driven professional association, whose sole purpose is to advance the use of sound risk principles in the financial services industry. RMA promotes an enterprise approach to risk management that focuses on credit risk, market risk, and operational risk.
 
 

Solutions
Actionable Risk
Continuous Compliance
Risk-Based Security
Products
Technology
Platform
Applications
Connectors
Content
Services
Cont. Comp. Services
Cloud Managed Services
Consulting Services
Support
Education
Customers
Financial Services
Healthcare and Privacy
Public Sector
Retail, Internet and Media
Technology, Industrial and Energy
Partners
Service Providers
Technology Providers
Content Providers
OpenGRC™ by Agiliance
Become a Partner
News
Press Releases
Webcasts
Events
Demo Tuesday
Company
Management
Directors
Careers
Contact Us