Institute for Information Assurance



Information Security Websites

American Society of Digital Forensics & eDiscovery 
www.asdfed.com

Argonne National Laboratory
Scavenger an open source real-time vulnerability management tool
https://trac.anl.gov/scavenger/wiki

CERT
http://www.cert.org/cert/

Common Criteria Evaluation and Validation Scheme
http://www.niap-ccevs.org/cc-scheme/
http://www.commoncriteriaportal.org/

Common Vulnerabilities and Exposure
http://cve.mitre.org

Computer Security Institute
http://www.gocsi.com/

CSO Magazine
http://www.csoonline.com

CyberCiege
http://cisr.nps.edu/cyberciege/latestv.html

Department of Energy Cyber Incident Response Capability (DOE-CIRC)
http://www.doecirc.energy.gov/

Executive women’s Forum
http://www.infosecuritywomen.com

Information Security Magazine
http://searchsecurity.techtarget.com/magazineCurrent/0,296884,sid14,00.html

Information Systems Audit and Control Association
www.isaca.org

The Information Warfare Site
http://www.iwar.org.uk/index.htm

The International High Technology Crime Investigation Association (HTCIA)
http://www.htcia.org/

International Information Systems Forensics Association (ITFSA)
www.iisfa.org

International Information Systems Security Certification Consortium, Inc., (ISC)²
http://www.isc2.org/

National Security Agency – Central Security Service
http://www.nsa.gov/ia/

National Vulnerability Database
http://nvd.nist.gov/

NIST Computer Security Resource Center
http://csrc.nist.gov/index.html

NIST  Special Publications (800 Series)
http://csrc.nist.gov/publications/PubsSPs.html

SCMagazine for Information Security Professionals
www.scmagazineus.com

SearchSecurity
http://searchsecurity.techtarget.com/

SecurityFocus – Bugtraq Center
http://www.securityfocus.com

SysAdmin, Audit, Network, Security (SANS)
http://www.sans.org


Information Security Standards and Regulations

COBIT Framework
www.isaca.org

COSO Framework
http://www.coso.org/

The Health Insurance Portability and Accountability Act of 1996 (HIPAA)
http://www.hhs.gov/ocr/privacy/index.html

ISO 27000 Information Security Standards
http://www.27000.org/index.htm

Sarbanes-Oxley (SOX) Section 404
http://www.sec.gov/info/smallbus/404guide.shtml
http://www.sec.gov/rules/final/33-8238.htm