Capability and Maturity Model Creation in Information Security
Please read my guest blog post over at IT Knowledge Exchange. It covers the topic of: Capability and Maturity Model Creation in Information Security.
The post references the following capability and maturity model (CMM) resources:
- Information Security Management Maturity Model (ISM3, or ISM-cubed)
- Systems Security Engineering Capability Maturity Model (SSE-CMM), which is ISO standard 21827
- Computer Security Handbook 4th Edition (general theory)
Also, Katie Moussouris reminded me of the Microsoft SDL Optimization Model.
Chaordic Conversations