Category
page 1Computer security standards
Common Criteria
International standard for computer security certification
ISO/IEC 27002
Information security standard
S/MIME
S/MIME (Secure/Multipurpose Internet Mail Extensions) is a standard for public-key encryption and signing of MIME data. S/MIME is on an IETF standards track and defined in a number of documents, most importantly . It was originally developed by RSA Data Security, and the original specification used the IETF MIME specification with the de facto industry standard PKCS #7 secure message format. Change control to S/MIME has since been vested in the IETF, and the specification is now layered on Cryptographic Message Syntax (CMS), an IETF specification that is identical in most respects with PK
Same origin policy
The idea is to organize content based on the origin from which it arrives at the browser, preventing outside interference.
HTTP Strict Transport Security
HTTP response header field and associated policy
pluggable authentication module
flexible mechanism for authenticating users
Trusted Computer System Evaluation Criteria
DoD standard for computer security
Common Vulnerability Scoring System
standard for assessing computer system vulnerabilities
Content Security Policy
computer security concept, to prevent cross-site scripting and related attacks
BS 7799
IEEE 802.10
IEEE standard
Security Content Automation Protocol
set of security information exchange specifications
ITSEC
The Information Technology Security Evaluation Criteria (ITSEC) is a structured set of criteria for evaluating computer security within products and systems. The ITSEC was first published in May 1990 in France, Germany, the Netherlands, and the United Kingdom based on existing work in their respective countries. Following extensive international review, Version 1.2 was subsequently published in June 1991 by the Commission of the European Communities for operational use within evaluation and certification schemes.
IEC 62443
cybersecurity standard
ISO/IEC 27017
Cloud service provider security standard
FIPS 140-2
U.S. government cryptographic standard
Rainbow Series
series of computer security standards and guidelines published by the United States government
Information security standards
Term in information security policy