Standard of Good Practice for Information Security (SoGP)
The Standard of Good Practice for Information Security (SoGP) is an information security framework from the Information Security Forum (ISF).
ISF is an independent, non-profit organisation with members across many industries. Just over half of its members are large global companies. Public sector bodies and government agencies are also among its members. In total, 27,000 information security professionals are covered through the organisation's member companies. ISF aims to provide knowledge sharing and access to research, tools and methods.
SoGP is intended to provide comprehensive, practical guidance and help organisations effectively protect their information assets, manage risk, achieve regulatory compliance and prepare for certifications. SoGP is designed for information security and risk management specialists and is updated regularly to address new threats and risks.
Several aspects are covered. According to ISF (2022):
- Resilience — the ability to react quickly to growing threats using a ready-made framework.
- Risk assessment and protection in line with the organisation's risk appetite.
- Supply chains in risk management and information security.
- Regulatory compliance and certification in a cost-effective way, aligned with ISO 27002 and the NIST Cybersecurity Framework.
- Policies, standards and procedures presented in a simplified way, ideally forming the basis of an Information Security Management System (ISMS) in line with ISO 27001.
- Awareness of information security throughout the organisation.
The 2024 edition updates the framework by integrating topics such as AI, Zero Trust and cyber resilience.
SoGP consists of 142 topics across 34 areas within 17 categories:
- Security Governance
- Information Risk Assessment
- Security Management
- People Management
- Information Management
- Physical Asset Management
- System Development
- Business Application Management
- System Access
- System Management
- Network and Communications
- Supply Chain Management
- Technical Security Management
- Threat and Incident Management
- Physical and Environmental Management
- Business Continuity
- Security Assurance.
In addition to its ongoing alignment with other established standards and frameworks, SoGP evolves over time based on new research conducted by ISF, together with good practice examples from member organisations' security work and outcomes from members' collaborative forums.
SoGP is aligned with several other established standards and frameworks, such as ISO 27002, the NIST Cybersecurity Framework, CIS Controls, PCI DSS, COBIT and the CSA Cloud Control Matrix. The intention is to make it possible to consolidate all compliance work within a single tool.
The Cloud Controls Matrix (CCM) is a framework for cloud services developed by the Cloud Security Alliance (CSA), with controls covering cloud infrastructure, SaaS/PaaS/IaaS, supplier relationships and data protection.