: A method for engineering business requirements into measurable security goals.

if any organization want use need guide line

: A model for managing risk and trust by grouping elements under a common security policy.

Zalo