GAISPGenerally Accepted Information Security Principles
From an auditing perspective, the responsibility of compliance to regulations like HIPPA, SOX, FISMA, IPEDS and GAISP [Robinson, 2005] fall in the hands of the Information Technology (IT) department.
GAISP is an attempt to draw together a hierarchical set of principles that have been reviewed by experts in information security and that meet specified criteria.
GAISP is a successor to an earlier effort called Generally Accepted System Security Principles.