02. Standards and Frameworks Flashcards
Standards and Frameworks
PCI-DSS
Payment Card Industry Data Security Standard
- Standard required if handling debit or credit cards
- it is a standard, but REQUIRED
Standards and Frameworks
OCTAVE
Operationally Critical Threat, Asset, and Vulnerability Evaluation
- SELF DIRECTED Risk Management
Standards and Frameworks
COBIT
Control Objectives for Information and related Technology
- GOALS for IT
- Stakeholder needs mapped to IT related goals
- REMEMBER COBIT - IT for IT
- COBIT - Operational Level
- COSO - Oganisational Level
Standards and Frameworks
COSO
Committee Of Sponsoring Organisations
- GOALS for entire organisation
- REMEMBER COSO - O at the end for entire organisation
- COBIT - Operational Level
- COSO - Oganisational Level
Standards and Frameworks
ITIL
Information Technology Infrastructure Library
- ITSM - IT Service Management
- Frameworks and best practices to align IT services with businesses needs
Standards and Frameworks
FRAP
Facilitated Risk Analysis Process
- Analysed one business unit, application or system at a time
- Focused on one system at a time
- Brainstorming with INTERNAL employees
Standards and Frameworks
ISO 27001
- Establish, Implement, Control and Improvement of ISMS
- Plan, Do Check, Act
- Organisation can be certified in ISO 27001
- Shows organisation adheres to industry best practices
Standards and Frameworks
ISO 27002
- Practical Advice; How to implement security controls
- 10 Domains used for ISMS
- More indepth than ISO 27001
- Cannot be certified against
- Practical implementation
Standards and Frameworks
ISO 27004
Metrics and measuring success of ISMS
Standards and Frameworks
ISO 27005
Standards Based Approach to Risk Management
Standards and Frameworks
ISO 27799
Directives on how to protect PHI
Protected Health Information
- Key word PROTECTED Health Information
Standards and Frameworks
Defense in Depth
Layered Defense
- Implement multiple overlapping security controls to protect an asset
- Applies to physical, administrative, and logical controls
- No single security control secures an asset
- Defense in Depth improves organisations CIA
EXAMPLE;
* Getting through locked doors, security guards, locked cage
* Getting through IPS, Firewall, switches
Standards and Frameworks
CIA
- Confidentiality
- Integrity
- Availbility