5.2 applicable regulations, standards, or frameworks that impact organizational security posture. Flashcards
CIS
Center for Internet Security
NIST
Natl Institute of Standards and Technology
mandatory for federal agencies and federal data
CSA
Cloud Security Alliance
ISO/IEC
27001 - Information Security Mgmt System
27002 - Information Security Controls
27701 - Privacy Information mgmt Systems
31000 - Risk Management Practices
ISO 27001
ISMS
establishing, implementing, and managing an information security management system (ISMS)
ISO 27002
SUPPORTING
a supporting standard that guides how the information security controls can be implemented from 27001
27701
PRIVACY
an international standard for managing privacy information
31000
RISK
international standards for risk management
RMF
Risk Management Framework
dictates how the United States government IT systems must be architected, secured, and monitored
CSF
Cyber Security Framework
voluntary commercial framework
SSAE SOC 2 type I/II
AUDIT
auditing standard covers security controls in large corporations
CCM
Cloud Controls Matrix (CCM) is a cybersecurity framework for cloud computing. It’s considered the standard for cloud security and privacy.