5.2 - Explain the importance of applicable regulations, standards, or frameworks that impact organizational security posture. Flashcards

1
Q

International Organization for Standardization (ISO) 27001/27002/27701/31000

A

ISO/IEC frameworks

International Organization for Standardization/International Electrotechnical Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO 27001

A

International Organization for Standardization

– Standard for an Information Security Management System (ISMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISO 27002

A

International Organization for Standardization

– Code of practice for information security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO 27701

A

International Organization for Standardization

– Privacy Information Management Systems (PIMS)

-extends the ISO 27001 + 27002 standards to include detailed mgmt of PII (Personally Identifiable Information) + data privacy

-extends 27001 wth enhancements 4 privacy to establish + maintain info mgmt systems specific to privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISO 31000

A

International Organization for Standardization

– International standards for risk management practices

-provides framework 4 risk mgmt process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SSAE SOC 2 Type I/II

A

The American Institute of Certified Public Accountants (AICPA) auditing standard Statement on Standards for Attestation Engagements number 18 (SSAE 18)
* SOC 2 - Trust Services Criteria (security controls) – Firewalls, intrusion detection, and
multi-factor authentication

  • Type I audit
    – Tests controls in place at a particular point in time
  • Type II
    – Tests controls over a period of at least six
    consecutive months
How well did you know this?
1
Not at all
2
3
4
5
Perfectly