ISO and NIST Flashcards

1
Q

NIST 800-145

A

NIST Definition of Cloud Computing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the ISO equivalent to NIST 800-145? What does it provide?

A

ISO 17789 provides Cloud Computing Reference Architecture (CCRA) similar to NIST 800-145

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISO

A

the International Organization for Standardization (ISO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO 27001

A

The “What to Do” for ISMS

Rules and Requirements for the implementation and management of an Information Security Management System (ISMS)

As a standard, the organization is granted a CERTIFICATiON or is CERTIFIED given a successful audit.

—–Extra Info—–

contains 114 controls across 14 domains (or clauses)

a globally recognized standard, it is not cloud specific so must not be used exclusively when evaluating cloud security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISO 27002

Describe, What is the result, What is the NIST equivalent?

A

builds on ISO 27001 by providing GUIDELINES for organizations to SELECT, IMPLEMENT, and MANAGE security controls based on their own security RISK PROFILE

same security controls as ISO 27001 just more prescriptive

As a standard, the organization is granted a CERTIFICATiON or is CERTIFIED against the requirements given a successful audit.

The “How to”

Similar to NIST 800-53

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISO 27017

A

builds on ISO 27002 and provides guidelines for security controls related to the PROVISION and USE of CLOUD SERVICES. The standard offers security controls and implementation guidance for both CSPs and cloud service CUSTOMERS for relevant controls specified in ISO 27002

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

NIST 800-53

A

NIST Special Publication 800-53 - A guidance document with the primary goal of ensuring that appropriate security requirements and controls are applied to all US federal government data and information systems. Similar to ISO 27002.

–Extra Info—

NIST Rev 4 (release 2013) contains information on cloud security

outlines 100s of security controls across 18 control families, targeted at US government but used across industry and around the globe

NIST Rev 5 DRAFT, not yet final publication, expected to add modern secure cloud system security and other emerging technologies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

NIST 800-60

A

NIST’s Guide for Mapping Types of Information Systems to Security Categories (NIST 800-60) was last published in 2008, is a resource that provides a step-by-step methodology to classifying data based on risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does ISO 17788 consist of?

A

Cloud Computing Definitions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Describe what is in ISO 19086-1

A

Information Technology - Cloud Computing - Service Level Agreement (SLA) Framework - Part 1: Overview and Concepts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Describe what is in ISO 19086-2

A

Information Technology - Cloud Computing - Service Level Agreement (SLA) Framework - Part 2: Metrics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Describe what is in ISO 19086-3

A

Information Technology - Cloud Computing - Service Level Agreement (SLA) Framework - Part 3: Core Requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ISO 27014

A
  • Governance of Information Security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ISO 38501

A

ISO 38501 - Governance of Information Technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ISO 27018

A

published in 2014, it is the first international code of practice that focuses on protection of personal data in the cloud; based on ISO 27002 and provides implementation guidelines of ISO 27002 controls applicable to protecting PII in public cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ISO 31000

A

Risk Management Guidelines

Provides an overall Enterprise framework and process for managing risk. It can be used by any organization regardless of size, activity or sector.

Cannot be used for certification purposes, however it does provide guidance for internal or external audit programs

17
Q

ISO 27005

A

Information and Security Risk Management

Guidelines and best practices for information security risk management

18
Q

NIST 800-37r2

A

Risk Management Framework for Information Systems and Organizations (RMF)

A system LIFECYCLE approach for SECURITY and PRIVACY, which builds RMF into the SDLC and drives the process of the 6 STEPS of the RMF.

19
Q

FIPS 140-3

A

aligns the new standard with those set forth in ISO/IEC 19790:2012 (Security Requirements for Cryptographic Modules) and ISO/IEC 24759:2017 (Test Requirements for Cryptographic Modules)

20
Q

ISO 28001

A

provides requirements and guidance for organizations in international supply chains to:

Develop and implement supply chain security processes
Establish and document minimum levels of security within a supply chain(s) or segment of a supply chain

21
Q

ISO 19441

A

Information Technology - Could Computing - Interoperability and Portability

Focuses on cloud SERVICE AGREEMENTS and related interoperability and portability between cloud services

22
Q

ISO 22237-2

A

Physical Design of Data Center
Specification and requirements for construction of BUILDING that will house a data center:

  • location and site selection
  • building construction and configuration
  • fire protection
  • quality construction measures

4 Protection Classes where the provider is categorizing the most critical and highly valued systems that require the greatest levels of protection

4 Availability Classes that are about power distribution to the data center

23
Q

ISO 22237-6

A

Addresses security systems and Fire Prevention

24
Q

NIST 800-207

A

Zero Trust Model - evolving set of cybersecurity paradigms that move defenses from static, network perimeters to focus on users, assets, and resources

25
Q

NIST 800-64

A

Special Security Considerations in the System Development Lifecycle

(SDLC for security)

26
Q

ISO 27034-1

A

Information technology - Security techniques - Application security ONF/ANF

Organization Normative Framework/Application Normative Framework

27
Q

ISO 7498

A

OSI reference model

An educational model to explain how networking protocols work
A framework for designing and building network protocols

28
Q

ISO 20000-1

A

A Service Management System (SMS) standard. It specifies requirements for the service provider to plan, establish, implement, operate, monitor, review, maintain, and improve an SMS. The requirements include the design, transition, delivery and improvement of services to fulfill agreed service requirements.

ITIL equivalent

29
Q

ISO 18788

A

Security Operations Management Systems for security operations

Provides a framework, principles, and requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the management of security

Used to establish a Security Operations Center