ISO Standards for Security Flashcards

Learn which ISO standards are relevant to the CISSP Exam

1
Q

ISO 27001

A

ISMS

ISO 27001 (formally known as ISO/IEC 27001:2005) is a specification for an information security management system (ISMS). An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation’s information risk management processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO 27002

A

Information technology – Security techniques – Code of practice for information security controls.

ISO/IEC 27002:2005. This second standard describes a comprehensive set of information security control objectives and a set of generally accepted good practice security controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISO 27005

A

IT Risk Management

ISO/IEC 27005:2018 provides guidelines for information security risk management and supports the general concepts specified in ISO 27001. Last updated in 2011, this standard is designed to assist the implementation of an ISMS based on a risk management approach. In order to gain a complete understanding of ISO/IEC 27005:2018, managers and directors first need to have a knowledge of the concepts, models, processes and terminologies described in ISO 27001 and ISO 27002.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO 22301

A

Business continuity management

ISO 22301 Societal security – Business continuity management systems – Requirements is a management system standard that specifies requirements to plan, establish, implement, operate, monitor, review, maintain and continually improve a documented management system to protect against, reduce the likelihood of occurrence, prepare for, respond to, and recover from disruptive incidents when they arise. It is intended to be applicable to all organizations, or parts thereof, regardless of type, size and nature of the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISO 27031

A

IT Continuity (DRP)

ISO/IEC 27031:2011 - Information technology — Security techniques — Guidelines for information and communications technology readiness for business continuity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISO 15408

A

Common Criteria

The Common Criteria for Information Technology Security Evaluation (referred to as Common Criteria or CC) is an international standard (ISO/IEC 15408) for computer security certification. It is currently in version 3.1 revision 5.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ISO 7498-1

A

OSI Model

Information technology - Open Systems
Interconnection - Basic Reference Model:
The Basic Model

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ISO 17025

A

Forensics

ISO/IEC 17025 General requirements for the competence of testing and calibration laboratories is the main ISO standard used by testing and calibration laboratories.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

ISO 90003

A

Software engineering

ISO/IEC 90003 Software engineering – Guidelines for the application of ISO 9001:2008 to computer software is a guidelines developed for organizations in the application of ISO 9001 to the acquisition, supply, development, operation and maintenance of computer software and related support services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ISO 31000

A

Risk Management Framework and Guidelines

ISO 31000 is a family of standards relating to risk management codified by the International Organization for Standardization. The purpose of ISO 31000:2009 is to provide principles and generic guidelines on risk management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly