Module 1 - The Basics Flashcards
The Basics
Name nine drivers for implementing ISO 27001
Client confidence
Avoid breaches and fines
Improve company culture
Secure information in all its forms
Manage information securely consistently
Protect the CIA of your data
Increase attack resilience
Respond to evolving threats
Reduce costs associated with info sec
What year was the current ISO 27001 and 27002 standards updated?
2022
What year was the previous ISO 27001 standard updated?
2013
How many themes and controls are in ISO 27001:2022?
4 themes and 93 controls
How many new controls were added in ISO 27001:2022?
11 new controls
How long was the transition period between ISO 27001:2013 and ISO 27001:2022?
3 years
What is a standard?
Specification that something can conform to, approved by a recognised body
What does a standard achieve?
Standards provide a reliable basis to review expectations about a product or service
Name the 6 Stages an ISO Standard goes through in order?
Mnem: Nutty …
- New standard / Revision
- WD – Working Draft
- CD – Committee Draft
- DIS – Enquiry Draft International Stage
- FDIS – Final Draft International Standard
- IS – International Standard adopted
Nutty Witches Chose Dry Figs Impressively
What are the 5 types of stages an ISO standard goes through?
Mnem: Px-xxx
- Prepatory Stage
- Committee Stage
- Enquiry Stage
- Approval Stage
- Publication Stage
PC-EAP
What does ISO stand for?
International Organisation of Standardisation
What does IEC stand for?
International Electrotechnical Commission
How does ISO decide what gets published?
Committee vote
Through what means do ISO and IEC collaborate?
JTC – Joint Technical Committee
What does JTC stand for?
Joint Technical Committee, this is the means for collaboration between ISO and IEC
What is the purpose of ISO?
To write International Standards
What do ISO use as input for early standard drafts?
ISO take National Standards as input for first drafts of International Standards
How long does it typically take for an ISO Standard to progress from WD to CD?
Usually around 3 years
What are the 10 Sections of the ISO 27001 Standard?
Sxx-xxx-xxxx
- Scope
- Normal References
- Terms and Definitions
- Context of the Organisation
- Leadership
- Planning
- Support
- Operation
- Performance Evaluation
- Improvement
SNT-CLP-SOPI
Sent-Clip-Soppy
What are the 9 ISMS Principles detailed for ISO 27000:2018 series?
Axx-xxxx-xx
- Awareness
- assignment of Responsibility
- incorporating management/stakeholder Commitment
- enhancing Societal values
- controls Proportional to risks
- security as an Essential element of networks and systems
- active prevention and Detection of incidents
- Comprehensive approach to information security management
- continual reassessment and Improvement
ARC-SPED-CI
Arc-Sped-Sea