Module 3 Flashcards
is a critical process used across industries to identify, evaluate, and mitigate potential risk that could impact business operations, safety, and compliance.
Risk Assessment
Common Risk Assessment Methodologies
- Qualitative Risk assessment
- Quantitative Risk Assessment (QRA)
- Failure Modes and Effects Analysis
- Hazzard and Operability Study(HAZOP)
- Bowtie Analysis
A set of rules and procedures to protect organizational assets.
Security Policies
Established guidelines and frameworks to ensure consistent security measures.
Security Standards
Reduces the likelihood of security breaches
Risk Mitigation
Ensures adherence to legal regulations
Compliance
Builds confidence among stakeholders, clients, and employees.
Trust
Facilitates efficient response and recovery from security incidents.
Incident Management
Key Elements of Security Policies
- Access Control
- Data Protection
- Acceptable Use
- Incident Response
- Training and Awareness
- Compliance Monitoring
Types of Security Standards
- ISO 27001
- NIST (National Institute of Standards and Technology)
- PCI DSS
- CIS (Center for Internet Security)
International Standard for Information security management systems (ISMS)
ISO 27001
Cyber security Frameworks (CSF) for managing and reducing risks
NIST (NATIONAL INSTITUTE of Standards Technology)
Payment Card Industry Data Security Standard for payment data protection
PCI DSS
Critical Security controls and benchmarks
CIS (Center for Internet Security)
it refers to the framework, policies, and process established to ensure the organization’s security objectives align with business goals.
Information Security Governance
Steps to Establish Effective Governance
- Assess Current State
- Define Objectives
- Develop Policies
- Implement Frameworks
- Monitor and Improve
laws in Information Security
- Protect sensitive data and privacy
- Prevent Cybercrime
- Ensure business continuity
- Build trust with stakeholders
Consequences of Non-compliance
- Financial Penalties
- Legal actions and lawsuits
- Reputational Damage
- Operational disruptions