Module 4 ISO/IEC 27k series Flashcards
1
Q
ISO 27799 is what
A
- Health informatics — Information security management in health using ISO/IEC 27002
- By implementing the ISO 27799, healthcare organizations and other
custodians of health information will be able to ensure a minimum
requisite level of security that is appropriate to their organization’s
circumstances and that will maintain the confidentiality, integrity and
availability of personal health information.
2
Q
what sector does ISO 27799 apply to
A
- ISO 27799 applies to health information in all its aspects:
- The purpose is to provide guidance to healthcare organizations and other
holders of personal health information on how to protect such information
via implementation of ISO/IEC 27002.
3
Q
what is ISO 27001
A
- International standard that provides the specification for an Information Security Management System (ISMS)
4
Q
there are 7 objectives/phases for 27001, list them
A
- Context of the organization
- Leadership
- Planning
- Support
- Operation
- Performane Evaluation
- Improvement
5
Q
ISO 27001 primary objectives
A
- The establishment and implementation of an organization’s information security management system is influenced by the organization’s needs
and objectives, security requirements, the organizational processes used and the size and structure of the organization. - It is important that the information security management system is part of and integrated with the organization’s processes and overall management structure and that information security is considered in the design of processes, information systems, and controls.
6
Q
what does a properly implemented ISMS accomplisy
A
- An Information SecurityManagement System(ISMS) preserves the confidentiality, integrity, and availability of information by applying a risk
management process and gives confidence to interested parties that risks
are adequately managed.
7
Q
ISO 27001- what is in the support phase/objective
A
- Resources
- competence
- Awareness
- communications
- Documented information
8
Q
what was ISO 27002 created for
A
- Reference for determining and implementing controls for information security risk treatment in an ISMS based on ISO/IEC 27001.
- Guidance document for organizations determining and implementing commonly accepted information security controls
9
Q
what are ISO 27002 controls
A
- People
- Organization
- Technology
- Physical
10
Q
some examples of ISO 27002 People controls
A
- Screening
- Terms and conditions of employment
- Information security awareness, education and training
- Disciplinary process
11
Q
some examples of ISO 27002 Physical controls
A
- Physical security perimeters
- Physical entry
- Securing offices, rooms and facilities
- Physical security monitoring
- Protecting against physical and environmental threats
12
Q
some examples of ISO 27002 Technology controls
A
- Data leakage prevention
- Information backup
- Redundancy of information processing facilities
- User endpoint devices
- Privileged access rights
- Information access restriction
- Access to source code
- Secure authentication
- Capacity management
- Protection against malware
- Management of technical vulnerabilities
- Configuration management
- Segregation of networks
- Web filtering
- Use of cryptography
- Secure development life cycle