Section 2 Standards and regulatory frameworks Flashcards
ISO/IEC 27005
pertains to?
guidance on?
Information Security, cybersecurity and privacy protection - Guidance on managing information security risk.
ISO/IEC 31000:2018
- This standard provides GUIDELINES for managing risk face by organizations in ANY industry or sector
- Applicable to ANY type of risk
- Org. cannot obtain this certification
What is ISO?
International Organization for Standardization
Published as International Standards
ISO/IEC 27005
Guidlines for managing information security risks, in accordance with the requirements of ISO/IEC 27001.
ISO/IEC 27001
Specifies requirements for ISMS
Requirements for establishing, implementing, maintaining, and continuall
ISO/IEC 27000
General Overview of ISMS
Terms and Definition for ISMS
BS 7799
Establish?
Government of?
- Establish and Implement ISMS
- UK government
- Department of Trade and Industry (DTI)
27001
verb?
can organizationobtain this certification?
- “shall”
- all organization (type, size, industry)
- can obtain certification
How do you preserve the CIA of Information?
ISMS preserves CIA by applying Risk Management
ISO/IEC 27005
Complying to?
expressed with the verb?
Can organizations obtain this certification?
- Complying to 27001
- Guidlines for conducting Information Security Risk Management
- verb “should”
- Orgnizations cannot obtain certification against this standard
How many clauses and Annex?
ISO/IEC 27005
- 10 clauses
- Annex A
- Clauses 1- 4: general information on standrad
- Clause 5: introduces the information security risk management process and cycle
- Clause 6 to 10: elaborates information security risk management activities
- Annex A: examples for RA process
Risk Management Activities
outlined in clause 7-10
Input
Action
Trigger
Output
Guidance
Input
Action
Trigger
Output
Guidance
Input - Identification of requirements to perform the activity
Action - describes the activity
Trigger - guidance on when to start
Output - information after performing the activity
Guidance - guidnace on performing the activity, keyword and key concept
ISO 31000
what is ISO 31000?
applicable to what risk?
organization can be certified with ISO 31000?
- guidelines for managing risk
- applicable to any type of risk, regardless of its nature or consiquences
- Organization? No
Purpose of RMF?
Assist orgnization in integrating Risk Management