Section 2 Standards and regulatory frameworks Flashcards

1
Q

ISO/IEC 27005

pertains to?
guidance on?

A

Information Security, cybersecurity and privacy protection - Guidance on managing information security risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO/IEC 31000:2018

A
  • This standard provides GUIDELINES for managing risk face by organizations in ANY industry or sector
  • Applicable to ANY type of risk
  • Org. cannot obtain this certification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is ISO?

A

International Organization for Standardization

Published as International Standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO/IEC 27005

A

Guidlines for managing information security risks, in accordance with the requirements of ISO/IEC 27001.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISO/IEC 27001

A

Specifies requirements for ISMS

Requirements for establishing, implementing, maintaining, and continuall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISO/IEC 27000

A

General Overview of ISMS
Terms and Definition for ISMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

BS 7799

Establish?
Government of?

A
  • Establish and Implement ISMS
  • UK government
  • Department of Trade and Industry (DTI)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

27001

verb?
can organizationobtain this certification?

A
  • “shall”
  • all organization (type, size, industry)
  • can obtain certification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How do you preserve the CIA of Information?

A

ISMS preserves CIA by applying Risk Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ISO/IEC 27005

Complying to?
expressed with the verb?
Can organizations obtain this certification?

A
  • Complying to 27001
  • Guidlines for conducting Information Security Risk Management
  • verb “should”
  • Orgnizations cannot obtain certification against this standard
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How many clauses and Annex?
ISO/IEC 27005

A
  • 10 clauses
  • Annex A
  • Clauses 1- 4: general information on standrad
  • Clause 5: introduces the information security risk management process and cycle
  • Clause 6 to 10: elaborates information security risk management activities
  • Annex A: examples for RA process
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk Management Activities
outlined in clause 7-10

A

Input
Action
Trigger
Output
Guidance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Input
Action
Trigger
Output
Guidance

A

Input - Identification of requirements to perform the activity
Action - describes the activity
Trigger - guidance on when to start
Output - information after performing the activity
Guidance - guidnace on performing the activity, keyword and key concept

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ISO 31000

what is ISO 31000?
applicable to what risk?
organization can be certified with ISO 31000?

A
  • guidelines for managing risk
  • applicable to any type of risk, regardless of its nature or consiquences
  • Organization? No
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Purpose of RMF?

A

Assist orgnization in integrating Risk Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

IEC 31010

What is IEC 31010?
Can organization obtain this?

A
  • Selection and Application of techniques in assessing risk
  • Organizations cannot obtain this
17
Q

Relationship of ISO/IEC 27005 and ISO 31000

A
  • 27005 - Framework on Risk Management applied to Information Security
  • 31000 - Generic Framework
18
Q

Purpose of Risk Management

A

creation and protection of value