Security Frameworks Flashcards
CIS
Center for Internet Security
To improve cyber defenses and to develop secure configuration postures
NIST RMF
National Institute of Standards
and Technology Risk
Management Framework
Mandatory for US Federal agencies and organizations that handle federal data
CSF
Cybersecurity Framework
A set of guidelines and best practices for managing and reducing cybersecurity risks across all sectors.
ISO 27001
International Organization
for Standardization 27001
Focuses on information security management.
ISO 27002
International Organization
for Standardization 27002
Provides detailed guidance on information security controls for implementing the controls specified in ISO 27001
ISO 27701
International Organization
for Standardization 27701
Focuses on protecting privacy rights and personal data within the context of an ISMS.
ISO 31000
International Organization
for Standardization 31000
Focuses on risk management in general, not specifically on information security.
SSAE SOC 2 Type I
Service Organization Controls Type I
A standard for auditing security controls
Evaluates controls’ suitability as of a specific date.
SSAE SOC 2 Type II
Service Organization Controls Type II
A standard for auditing for security controls
Tests controls over a period of time, typically six months or more.
Cloud control matrix
Cloud control matrix
Framework developed by the Cloud Security Alliance (CSA)
Focuses on cloud-specific security controls and provides a structured approach to assessing and improving cloud security.
CSA
Cloud Security Alliance
A set of guidelines and best practices for managing and reducing cybersecurity risks across all sectors.