Security Management Flashcards

1
Q

what ISO27K series is about

A

En serie med informasjonssikkerhets-standarder som kombineres for å oppnå a globally recognised framework for best-practice information security management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Title and purpose of ISO27001 standard

A

Title: Information Security Management System (ISMS)

purpose: ISO 27001 specifies requirements for establishing,
implementing, maintaining and continually improving an
information security management system (ISMS) within the context of the organization.

While the ISO 27002 (code of practice) defines a set of
security goals and controls, ISO 27001 (ISMS) defines
how to manage the implementation of security controls.
• Organizations can be certified against ISO 27001

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Title and purpose of ISO27002 standard

A

Title Code of practice for information security controls

Pupose:
• ISO 27002 provides a checklist of general security controls to be considered implemented/used in organizations
– Contains 14 categories (control objectives) of security controls and each category contains a set of security controls

• Not all controls are relevant to every organisation

• Objective of ISO 27002:
“gives guidelines for information security management practices including the selection,
implementation and management of controls taking into consideration the organization’s information security risk environment(s).”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Elements of ISMS (cycle)

A

Stegene er utført parallelt

  1. Planning
  2. Risk Assessment
  3. Security controls
  4. Evaluation
  5. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The security management levels

A

Dette er et hierarki som består av (på bunn) IT security Operations: Drift/admin av informasjonssikkerhet. (I midten) Information Security Management: Ledelse av informasjonssikkerhet
(Internkontroll). Og (på topp) Information Security Governance:
Styring av informasjonssikkerhet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly