Understanding Concepts Flashcards
Risk frameworks
Address the “why” they guide strategic decision making about risk
Security control frameworks
Address the how providing specific controls to mitigate cybersecurity risk
NIST Risk Management Framework also known as RMF
Audience is federal government agencies. The RMF is mandatory for those to which it applies.
NIST Cybersecurity Framework also known as CSF
Is aimed at private(commercial) business. The CSF is purely Optional guidance from NIST
ISO/IEC 27001:2022
Outlines a framework for implementing maintaining and continually improving an Information Security Management System(ISMS)
Information Security Management System(ISMS)
Is a set of policies, processes, and controls that helps organizations protect their information assets.
ISO/IEC 27001:2022 guides organizations in
Identifying information assets and assessing their value and information security risks AND
Implementing mitigating security controls(based on ISO 27002)
Regularly monitoring and measuring effectiveness of and continuously improving ISMS
basically focuses more on the What and Why
ISO/IEC 27002:2022
Offers best practices and control objectives related to key aspects of cybersecurity in support of ISO/IEC 27001.
ISO/IEC 27002:2002 focus areas
Includes access control, cryptography, human resource security, operational security, and incident response
Serves as a practical blueprint for organizational aiming to effectively safeguard their information assets against cyber threats
basically brings practical guidance on how
Privacy vs Confidentiality
Privacy focus on the right of the individual person/customer
Confidentiality focuses on data