Font size
WorksheetsInformation security Management system (ISMS) chapter 1
Total questions: 15
Worksheet time: 8mins
What secure areas ?
To prevent loss, damage, theft or compromise of assets and interruption to the organization’s activities.
To prevent unauthorized physical access, damage, and interference
ensure that information receives an appropriate level of protection
achieve and maintain appropriate protection of organizational assets.
Choose 2 communications and operations management ?
Change management
Operational procedures and responsibilities
System planning and acceptance
Controls against malicious code
Objective network security management ?
To maintain the security of information and software exchanged within an organization and with any external entity.
To prevent unauthorized disclosure; modification, removal or destruction of assets, and interruption to business activities.
To ensure the protection of information in networks and the protection of the supporting infrastructure.
To maintain the integrity and availability of information and information processing facilities.
user access management expect ?
User registration
Privilege management
User password management
Access control policy
Objective application and information access control ?
To prevent unauthorized access to information held in application system.
To prevent unauthorized user access, and compromise or theft of information and information processing facilities.
To prevent unauthorized access to operating systems.
What cryptographic controls ?
ensured by validation tests carried out in the software development cycle.
To protect the confidentiality, authenticity or integrity of information by cryptographic means
To prevent errors, loss, unauthorized modification or misuse of information in applications.
To ensure that security is an integral part of information systems.
Benefits of ISO 27001 ?
Facilitation of trading in trusted environment
A set of tailored policy, standards, procedures and guidelines
Improved customer retention and acquisition
Compatible with other ISO standards
Advantages of ISO 27001 ?
Better knowledge of your company by employees
Reduced liability due to implemented or enforced policies and procedures
Problems are detected more quickly and solutions are improved
Potential lower rates on insurance premiums
Benefits of Certification ?
Improved participation of employees
Ensures management commitment
Drives forward improvement process
Training new employees is much easier
What Information assurance ?
the collection, storage, dissemination, archiving and destruction of information.
achieved only when the information and its systems are protected against attacks by means of the application security.
imbalance between two negotiating parties in their knowledge of relevant factors and details.
misconstrued for being information assurance and vice versa. Both areas of data protection are related, but there are fundamental differences.
How many aspect to achieve information assurance ?
3
6
4
5
Example NON-REPUDIATION ?
Cyptographic System
Amount transacted on the internet
Digital Signature
Credit Card Transaction on the internet
how many Primary element in information assurance ?
2
1
3
4
Primary element in information assurance expect ?
people
technology
operations
security
What INTEGRITY ?
Refer to preventing the disclosure of information to unauthorized individuals or systems.
Maintaining and assuring the accuracy and consistency of data over its entire life cycle.
computing systems used to store and process the information, the security controls used to protect it, and the communication channels used to access it must be functioning correctly.
one party of transaction cannot deny having received a transaction nor can the other party deny having sent a transaction.
