WorksheetsAssessment # 1- Information Assurance and Security 1
Total questions: 15
Worksheet time: 8mins
It is a series of international standards developed by the International Organization for Standardization (ISO) that focus on information security management systems (ISMS) and address various aspects of information security
ISO 27000 to ISO 27036
ISO 27001: Information Security Management Systems - Requirements
ISO 27002: Code of Practice for Information Security Controls
ISO 27003: Information Security Management System Implementation Guidance
This is the core standard for establishing, implementing, maintaining, and continuously improving an ISMS within an organization.
ISO 27000 to ISO 27036
ISO 27001: Information Security Management Systems - Requirements
ISO 27002: Code of Practice for Information Security Controls
ISO 27003: Information Security Management System Implementation Guidance
It covers various areas of information security, including organizational security, asset management, human resource security, physical and environmental security, and more.
ISO 27000 to ISO 27036
ISO 27001: Information Security Management Systems - Requirements
ISO 27002: Code of Practice for Information Security Controls
ISO 27003: Information Security Management System Implementation Guidance
It provides practical advice on the various phases of ISMS implementation, including planning, establishing, operating, monitoring, reviewing, maintaining, and improving the system.
ISO 27000 to ISO 27036
ISO 27001: Information Security Management Systems - Requirements
ISO 27002: Code of Practice for Information Security Controls
ISO 27003: Information Security Management System Implementation Guidance
It provides guidance on defining metrics, establishing measurement processes, and reporting on the status and performance of the ISMS.
ISO 27004: Information Security Management - Measurement
ISO 27001: Information Security Management Systems - Requirements
ISO 27002: Code of Practice for Information Security Controls
ISO 27003: Information Security Management System Implementation Guidance
It provides guidance on how to identify, assess, and treat information security risks within the context of an organization's overall risk management framework.
ISO 27004: Information Security Management - Measurement
ISO 27005: Information Security Risk Management:
ISO 27002: Code of Practice for Information Security Controls
ISO 27003: Information Security Management System Implementation Guidance
This standard sets out the requirements for bodies providing certification of an organization's compliance with ISO 27001.
ISO 27004: Information Security Management - Measurement
ISO 27005: Information Security Risk Management:
ISO 27002: Code of Practice for Information Security Controls
ISO 27006: Requirements for the Accreditation of Certification Bodies:
It outlines the principles and processes of auditing and provides recommendations for audit programs and the competence of auditors.
ISO 27007: Guidelines for Information Security Management Systems Auditing
ISO 27005: Information Security Risk Management:
ISO 27002: Code of Practice for Information Security Controls
ISO 27006: Requirements for the Accreditation of Certification Bodies:
This standard offers specific guidance for cloud service providers and cloud customers on implementing information security controls within cloud computing environments.
ISO 27007: Guidelines for Information Security Management Systems Auditing
ISO 27005: Information Security Risk Management:
ISO 27017: Code of Practice for Information Security Controls for Cloud Services
ISO 27006: Requirements for the Accreditation of Certification Bodies:
It provides guidelines for cloud service providers in handling PII and gives customers assurance about the protection of their personal data.
ISO 27007: Guidelines for Information Security Management Systems Auditing
ISO 27018: Code of Practice for Protection of Personally Identifiable Information (PII) in Public Clouds:
ISO 27017: Code of Practice for Information Security Controls for Cloud Services
ISO 27006: Requirements for the Accreditation of Certification Bodies:
ISO 27031: Guidelines for Information and Communication Technology (ICT) Readiness for Business Continuity.
It covers aspects such as risk assessment, business impact analysis, development of continuity plans, and testing and exercising of ICT systems.
This standard focuses on the protection of personally identifiable information (PII) within public cloud computing environments.
This standard offers guidance on improving the state of cybersecurity by addressing the risks and challenges posed by cyberspace.
This standard focuses on monitoring, measurement, analysis, and evaluation of the effectiveness and performance of an ISMS.
ISO 27032: Guidelines for Cybersecurity.
It covers aspects such as risk assessment, business impact analysis, development of continuity plans, and testing and exercising of ICT systems.
This standard focuses on the protection of personally identifiable information (PII) within public cloud computing environments.
This standard offers guidance on improving the state of cybersecurity by addressing the risks and challenges posed by cyberspace.
This standard focuses on monitoring, measurement, analysis, and evaluation of the effectiveness and performance of an ISMS.
It is an independent, not-for-profit organization based in Europe that develops standards for information and communication technologies (ICT) including telecommunications, broadcasting, and other electronic communications networks and services.
ETSI
ISO 27018
ISO 27031
ISO 27032
It outlines the policies, strategies, and actions necessary to enhance cybersecurity capabilities, prevent cyber threats, and respond effectively to incidents.
ETSI
ISO 27018
NCP
ISO 27032
What is NIST stand for?
National Institute of Standards and Technology
National Instituto of Standards and Technologies
National Institute of Standard and Technologies
National Institute of Standards and Technologized
