Evolving Security Standards & Practices Flashcards
NIST 1.0 Framework
Identify
Protect
Detect
Respond
Recover
NIST 2.0 Framework
Identify
Protect
Detect
Respond
Recover
Govern
Standard Development Organization in the Chemical Sector
American Chemistry Council
Standard Development Organization in the Petroleum Sector
American Petroleum Institute
Standard Development Organization in the Water & Wastewater Sector
American Water Works Association (AWWS)
Standard Development Organization in the Electric Sector
North American Electric Reliability (NERC)
NERC CIP
IEC
International Electrotechnical Commission
ISA
International Society of Automation
ANSI
American National Standards Institute
NIST
National Institute of Standards & Technology
NESA UAE
UAE Electronic Security Authority
Three European SDO’s
CEN
CENELEC
ETSI
NIST publication for IACS
Special Publication 800-82 Revision 3
ISO 27001:2022
IT - Security techniques - ISMS -requirements
ISO/IEC 21827:2008
IT-Security Techniques - System Security Engineering - Capability Maturity Model (SSE-CMM)
- Standard ending in 2008 does not necessarily mean that standard is outdated.
ISO/IEC 15408:2022
IT - Security Techniques - Evaluation Criteria of IT Security (Common Criteria)
Control Objectives for Information and Related Technology (ISACA)
COBIT 5
CCS CSC
Council on Cyber Security Critical Security Controls.
ISA/IEC 62443-2-1:2009
Requirements for IACSC security Management System (CSMS)
ISA/IEC 62443-3-3:2013
System Security Requirements & Security Levels
Frameworks Core
Frameworks Provide Common Taxonomy and Mechanism
NIST CST Tiers
Tier 1 – Partial
Tier 2 – Risk Informed
Tier 3 – Repeatable
Tier 4 – Adaptive
Characteristics of NIST CSF Tiers
1 - Organizations can use Tiers to shape their cybersecurity profiles, which reflect how they perceive and manage cybersecurity risks.
2 - Tiers range from basic and ad-hoc, reactive approaches to advanced, proactive ones guiding organizations in improving their cybersecurity governance and practices.
3 - Choosing Tiers establishes the organization’s approach to risk management.