ISM First Half Flashcards
(63 cards)
What is Information Security Management
Defines + manages controls that an organisation implements to protect confidentiality, availability and integrity of assets from threats
What is an Information Security Management System
Procedure for managing information security
Name some ISO standards
IS0 27000, 27001, 27002
What is an asset in ISM
Anything with value to an organisation
What is a threat in ISM
Potential cause of an unwanted incident
What is a vulnerability in ISM
Weakness of an asset or control that can be exploited
What is a risk in ISM
Effect of uncretainty on objectives
What is impact in ISM
Result of an incident
What are security controls in Information security management?
Activites that are taken to manage risks
Name the four purposes of security controls (ERTA)
Eliminate, Reduce, Transfer, Accept
What is identity in ISM?
Information that distinguishes one entity from another.
What is authentication in ISM?
Assurance of an entities’ identity
What is authorisation in ISM?
Permission granted to an entity to access a resource
What is accountability in ISM?
Ensures actions of an entity can be traced
What is an audit in ISM?
Review of a party’s ability to meet approval agreements
What is compliance in ISM?
Meeting requirements of a standard.
What is an ISMS?
Information Security Management System
How is an ISMS implemented?
Socio-technical system, staff via training, ongoing evaluation
What is the ISO27001?
Contains requirements for establishing, implementing, maintaining and improving an ISMS
How does the ISO27001 protect information?
Focused on information assets. Protects people, then facilities, then business activity, then information technology.
What is ISO27001 driven by?
Security Risk Management.
Outline the process of continuous security improvement.
Leadership - Planning - Support - Operation - Performance - Improvement
What is the ISO 27002?
List of Security Controls
What is the ISO27004
Evaluates security performance and effectiveness.