ISO Flashcards

1
Q

ISO17788

A

Cloud computing, overview, and vocabulary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO2237

A

7 part series on physical environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISO27000

A

Overview and glossary (make sense since, first section, u know ZERO about this yet)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO27001

A

Formal ISMS specification, security governance - how to manage information security; standards to which to certify.

(This is the first real section, high level);
ISMS = information Security Management System;

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISO27002

A

Infosec controls guideline; Best practice guideline; how to do 27001

Infosec Controls (Think control switch, has 2 positions), GUIDELINES (guide someone, you need to coordinate that requires 2)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISO27003

A

ISMS Implementation (think how to 1-2-3 steps)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ISO27004

A

Infosec measurements [metrics] (think 4 as four quadrants)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ISO27005

A

Infosec risk management (Poker is risky, you play with 5 cards)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

ISO27006

A

ISMS certification & audit guide (ssssertication - pronounce the 6)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ISO27007

A

Management system Audit (lucky 7 if you pass the audit)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

ISO27009

A

Information security, cybersecurity, and privacy protection — Sector-specific application of ISO/IEC 27001

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

ISO27010

A

Critical infrastructure (“10” is critical)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

IS027011

A

Telecommunication (11 = antenna)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ISO27014

A

guidance on concepts and principles for the Governance of information security (make it consistent and standardized, measurable, comprehensive, and modular)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

IS027015

A

Financial (5 looks like $ dollar)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ISO27017

A

Security guidelines, control for cloud (based on ISO/IEC 27002)

17
Q

ISO27018

A

PII for cloud

18
Q

ISO27034

A

Application security
ONF or Organizational Normative Framework
ANF or Application Normative Framework

19
Q

ISO27036

A

Supply chain security

20
Q

ISO27050

A

Digital forensic, along with 27037, 27041, 27042, 27043

21
Q

IS027099

A

Information Technology — Public key infrastructure — Practices and policy framework

22
Q

ISO28000

A

Supply chain (and other 2800*)

23
Q

ISO31000

A

Risk management framework

24
Q

ISO 15408

A

Common Criteria