Lead Auditor 27001 Flashcards
(236 cards)
Information is what kind of asset?
Strategic
Property of accuracy and completeness. CIA triad
Integrity
CIA Triad
Confidential
Integrity
Availability
A hacker compromising a message someone sends to another is what CIA?
Integrity, accuracy of message was corrupted
When someone sends a message and they can no longer claim they didn’t is what?
Non repudiation
Property is the entity it claims to be
Authenticity
Example of authentic and non repudiation
Digital signature
Use a framework of resources to achieve an organization’s objectives
Management systems
Management system components
Quality management
Scope
Organization
Process
Policies
Records
PDCA cycle
In the quality management:
Plan
Do
Check
Act
Management system used to ensure the information security of its information assets
ISMS
In sec man sys
Item of value to an org is a primary asset
False, information asset
Primary is business process
Stand. That specifies requirements for estáb implementation and manage. And continual improving of ISMS
ISO 27001
Catalog of security and privacy controls for all U.S. federal information systems
Nist 800-53
Framework for governance and manage of enterprise IT
Cobit 2019
Only normative standards like 27001 can be audited
True
Nist framework is what 5?
Identify
Protect
Detect
Respond
Recover
6th is governance
Standard that contains guidelines for implementing security controls
27002
Clause 7.5
Documented information
Which clause requires org to include documented information in the ISMS as directly required by 27001 and org for effectiveness of the ISMS
7.5
Documentation life cycle
Créate
Store
Use
Archive
Dispose
12 step method
Management support
Scope of ISMS
Gap Analysis
Information security policy
Competence assurance
Asset inventory
Risk management methodology
Risk assessment
Risk treatment
Performance evaluation
Improvement
Certification audit