0% found this document useful (0 votes)
9 views2 pages

Data Security Controls Frameworks Overview

Uploaded by

hb7
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views2 pages

Data Security Controls Frameworks Overview

Uploaded by

hb7
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

In this lesson, we began looking at data security controls by exploring the various security frameworks available and

how to use them.

Privatization should use controls to reduce and manage risk at reasonable levels acceptable to management.

This includes ensuring the costs of the controls do not exceed the cost of the risks.

Each organization should adopt one of the security frameworks available from various sources.

Using a framework ensures that the same approach one that follows best practices, is used to provide security across all
organizational elements.

Frameworks also have security teams to efficiently use existing resources and security budget dollars where they're
needed most.

Finally, frameworks help security teams and managers to create metrics to measure the effectiveness of implemented
controls.

Frameworks helped to manage risk by providing best practices for identifying, detecting, responding and recovering
from cyber attacks.

They also helped prevent those attacks from happening in the first place.

The ISO 27,001, 27,002 and 27,018 are a family of international standards that formalize risk management across
people, processes and technology.

The standards are available for fee. The U.S. National Institute of Standards and Technology, or NYSC, creates
standards for use by federal agencies.

They're also freely available to all organizations.

This special publications 853 and 853 A supported by Nest esp 800 Dash 37 provide guidance for incident response,

access controls, disaster recovery, and general business continuity.

The Center for Strategic and International Studies, or CCS, provides guidance for implementing 20 critical controls.

The systems considers these controls as the minimum needed to effectively manage risk.

All 20 are technical controls that focus on high risk cyberattacks.

They are a subset of newest framework controls.

This set of controls is a good start for new networks, for protection during initial risk assessments and full security
control implementation.

This like is COVID is a business framework for the governance and management of enterprise I.T.

It's used as the standard for third party audits by the major accounting firms.

It provides detailed guidance over four domains plan and organize, acquire and implement delivery and support and
monitor and evaluate.

[Link] 3:54:32 PM]


If your organization is subject to Sarbanes-Oxley audits, you are very likely to be audited in accordance with the
corporate framework.

The U.S. Federal Information Security Monitor Resolution Act or physical provides the Department of

Homeland Security with the authority to administer information security policies for federal agencies.

Policies are based on the FIPS 200 and the listed newest special publications.

Any organization that provides or manages information resources to the U.S.

government should be aware of and compliant with Fisman Policies and procedures.

Kozo, the committee of Sponsoring organizations of the Treadway Commission, emerged from financial industry
efforts.

It provides guidance for integrating risk management and business operation across five components governance and
culture,

strategy and objective setting performance review and revision and information.

Communication and reporting. Fedramp is a U.S. government program that provides standardized approaches to
security assessments,

authorization and cloud product and service monitoring.

The U.S. Department of Defense Instruction 8510 DOD zero one is a risk management framework that applies to all
D.O.D. information technology.

The Australian Government Information Security Manual is intended for use by specified government agencies.

It provides standards and guidelines for the risk based application of information security controls.

The Australian Government also encourages all other agencies and commercial organizations to also follow the ESM.

This is similar to the U.S. Government recommending that all public and private agencies

use news and other government standards and guidelines for information security.

The information and communication technology. Cyber security certification was developed by the EU Commission.

It provides a certification framework intended to establish acceptable levels of trust for products and services crucial for
the digital marketplace.

It relies on integration with multiple international standards.

Released in 2018, the new cybersecurity framework is likely the most widely used.

It is a collaboration between industry and government that enables an organization to develop the security program
around standards,

guidelines and practices. Documents and tools for implementation can be found at the links shown.

[Link] 3:54:32 PM]

You might also like