A Framework is
a structure underlying a system, concept, or text.
Purpose of frameworks in IT and cybersecurity is to ____
Provide structure to the ways in which we manage risks, develop enterprise architecture, and secure all our assets.
Four Basic breakdown of Framework
Example of Risk Frameworks
Examples Security Program Framework
Examples of Security Control Framework
Examples of Enterprise Architecture Framework
NIST RMF is described in three core interrelated Special Publications
NIST RMF - 2. Categorize - What is the SP?
NIST SP 800-60 applies sensitivity and criticality to each security objective (CIA) to determine a system’s criticality.
NIST RMF Defines 3 types of security controls, they are_____
NIST RMF 3. Select SP
NIST SP 800-53 R5 Security and Privacy Controls for Information Systems and Organizations
ISO/IEC 27005 outlines 4 ways in which the risk can be treated:
For RMF best results, which 2 ISO should be combined?
ISO/IEC 27005
ISO/IEC 27001
OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation)
Is a RMF or Methodology for Risk Assessment?
It is not a Framework but more of a methodology for risk assessment.
Common Use of OCTAVE is in Public Sector or Private Sector?
Private Sector
OCTAVE Approach focuses on which type of Asset
Most critical assets
80% of the Consequences come from 20% of the causes (Pareto Principle) used in which Risk Assessment Methodology?
OCTAVE
OCTAVE Risk Assessment Methodology is divided into 3 phases:
More Rigorous quantitative approach to manage risk - Proprietary Framework?
FAIR ( Factor Analysis Information Risk)
FAIR - Factor Analysis of Information Risk focus on: Possible Threats or Probable Threats
Probable Threats
Information Security Frameworks can be divided into 2 Categories:
Which ISO standard series serve as industry best practices for the management of security controls in a holistic manner within organizations around the world
ISO/IEC 27000
As you probably realize, ISO_______ is the most important of these standards for the most organization:
ISO 27001
NIST Cybersecurity Framework is divided into three main components: