Industry Standards
Summary
PDF p.376Common industry standards include ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018, NIST SP 800-63, PCI DSS, and FIPS. These standards provide benchmarks for evaluating compliance and security practices.
In plain words
Supplementary — not from your PDFKey industry standards: ISO/IEC 27001 (ISMS framework), 27002 (controls guidance), 27017 (cloud), 27018 (PII in public clouds), NIST SP 800-63 (digital identity), PCI DSS (cardholder data) and FIPS (federal cryptography).
Detailed explanation
PDF p.376-
ISO/IEC 27001
- Purpose: Framework for an ISMS.
-
ISO/IEC 27002
- Purpose: Guidance on specific controls for an ISMS.
-
ISO/IEC 27017
- Purpose: Specific to cloud services.
-
ISO/IEC 27018
- Purpose: Protecting PII in public clouds.
-
NIST SP 800-63
- Purpose: Digital identity guidelines.
-
PCI DSS
- Purpose: Protecting cardholder data.
-
FIPS
- Purpose: Cryptography standards for federal systems.
Important terms
taken from the text above- ISO/IEC 27001
- ISMS framework.
- ISO/IEC 27002
- ISMS controls.
- ISO/IEC 27017
- Cloud services.
- ISO/IEC 27018
- PII protection.
- NIST SP 800-63
- Digital identity.
- PCI DSS
- Cardholder data protection.
- FIPS
- Cryptography standards.
Examples & real-world scenarios
Supplementary — not from your PDF- ISO/IEC 27001 certification for an ISMS.
- PCI DSS compliance for a payment processor.
- FIPS-validated cryptography on a federal system.
Scenario
A company moving to the cloud wants recognized guidance. ISO/IEC 27017 (cloud) and 27018 (PII in public clouds) give it cloud-specific standards to follow.
Common mistakes
Supplementary — not from your PDF- Mixing up 27001 (the framework) and 27002 (controls guidance).
- Applying a US federal standard where it isn't relevant.
Practical skills
Supplementary — not from your PDF- Match a standard to its purpose.
What I should remember
Key Points PDF p.376- ISO/IEC 27001: ISMS framework.
- ISO/IEC 27002: ISMS controls.
- ISO/IEC 27017: Cloud services.
- ISO/IEC 27018: PII protection.
- NIST SP 800-63: Digital identity.
- PCI DSS: Cardholder data protection.
- FIPS: Cryptography standards.