Cyberstudy
PDF p.376 In progress Not in the PDF's table of contents

Industry Standards

Open PDF at p.376 14 flashcards

Summary

PDF p.376

Common industry standards include ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018, NIST SP 800-63, PCI DSS, and FIPS. These standards provide benchmarks for evaluating compliance and security practices.

In plain words

Supplementary — not from your PDF

Key industry standards: ISO/IEC 27001 (ISMS framework), 27002 (controls guidance), 27017 (cloud), 27018 (PII in public clouds), NIST SP 800-63 (digital identity), PCI DSS (cardholder data) and FIPS (federal cryptography).

Detailed explanation

PDF p.376
  • ISO/IEC 27001
    • Purpose: Framework for an ISMS.
  • ISO/IEC 27002
    • Purpose: Guidance on specific controls for an ISMS.
  • ISO/IEC 27017
    • Purpose: Specific to cloud services.
  • ISO/IEC 27018
    • Purpose: Protecting PII in public clouds.
  • NIST SP 800-63
    • Purpose: Digital identity guidelines.
  • PCI DSS
    • Purpose: Protecting cardholder data.
  • FIPS
    • Purpose: Cryptography standards for federal systems.

Important terms

taken from the text above
ISO/IEC 27001
ISMS framework.
ISO/IEC 27002
ISMS controls.
ISO/IEC 27017
Cloud services.
ISO/IEC 27018
PII protection.
NIST SP 800-63
Digital identity.
PCI DSS
Cardholder data protection.
FIPS
Cryptography standards.

Examples & real-world scenarios

Supplementary — not from your PDF
  • ISO/IEC 27001 certification for an ISMS.
  • PCI DSS compliance for a payment processor.
  • FIPS-validated cryptography on a federal system.

Scenario

A company moving to the cloud wants recognized guidance. ISO/IEC 27017 (cloud) and 27018 (PII in public clouds) give it cloud-specific standards to follow.

Common mistakes

Supplementary — not from your PDF
  • Mixing up 27001 (the framework) and 27002 (controls guidance).
  • Applying a US federal standard where it isn't relevant.

Practical skills

Supplementary — not from your PDF
  • Match a standard to its purpose.

What I should remember

Key Points PDF p.376
  • ISO/IEC 27001: ISMS framework.
  • ISO/IEC 27002: ISMS controls.
  • ISO/IEC 27017: Cloud services.
  • ISO/IEC 27018: PII protection.
  • NIST SP 800-63: Digital identity.
  • PCI DSS: Cardholder data protection.
  • FIPS: Cryptography standards.