Cyberstudy
PDF p.375 In progress

Standards

Open PDF at p.375 9 flashcards

Summary

PDF p.375

Standards define the expected outcomes of tasks, such as configuration states for servers or performance baselines for services. They are selected based on regulatory requirements, business needs, risk management strategies, industry practices, and stakeholder expectations.

In plain words

Supplementary — not from your PDF

Standards define the expected outcome of a task, such as a required server configuration or performance baseline. They're chosen based on regulatory requirements, business needs, risk management strategy, industry practice and stakeholder expectations.

Detailed explanation

PDF p.375
  • Regulatory Requirements
    • Primary Driver: Legal requirements and security, privacy, and data protection regulations.
    • Example: Healthcare providers in the US must comply with HIPAA standards.
  • Business-Specific Needs
    • Example: Organizations handling credit card transactions adopt PCI DSS to safeguard cardholder data.
  • Risk Management Strategies
    • Purpose: Identify, evaluate, and manage risks.
    • Example: ISO/IEC 27001 provides a framework for an information security management system (ISMS).
  • Industry Practices
    • Adherence: Demonstrates commitment to high security and data protection levels.
    • Example: Cloud-reliant organizations adopt ISO/IEC 27017 and ISO/IEC 27018.
  • Stakeholder Expectations
    • Influence: Stakeholders view adherence to standards as a commitment to quality, security, and reliability.

Important terms

taken from the text above
Primary Driver
Legal requirements and security, privacy, and data protection regulations.
Adherence
Demonstrates commitment to high security and data protection levels.
Influence
Stakeholders view adherence to standards as a commitment to quality, security, and reliability.

Examples & real-world scenarios

Supplementary — not from your PDF
  • A required hardening standard for all servers.
  • Adopting PCI DSS because the business takes card payments.
  • Using ISO/IEC 27001 as a risk management framework.

Scenario

A healthcare provider must meet HIPAA. That regulatory requirement drives the security standards it adopts for handling patient data.

Common mistakes

Supplementary — not from your PDF
  • Confusing standards (expected outcomes) with policies (rules).
  • Adopting standards that don't match the organization's actual obligations.

Practical skills

Supplementary — not from your PDF
  • Identify what drives an organization's choice of standards.

What I should remember

Key Points PDF p.375
  • Regulatory Requirements: Legal and security regulations.
  • Business Needs: Specific operational requirements.
  • Risk Management: Managing security risks.
  • Industry Practices: Best practices and standards.
  • Stakeholder Expectations: Commitment to quality and security.