PDF p.375
In progress
Standards
Summary
PDF p.375Standards define the expected outcomes of tasks, such as configuration states for servers or performance baselines for services. They are selected based on regulatory requirements, business needs, risk management strategies, industry practices, and stakeholder expectations.
In plain words
Supplementary — not from your PDFStandards define the expected outcome of a task, such as a required server configuration or performance baseline. They're chosen based on regulatory requirements, business needs, risk management strategy, industry practice and stakeholder expectations.
Detailed explanation
PDF p.375-
Regulatory Requirements
- Primary Driver: Legal requirements and security, privacy, and data protection regulations.
- Example: Healthcare providers in the US must comply with HIPAA standards.
-
Business-Specific Needs
- Example: Organizations handling credit card transactions adopt PCI DSS to safeguard cardholder data.
-
Risk Management Strategies
- Purpose: Identify, evaluate, and manage risks.
- Example: ISO/IEC 27001 provides a framework for an information security management system (ISMS).
-
Industry Practices
- Adherence: Demonstrates commitment to high security and data protection levels.
- Example: Cloud-reliant organizations adopt ISO/IEC 27017 and ISO/IEC 27018.
-
Stakeholder Expectations
- Influence: Stakeholders view adherence to standards as a commitment to quality, security, and reliability.
Important terms
taken from the text above- Primary Driver
- Legal requirements and security, privacy, and data protection regulations.
- Adherence
- Demonstrates commitment to high security and data protection levels.
- Influence
- Stakeholders view adherence to standards as a commitment to quality, security, and reliability.
Examples & real-world scenarios
Supplementary — not from your PDF- A required hardening standard for all servers.
- Adopting PCI DSS because the business takes card payments.
- Using ISO/IEC 27001 as a risk management framework.
Scenario
A healthcare provider must meet HIPAA. That regulatory requirement drives the security standards it adopts for handling patient data.
Common mistakes
Supplementary — not from your PDF- Confusing standards (expected outcomes) with policies (rules).
- Adopting standards that don't match the organization's actual obligations.
Practical skills
Supplementary — not from your PDF- Identify what drives an organization's choice of standards.
What I should remember
Key Points PDF p.375- Regulatory Requirements: Legal and security regulations.
- Business Needs: Specific operational requirements.
- Risk Management: Managing security risks.
- Industry Practices: Best practices and standards.
- Stakeholder Expectations: Commitment to quality and security.