W12
Topic Pick one of the many information security standards organizations and describe what they do and what type of standards they are responsible for.
Read and respond to below two student’s discussions. (150 words for each response) reflecting on your own experience, challenging assumptions, pointing out something new you learned, offering suggestions
#1. Posted by Anusha
NIST cybersecurity is one of the information Security standards Which has been designed for individual businesses and various organisation to assess various with their face. It is a Framework which has been divided into three parts Core, profile and tiers. In the Framework code, it contains various activities its outcomes and various references about various approaches and aspects to cybersecurity. In the Framework implementation Tier, it is used by the organisation to understand and clarify for itself and their partner is about the various views of threats and the intensity of the sophistication in their management approach. In the Framework profile, there is a list of various outcomes that any organisation has to choose from their categories and subcategories related to their needs and risk assessment. It has been seen that a study has been conducted related to security framework and option various organisation which suggest NIST Framework is one of the r best practice for computer security (Sauls & Gudigantala, 2019).
NST information security standard provides a higher level taxonomy to various cybersecurity outcomes as well as a methodology which will help the organisation to access and manage those outcomes. NIST Information security standard organised its various Core material into five functions which have been divided into 23 categories for each category. It has a specific number of cybersecurity outcomes and security controls. There are many functions and categories, which does have unique identifiers and definitions (Medina-Smith, Miller & Wick, 2018).
Identify: it is used to develop a better understanding, which will help the organisation to manage cybersecurity risk to their system, assets, capabilities and data.
Protect: NIST helps to develop and implement various safeguards, which are appropriate for the organisation to ensure better delivery of critical infrastructure services.
Detect: in NIST it develop and implement various activities which are appropriate for the organisation to identify the opposites of any cybersecurity event.
Respond: Develop and implement proper activities, which are appropriate for the organisation is to take action related to any detected cybersecurity event.
#2. Posted by Ashok
The information security organization about which I am going to talk is Centre for Internet Security. It is a 501.c non-profit organization which is focussed on enhancing the cyber security readiness and response of public and private sector entities with the commitment to excellence through collaboration. CIS provides resources that help partners achieve security goals through expert guidance and cost effective solutions.
The below are the standards of many of the organizations like this. ISO/IEC 27001, part of the growing ISO/IEC 27000 family of standards, is an information security management system (ISMS) standard, of which the last revision was published in October 2013 by the International Organization for Standardization (ISO) and the International Electro technical Commission (IEC).
ISO/IEC 27001 formally specifies a management system that is intended to bring information security under explicit management control.