ISO 27001 and 27002 Basic Summary - CISSP - Security and Risk Management

preview_player
Показать описание
------------------------------------------------------------------------------------------------------
Security and Risk Management - ISO - 27001 and ISO - 27002 Quick Summary
--------------------------------------------------------------------------------------------------------

***I Am NOT An Expert! ***

As a method of studying for the CISSP, I am attempting to briefly explain the concepts I am learning in an an effort to help me, and perhaps fellow students.

Please take everything with a grain of salt.If I'm missing something or focusing on the wrong aspect of a concept or term, please post your comment to let me know.
------------------------------------------------------------------------------------------

ISO - 27001 and ISO - 27002 - Notes

- Formerly British Standards 7799-1 and 7999-2
- ISO (International Standards Organization) absorbed them and renamed them and modified to ISO 27001 and 27002.
- Direction on how to plan, set up, manage and organize an improve an information security management system.
- It references CIA, Business continuity, asset management and domains just like CISSP.

27001 – Is how to get certified as an ISMS – What are the requirements for auditing whether you achieved 27002, etc.?
27002 – Is actual granular info on how to implement. – What are the actual steps?

------------------------------------------------------------------------------------------------------
Security and Risk Management - ISO - 27001 and ISO - 27002 Quick Summary
--------------------------------------------------------------------------------------------------------

***I Am NOT An Expert! ***

As a method of studying for the CISSP, I am attempting to briefly explain the concepts I am learning in an an effort to help me, and perhaps fellow students.

Please take everything with a grain of salt.If I'm missing something or focusing on the wrong aspect of a concept or term, please post your comment to let me know.
------------------------------------------------------------------------------------------

ISO - 27001 and ISO - 27002 - Notes

- Formerly British Standards 7799-1 and 7999-2
- ISO (International Standards Organization) absorbed them and renamed them and modified to ISO 27001 and 27002.
- Direction on how to plan, set up, manage and organize an improve an information security management system.
- It references CIA, Business continuity, asset management and domains just like CISSP.

27001 – Is how to get certified as an ISMS – What are the requirements for auditing whether you achieved 27002, etc.?
27002 – Is actual granular info on how to implement. – What are the actual steps?
Рекомендации по теме
Комментарии
Автор

Thanks for your reply. I have cleared my CISSP exam yesterday.

RameshKumar-sidq
Автор

Can you please tell me what all ISO- series, NIST 800 series we need to memorize for CISSP exam

RameshKumar-sidq