The Information Security Forum (ISF) has published a Standard of Good Practice for Information Security. In this video, take a look at the standard and how it compares to the ISO and NIST standards.
- [Instructor] While controls can be applied … by an enterprise as a customized response to business risks, … in many cases, an external authority … will direct that a predefined set of controls be adopted … as a baseline for security. … An example of government policy is SP 800-53, … Security and Privacy Controls … for Federal Information Systems and Organization, … which federal organizations are required to adopt. … The authority may be an industry body, … such as the Payment Card Industry counsel, … which requires that merchants adhere … to the Payment Card Industry data security standard. … NIST's SP 800-53 is one of two important control frameworks … used in cyber security, the other being ISO 27002. … They are both structured as a set of control categories, … within which exists a number of specific controls. … While the categories and controls … are different for each standard, … they can be mapped against each other. … These two control frameworks are widely referenced … by other security schemes, …
Author
Released
2/13/2020- Dissecting cyber risk
- Working with NIST, COBIT, and other frameworks
- Exploring cybercrime
- The different stages of the cyber kill chain
- How cyber criminals hide their attacks
- Measuring incident management maturity
- Detecting and responding to attacks
Skill Level Intermediate
Duration
Views
Related Courses
-
Learning Security Frameworks
with Mandy Huth47m 8s Intermediate -
Security Matters (To Everyone)
with Mandy Huth33m 8s Beginner -
GDPR Compliance: Essential Training
with Mandy Huth55m 17s Intermediate -
Penetration Testing Essential Training
with Malcolm Shore2h 29m Intermediate
-
Introduction
-
1. Frameworks and Controls
-
An advanced risk framework5m 22s
-
Managing security with COBIT3m 15s
-
ASD and its top controls2m 49s
-
Protecting payment card data7m 14s
-
Clouding the issues3m 44s
-
2. Cyber Threats
-
Hiding using processes3m 59s
-
3. Managing Cyber Incidents
-
Incident management basics3m 48s
-
Detecting an attack4m 4s
-
Responding to an incident2m 33s
-
-
Conclusion
-
What's next55s
-
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.
CancelTake notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.
Share this video
Embed this video
Video: Cybersecurity control framework