Information security framework components
Frameworks are structures or outlines that support the implementation of an information security strategy. They provide the best practices for a structured security program. Frameworks are flexible structures that any organization can adopt as per their environment and requirements. Governance frameworks such as COBIT 5 and ISO 27000 are widely accepted and implemented frameworks for security governance.
Generally, a security framework has the following components:
- Technical components: This means the part of the framework that covers the technical and IT aspects of security. Examples of technical aspects include the configuration, monitoring, and maintenance of technical components such as a firewall, IDS, SIEM, and so on. It is very important to have assigned ownership for each technical asset to ensure proper risk treatment and compliance with security policies.
- Operational components: This means the part of the framework...