Industry Standards and Frameworks for Information Security
A framework is a structure or outline that supports the implementation of an information security strategy. Frameworks provide the best practices for a structured security program. They are flexible structures that any organization can adopt as per its environment and requirements. Governance frameworks such as COBIT 5 and ISO 27001 are examples of widely accepted and implemented frameworks for security governance.
Generally, a security framework has the following components:
- Technical components: Technical components are parts of the framework that cover technical and IT aspects of security. Examples of technical aspects include configuration, monitoring, and maintenance of technical components such as firewalls, intrusion detection systems (IDSs), and SIEM. It is very important to have assigned ownership for each technical asset to ensure proper risk treatment and compliance with security policies.
- Operational...