Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

QUESTION 18 C2. ISO 13335 recognizes four approaches to identifying and mitigating risks to an organization's IT infrastructure. L Explain: the need for a range

image text in transcribed
QUESTION 18 C2. ISO 13335 recognizes four approaches to identifying and mitigating risks to an organization's IT infrastructure. L Explain: the need for a range of formal standards that detail suitable IT security risk assessment processes, including ISO 13335, ISO 27005, ISO 31000, and NIST SP 800 30. (1 mark) Give an example from the ISO 27000 series family and what does it cover? (1 mark) What are the considerations when any organization decide to which approach to follow? (List 3 only) (1.5 marks) iv. What approach you should be implemented in the following: (4 marka) a Implement a basic general level of security controla on systems using baseline documents, codes of practice, and industry best practice which can be obtame from a range of organizations eg CERT and NSA b. Pragmatic risk analysis for the organization's IT systems which does not involve the use of a formal, structured process, but rather exploits the knowledge and expertise of the individuals performing this analytis, c Comprehensive approach to conduct intense risk assement of the organization's IT systems, using a formal structured process with great degree of assurance that all significant risks are identified, and their implications considered. provide reasonable levels of protection as quickly as possible then to examine and adjust the protection controls deployed on key systems over time d Provide reasonable levels of protection as quickly as possible then to examine and adjust the protection controls deployed on key systems over time QUESTION 18 C2. ISO 13335 recognizes four approaches to identifying and mitigating risks to an organization's IT infrastructure. L Explain: the need for a range of formal standards that detail suitable IT security risk assessment processes, including ISO 13335, ISO 27005, ISO 31000, and NIST SP 800 30. (1 mark) Give an example from the ISO 27000 series family and what does it cover? (1 mark) What are the considerations when any organization decide to which approach to follow? (List 3 only) (1.5 marks) iv. What approach you should be implemented in the following: (4 marka) a Implement a basic general level of security controla on systems using baseline documents, codes of practice, and industry best practice which can be obtame from a range of organizations eg CERT and NSA b. Pragmatic risk analysis for the organization's IT systems which does not involve the use of a formal, structured process, but rather exploits the knowledge and expertise of the individuals performing this analytis, c Comprehensive approach to conduct intense risk assement of the organization's IT systems, using a formal structured process with great degree of assurance that all significant risks are identified, and their implications considered. provide reasonable levels of protection as quickly as possible then to examine and adjust the protection controls deployed on key systems over time d Provide reasonable levels of protection as quickly as possible then to examine and adjust the protection controls deployed on key systems over time

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Visual Basic 4 Ole Database And Controls Superbible

Authors: Michael Hatmaker, C. Woody Butler, Ibrahim Malluf, Bill Potter

1st Edition

1571690077, 978-1571690074

More Books

Students also viewed these Databases questions

Question

2. Why has the conflict escalated?

Answered: 1 week ago