Standards for ISM + PCI-DSS

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/10

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

11 Terms

1
New cards

What is an Information security standard?

a description of security best practice. A description of the required level of activity/coverage and framework for documenting and auditing.

2
New cards

Why are standards important for ISM? Give 4 points

Help implement policy

Improve governance

Improve compliance

Improve security

3
New cards

What is PCI-DSS and what does it cover?

Payment Card Industry Data Security Standard. Covers the security of operating online payment systems and handling digital card payments.

4
New cards

How does PCI-DSS operate

Secure Network (Firewalls, No defaults).

Protect Data (Stored data protection, Encryption in transit).

Vulnerability Management (Anti-virus, Secure systems).

Access Control (Need-to-know, Authentication, Physical access).

Monitor & Test (Track access, Regular tests).

Policy (Maintain info sec policy)

5
New cards

What are the strengths of PCI-DSS?

Improved reputation for online shopping

Reduced fraud rates

Encouraged merchants with poor security to take it seriously

Not a significant burden for merchants who already had good security

6
New cards

What are the weakness of PCI-DSS

Can be expensive

Encourages box ticking approach rathe than real security

Shifts blame to merchants, hiding weaknesses of payment mechanisms

Focuses on technology/payments rather than holistic system security

7
New cards

How can outsourcing be used to implement PCI-DSS

Hosting: Transfers secure network compliance

Payment Function: Transfers compliance for secure network data protection access control and monitoring

8
New cards

What is cyber essentials and what does it cover?

Helping organisations implement basic levels of protection against cyber attacks. Covers basics to protect against unskilled internet based attackers using commodity capabilities

9
New cards

How does cyber essentials operate (5 controls)

Boundary firewalls and internet gateways

Secure configuration

Access control

Malware protection

Patch management

10
New cards

What are the strengths of cyber essentials?

Affordable

Solves simple issues

Demonstrates customers that the organisation takes cyber security seriously

Available at two levels

11
New cards

How is cyber essentials implemented?

Basic: independently verified self assessment where the organisation assesses itself against the 5 controls

PLUS: qualified independent assessor examines the controls and tests that they work by doing simulated attacks