Please enable JavaScript.
Coggle requires JavaScript to display documents.
1.1.5 (AUDITING THE INFORMATION SECURITY
MANAGEMENT FRAMEWORK (involves,…
1.1.5
-
-
Implementation
-
a poorly implemented control may pose a significant risk to the organization by creating a false sense of security or leading to a denial of service if the control does not function correctly.
Standards
Many industries have standards that may be used as a benchmark for security across the industry sector
To meet the requirements of the standard, a framework is often used to describe how an organization can achieve compliance.
A control framework is a set of fundamental controls that helps support and protect an enterprise by preventing/minimizing financial or information loss and adding/preserving value.
selection of controls requires the evaluation and implementation of the right control in the right way.
Based on data collected through an analysis method (e.g., cost-benefit, return on investment [ROI] and risk assessment results), management will decide on the best available control, or group of controls, to mitigate a specific risk
Information security is an essential component of governance and management that affects all aspects of entity-level controls.