C838 - Managing Cloud SecurityQuestions and Answers
All for this textbook (2)
Written for
C838
All documents for this subject (20)
Seller
Follow
Certifiedacademics
Content preview
C838 ISO/IEC and NIST Standards
(VERIFIED 2023)
ISO/IEC 17788 -: Overview and vocabulary for cloud computing.
ISO/IEC 27034-1 -: Standards for secure application development.
ISO/IEC 27017:2015 -: Guide for cloud information security controls.
ISO/IEC 27037:2012 -: Guide for collecting and identifying digital evidence.
ISO/IEC 27041:2015 -: Guide for incident investigation.
ISO/IEC 27042:2015 -: Guide for digital evidence analysis.
ISO/IEC 27043:2015 -: Principles and process for incident investigation.
ISO/IEC 27050-1:2016 -: Overview and process for eDiscovery.
ISO/IEC 27001 -: Standard for the establishment, implementation, control, and improvement of the
Information Security Management System (ISMS)
ISO/IEC 15408-1:2009 -: Common criteria assurance framework.
ISO/IEC 31000:2009 -: Risk Management guide and framework (RMF) to design and implement a risk
management program. 11 principles. Protect value, all aspects of organization, part of all org decisions,
RM mitigates uncertainty, integrated efficiently with processes, uses accurate data, tailored to business
needs, include human elements, transparent, flexible, continual improvements.
, ISO/IEC 27018 -: Standards for cloud privacy.
NIST 800-145 -: Definition for cloud computing.
NIST 800-53 -: Guide for the security requirements for the U.S. federal government information systems.
NIST SP 800-37 -: Risk Management Framework
NIST SP 800-88 -: Guide for cryptographic erasure.
NIST SP 800-122 -: Defines personal identifiable information (PII)
EU Data Directive 95/46/EC -: Applies to data related to EU citizens that is processed by automatic or
manual (paper) means.
The Electronic Communication Privacy Act (ECPA) -: Enhance laws restricting the government from
putting wire taps on phone calls, updating them to include electronic communication in the form of data.
The Stored Communications Act (SCA) -: Restrict government from forcing ISPs to disclose customer data
the ISP might possess.
Graham Leach Bliley Act (GLBA) -: Allow banks to merge with and own insurance companies. Included in
the law were stipulations that customer account information be kept secure and private, and that
customers be allowed to opt out of any information-sharing arrangements the bank or insurer might
engage in.
Sarbanes-Oxley Act -: An act passed into law by Congress in 2002 to establish strict accounting and
reporting rules in order to make senior managers more accountable and to improve and maintain
investor confidence.
Health Insurance Portability and Accountability Act (HIPAA) -: Protect patient records and data, known as
electronic protected health information (ePHI).
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Certifiedacademics. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $10.29. You're not tied to anything after your purchase.