Let kilo remove bof cruft
This commit is contained in:
parent
c88dcd383b
commit
984ccff4e4
50 changed files with 2326 additions and 103 deletions
|
|
@ -1,9 +1,5 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
|
## 3.1 Terms and definitions
|
||||||
**3.1** **Terms** **and** **definitions**
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
For the purposes of this document, the following terms and definitions apply.
|
For the purposes of this document, the following terms and definitions apply.
|
||||||
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 5.12 Classification of information
|
## 5.12 Classification of information
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 5.15 Access control
|
## 5.15 Access control
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.17 Authentication information
|
## 5.17 Authentication information
|
||||||
|
|
||||||
### Control
|
### Control
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.19 Information security in supplier relationships
|
## 5.19 Information security in supplier relationships
|
||||||
|
|
||||||
**Control**
|
**Control**
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.20 Addressing information security within supplier agreements
|
## 5.20 Addressing information security within supplier agreements
|
||||||
|
|
||||||
**Control**
|
**Control**
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
[[ISO_27002_PE 5.21 Managing information security in the ICT supply chain]]
|
|
||||||
|
|
||||||
## 5.21 Managing information security in the ICT supply chain
|
## 5.21 Managing information security in the ICT supply chain
|
||||||
|
|
||||||
**Control**
|
**Control**
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,4 @@
|
||||||
#iso27002/2022/EN
|
## 5.22 Monitoring, review, and change management of supplier services
|
||||||
|
|
||||||
**Control**
|
**Control**
|
||||||
The organization should regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.
|
The organization should regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.23 Information security for use of cloud services
|
## 5.23 Information security for use of cloud services
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.24 Information security incident management planning and preparation
|
## 5.24 Information security incident management planning and preparation
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.27 Learning from information security incidents
|
## 5.27 Learning from information security incidents
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.29 Information security during disruption
|
## 5.29 Information security during disruption
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.3 Segregation of duties
|
## 5.3 Segregation of duties
|
||||||
|
|
||||||
### Control
|
### Control
|
||||||
|
|
|
||||||
|
|
@ -1,9 +1,4 @@
|
||||||
#iso27002/2022/EN
|
## **5.30** **ICT** **readiness** **for** **business** continuity
|
||||||
See also:
|
|
||||||
- [BCP_Bedrijfscontinuïteitsplanning](../../../../../📚️%20Literature%20notes/BCP_Bedrijfscontinuïteitsplanning.md)
|
|
||||||
- [Disaster Recovery Planning](../../../../../🎇%20Sparks/Disaster%20Recovery%20Planning.md)
|
|
||||||
|
|
||||||
# **5.30** **ICT** **readiness** **for** **business** continuity
|
|
||||||
|
|
||||||
## Purpose
|
## Purpose
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.32 Intellectual property rights
|
## 5.32 Intellectual property rights
|
||||||
|
|
||||||
**Control**
|
**Control**
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
|
|
||||||
|
|
||||||
## 5.37 Documented operating procedures
|
## 5.37 Documented operating procedures
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.4 Management responsibilities
|
## 5.4 Management responsibilities
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.5 Contact with authorities
|
## 5.5 Contact with authorities
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.6 Contact with special interest groups
|
## 5.6 Contact with special interest groups
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.7 Threat intelligence
|
## 5.7 Threat intelligence
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 5.8 Information security in project management
|
## 5.8 Information security in project management
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 5.9 Inventory of information and other associated assets
|
## 5.9 Inventory of information and other associated assets
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,4 @@
|
||||||
# Control 6.1 Screening
|
## Control 6.1 Screening
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 6.3 Information security awareness, education and training
|
## 6.3 Information security awareness, education and training
|
||||||
|
|
||||||
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
|
|
||||||
|
|
||||||
## 6.5 Responsibilities after termination or change of employment
|
## 6.5 Responsibilities after termination or change of employment
|
||||||
|
|
||||||
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
|
|
||||||
|
|
||||||
## 6.6 Confidentiality or non-disclosure agreements
|
## 6.6 Confidentiality or non-disclosure agreements
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
|
|
||||||
|
|
||||||
## 6.8 Information security event reporting
|
## 6.8 Information security event reporting
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
|
|
||||||
|
|
||||||
## 7.1 Physical security perimeters
|
## 7.1 Physical security perimeters
|
||||||
|
|
||||||
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
|
|
||||||
|
|
||||||
## 7.3 Securing offices, rooms and facilities
|
## 7.3 Securing offices, rooms and facilities
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
|
|
||||||
|
|
||||||
## 7.4 Physical security monitoring
|
## 7.4 Physical security monitoring
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 8.13 Information backup
|
## 8.13 Information backup
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 8.15 Logging
|
## 8.15 Logging
|
||||||
|
|
||||||
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 8.16 Monitoring activities
|
## 8.16 Monitoring activities
|
||||||
|
|
||||||
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
| **Control type** | **Information security properties** | **Cybersecurity concepts** | **Operational capabilities** | **Security domains** |
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 8.19 Installation of software on operational systems
|
## 8.19 Installation of software on operational systems
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 8.2 Privileged access rights
|
## 8.2 Privileged access rights
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
|
|
||||||
|
|
||||||
## 8.21 Security of network services
|
## 8.21 Security of network services
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 8.22 Segregation of networks
|
## 8.22 Segregation of networks
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,9 +1,3 @@
|
||||||
---
|
|
||||||
tags:
|
|
||||||
- iso27001/2022/EN
|
|
||||||
---
|
|
||||||
|
|
||||||
|
|
||||||
## 8.24 Use of cryptography
|
## 8.24 Use of cryptography
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,8 +1,3 @@
|
||||||
---
|
|
||||||
tags:
|
|
||||||
- iso27001/2022/EN
|
|
||||||
---
|
|
||||||
|
|
||||||
## 8.25 Secure development life cycle
|
## 8.25 Secure development life cycle
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 8.26 Application security requirements
|
## 8.26 Application security requirements
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,8 +1,3 @@
|
||||||
---
|
|
||||||
tags:
|
|
||||||
- iso27001/2022/EN
|
|
||||||
---
|
|
||||||
|
|
||||||
## 8.27 Secure system architecture and engineering principles
|
## 8.27 Secure system architecture and engineering principles
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,14 +1,3 @@
|
||||||
---
|
|
||||||
tags:
|
|
||||||
- iso27001/2022/EN
|
|
||||||
---
|
|
||||||
|
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
|
||||||
| ------------ | ----------------------------------------- | ---------------------- | -------------------------------------------------- | ---------------- |
|
|
||||||
| #Preventive | #Confidentiality #Integrity #Availability | #Protect | #Application_security #System_and_network_security | #Protection |
|
|
||||||
|
|
||||||
|
|
||||||
## 8.28 Secure coding
|
## 8.28 Secure coding
|
||||||
|
|
||||||
#### Control
|
#### Control
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 8.29 Security testing in development and acceptance
|
## 8.29 Security testing in development and acceptance
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 8.32 Change management
|
## 8.32 Change management
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
|
|
||||||
## 8.5 Secure authentication
|
## 8.5 Secure authentication
|
||||||
|
|
||||||
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,4 @@
|
||||||
#iso27002/2022/EN
|
## 8.7 Protection against malware
|
||||||
|
|
||||||
# 8.7 **Protection** **against** **malware**
|
|
||||||
|
|
||||||
## Control
|
## Control
|
||||||
Protection against malware should be implemented and supported by appropriate user awareness.
|
Protection against malware should be implemented and supported by appropriate user awareness.
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
x
|
|
||||||
## 8.8 Management of technical vulnerabilities
|
## 8.8 Management of technical vulnerabilities
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
#iso27002/2022/EN
|
|
||||||
## 8.9 Configuration management
|
## 8.9 Configuration management
|
||||||
|
|
||||||
### Control
|
### Control
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,6 @@
|
||||||
---
|
---
|
||||||
Related:
|
Related:
|
||||||
- "[ISO\\_27002\\_OT 3 Terms, definitions and abbreviated terms](Standards/ISO27x/OST/27002/EN/ISO_27002_OT%203%20Terms,%20definitions%20and%20abbreviated%20terms.md)"
|
- "[ISO\\_27002\\_OT 3 Terms, definitions and abbreviated terms](Standards/ISO27x/OST/27002/EN/a-3-Terms-definitions-and-abbreviated-terms.md)"
|
||||||
- https://csiac.org/databases/acronyms/
|
- https://csiac.org/databases/acronyms/
|
||||||
tags:
|
tags:
|
||||||
- type/MoC
|
- type/MoC
|
||||||
|
|
|
||||||
2320
prepend_frontmatter.py
Normal file
2320
prepend_frontmatter.py
Normal file
File diff suppressed because it is too large
Load diff
Loading…
Add table
Add a link
Reference in a new issue