M9 ASSIGNMENT

pptx

School

Bellevue University *

*We aren’t endorsed by this school

Course

611

Subject

Computer Science

Date

Apr 3, 2024

Type

pptx

Pages

17

Uploaded by Manojmanu7

Report
CYBER SECURITY FRAMEWORKS -NIST 800-53R5 AND ISO 27001-27002 MANOJ KUMAR MARRIBOYINA 21430414 CIS 611- T301 CLOUD COMPUTING
What are Security Frameworks? Security Frameworks are organized collections of standards, best practices and recommendations that are intended to assist businesses in managing and strengthening their cyber security posture. Risk management, threat detection and response, access, control, data protection and regulatory compliance are just a few of the cyber security related issues that these frameworks offer a methodical way to handle.   Some of the Security Frameworks are: 1. NIST (National Institute of Standards and Technology) Cyber security Framework 2. ISO (International Organization for Standardization) 27000 Series 3. COBIT (Control Objectives for information and Related Technologies) 4. CIS Controls 5. PCI DSS (Payment Card Industry Data Security Standard) 6. NIST 800-53r5
NIST CYBER SECURITY FRAMEWORK
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help
What is NIST 800-53r5   1.NIST 800-53 framework, fifth revision. 2.It Sustains all essential infrastructural sectors, including the federal government. 3.An inventory of information systems' privacy and security measures 4.Businesses to safeguard a business. 5.Eighteen control families make up this version. 6.Different requirements are addressed by these controls
NIST 800-53R5
WHAT IS ISO 27001 AND 27002 1.Through the implementation of an Information Security Management System (ISMS), ISO 27001 offers a framework to assist enterprises of any size or industry in protecting their data in a methodical and economical manner. 2.When implementing the security measures specified in ISO 27001, this publication offers information on best practices. 3.ISO 27001 enables a business to obtain an audited certification on its own. This is the only cybersecurity standard that provides this.
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help
ISO 27001 AND 27002
ISO 27000 SERIES Information Security Management System (ISMS) requirements are provided by ISO 27001 Maintains the CIA (Confidentiality, Integrity, and Availability). Contains the Plan, Do, Check, Act (PDCA) cycle
DIFFERENCE BETWEEN THE STANDARDS OF NIST 800- 53R5 VS ISO 27001-27002 Frameworks for risk management are comparable. NIST was established to assist US government entities. ISO is a globally acknowledged methodology. NIST is more focused on security controls. ISO is more concerned with risk.
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help
NIST 800-53R5 VS ISO 27001-27002
MANAGING NIST 800-53 IN AWS (NIST CSF COMPLIANCE, 2019) 1.Security and compliance are ultimately shared responsibilities between AWS and the cloud customer, as demonstrated by the independent validation of AWS against NIST 800-53 procedures. 2.NIST security guidelines are adhered to by AWS. 3.specific compliance guidelines 4.Technological safeguards 5.ongoing oversight of compliance
NIST 800-53 IN AWS
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help
COMPANIES THAT OFFER CLOUD SERVICES AND ADHERE TO THESE STANDARDS. 1.Security and compliance are ultimately shared responsibilities between AWS and the cloud customer, as demonstrated by the independent validation of AWS against NIST 800-53 procedures.
Azure has demonstrated its compliance with the NIST 800-53 standard by implementing the AC-2 and AC-3 Controls. The account management control is AC-2, and the access enforcement control is AC-3.
Google Cloud adheres to the Federal Risk and Authorization Management Program (FedRAMP), which is a government-wide initiative that offers a standardized method for the security evaluation, approval, and ongoing observation of cloud-based goods and services. This facilitates NIST 800-53 compliance for its services.
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help
REFERENCE: 1.NIST - Amazon Web Services (AWS). (n.d.). Amazon Web Services, Inc. https://aws.amazon.com/compliance/nist/ 2.Security and Privacy Controls for information ... - NIST. (n.d.). Retrieved February 14, 2022, from https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf 3.The Complete Guide to Understanding Cybersecurity Frameworks. Dark Cubed. (n.d.). Retrieved February 14, 2022, from https://darkcubed.com/cybersecurity-frameworks# 4.Roncevich, T. (n.d.). What is the ISO 27001 and do you need it? CyberGuard Compliance: Regulatory Compliance, Audits, SSAE 18. Retrieved February 14, 2022, from https://info.cgcompliance.com/blog/what-is-the-iso-27001-and-do-you-need-it 5.www.isect.com, I. T. L. (n.d.). ISO/IEC 27001:2013 - information technology - security techniques - information security management systems - requirements (second edition). ISO/IEC 27001 certification standard. Retrieved February 14, 2022, from https://iso27001security.com/html/27001.html
6.ISO 27002, the Information Security Management System Framework. ISMS.online. (n.d.). Retrieved February 14, 2022, from https://www.isms.online/iso-27002/ 7.NIST CSF compliance. NIST 800-53 management for AWS. Dash Solutions. (2019, October 22). Retrieved February 14, 2022, from https://www.dashsdk.com/aws-nist-800-53-compliance/ 8.https://docs.microsoft.com/en-us/azure/governance/policy/samples/gov-nist-s p-800-53- r5 9.NIST 800-53 vs ISO 27002 vs NIST CSF (2023). (2023, July 10). Kyloot. https://kyloot-com.ngontinh24.com/article/nist-800-53-vs-iso-27002-vs-nist-csf