12.07.2015 Views

INTERNATIONAL ISO/IEC STANDARD 18028-1

INTERNATIONAL ISO/IEC STANDARD 18028-1

INTERNATIONAL ISO/IEC STANDARD 18028-1

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IS0/<strong>IEC</strong><strong>18028</strong>-1:2006(E)A conceptual model of network security showing where the types of security risk may occur is shownin Figure 3.Information should be gathered on the implications to business operations related to the types of securityrisk referred to above, with due consideration of the sensitivity or value of information involved(expressed as potential adverse business impacts) and related potential threats and vulnerabilities.Related to this, if there is likely to be more than a minor adverse impact on the business operations of theorganization, then reference should be made to the matrix in Table 5 below.It is emphasized that in completing this task, use should be made of the results from security riskassessment and management review(s) 7 ) conducted with regard to the network connection(s). Theseresults will enable a focus, to whatever level of detail the review(s) have been conducted, on thepotential adverse business impacts associated with the types of security risk listed above, as well as thethreat types, vulnerabilities and hence risks of concern.When considering network vulnerabilities during a security risk assessment and management review, itmay be necessary to consider a number of network facets separately. Table 4 below lists the types ofvulnerability that could be exploited at each network facet.7) Guidance on security risk assessment and management approaches is provided in <strong>ISO</strong>/<strong>IEC</strong> 17799, and will bein <strong>ISO</strong>/<strong>IEC</strong> 13335-2 when published.© <strong>ISO</strong>/<strong>IEC</strong> 2006 - All rights reserved 23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!