Cyber Security Standards
When it comes to international cyber security standards it would be hard not to mention International Organization for Standardization (ISO). This organization has published numerous security standards since 1980s but the most famous publications related to cyber security are marked as ISO 27001 followed by ISO 27002 and ISO 27005 (Infosec and ISO, 2013). Innovation and Research Expert in Australia
These three standards belong to the family of information security management standards and under the general title of Information technology – Security techniques (ISO/IEC, 2014). ISO 27001 encompasses the requirements for information security management systems, ISO 27002 relates to code of practice for information security controls and ISO 27005 emphasizes information security risk management (Infosec and ISO, 2013). Digital Transformation Expert in Australia
Although, these three ISO standards more refer to the term of information security, ISO 27032 encompasses cyber security guidance and covers four domains namely information security, network security, internet security and critical information infrastructure protection (ISO/IEC, 2012). European Council adopted a directive to confront cyber-attacks against information systems as a part of Digital agenda for Europe in 2020 initiative (European Commission, 2014).
This directive emphasizes the importance of information systems in European Union (EU) and points out that cyber-attacks can be critical to both, private and public sector in EU (European Parliament, 2013). Beside this directive EU also established European cybercrime platform, work with global stakeholders against computer-based security attacks and supports EU wide cyber security preparedness exercises (European Commission, 2013). According to Rezek et al. (2012, p. 9) there is “no state-sponsored institution in Slovakia specialized exclusively in the whole spectrum of cyber security issues”. They continue by explaining that cyber security is dispersed among Slovak National Accreditation Service, National Security Authority, Ministry of Interior, Ministry of Defense, Ministry of Finance and Personal Data Protection Office. However, the Ministry of Finance of Slovak Republic has established so called Computer Security Incident Response Team that is in charge to protect critical information and communication infrastructure (CSIRT, 2009). It remains being a question how many SMEs in Slovakia really use these or any other cyber security standards to protect their ISs but this question we categorized into organizational aspect of cyber security and asked our IT professionals that we interviewed.
Comments
Post a Comment