Security controls
Selecting and implementing proper
security controls will initially help an
organization bring down risk to
acceptable levels. Control selection
should follow and should be based on
the risk assessment. Controls can vary in
nature, but fundamentally they are ways
of protecting the confidentiality, integrity
or availability of information. ISO/IEC
27001 has defined controls in different
areas. Organizations can implement
additional controls according to
requirement of the organization.
[48]
ISO/IEC 27002 offers a guideline for
Do'stlaringiz bilan baham: |