Book Image

Cybersecurity and Privacy Law Handbook

By : Walter Rocchi
5 (1)
Book Image

Cybersecurity and Privacy Law Handbook

5 (1)
By: Walter Rocchi

Overview of this book

Cybercriminals are incessantly coming up with new ways to compromise online systems and wreak havoc, creating an ever-growing need for cybersecurity practitioners in every organization across the globe who understand international security standards, such as the ISO27k family of standards. If you’re looking to ensure that your company's data conforms to these standards, Cybersecurity and Privacy Law Handbook has got you covered. It'll not only equip you with the rudiments of cybersecurity but also guide you through privacy laws and explain how you can ensure compliance to protect yourself from cybercrime and avoid the hefty fines imposed for non-compliance with standards. Assuming that you're new to the field, this book starts by introducing cybersecurity frameworks and concepts used throughout the chapters. You'll understand why privacy is paramount and how to find the security gaps in your company's systems. There's a practical element to the book as well—you'll prepare policies and procedures to prevent your company from being breached. You’ll complete your learning journey by exploring cloud security and the complex nature of privacy laws in the US. By the end of this cybersecurity book, you'll be well-placed to protect your company's data and comply with the relevant standards.
Table of Contents (18 chapters)
1
Part 1: Start From the Basics
3
Part 2: Into the Wild
8
Part 3: Escape from Chaos

ISO 27002

The current version of ISO 27002 was issued in 2013 and is now hopelessly out of date. A great deal has changed in the last 8 years! Let’s hope we won’t have to wait another 8 years for the next edition.

As with the previous edition, ISO 27002 is meant to be independent in the sense that it may be utilized by organizations who are uninterested in ISO 27001 and just want a set of information security rules to implement inside their organization. In this regard, it is identical to other control frameworks, such as the CSA’s NIST CSF. Choose your poison!

The new version will go out possibly in the upcoming months where the only significant change is that Annex A will match the new ISO 27002. This introduces 11 new controls, which are as follows:

  • Threat intelligence
  • Information security for use of cloud services
  • ICT readiness for business continuity
  • Physical security monitoring
  • Configuration management
  • Information deletion...