How could evidence be obtained to validate

Assignment Help Computer Engineering
Reference no: EM133423878

Question: Select a section of the ISO 27002:2013 standard at the control level from section 12 (Operations Security).  The control level is at the 3rd layer down, for example: '12.2.1 Controls against malware' has control as its primary feature.  We are trying to get a reasonable spread of these controls throughout the class so try to do them at random from section 12.  [See the week 4 tutorial work if you need to know how to get a copy of the ISO 27002 standard.]

With respect to the control, consider the following issues (and include in your submission):

  • should it be generally accepted (or generic, in that it should apply to all organisations using the standard), or company-specific (in that it should only apply to some organisations, based on the local circumstances)? (Justify your answer).
  • can you find evidence from academic literature supporting the need for the control that you have selected (you may need to have a quick google scholar search)? One or two articles should be sufficient for this question.
  • if this evidence is not apparent in the literature, how could this evidence be obtained to validate the need for such controls, as distinct from just relying on 'best practice'?

Note that these questions are exploring the differences between 'best practice' (an expert consensus model) and academic evidence.  Typically, standards like ISO 27002 are best practice models and are usually derived by groups of experts meeting to discuss the contents, and subsequently reaching some form of consensus about what should go into the standard and how it should be structured.  This is quite different from academic literature where empirical evidence is used to substantiate claims.

Reference no: EM133423878

Questions Cloud

Did cogdill have a contract with the bank of benton : The bank's president Julio Plunkett thanked Buster for the proposal and said, "I will start the paperwork." Did Cogdill have a contract with the Bank of Benton?
How did the media portray the police : Discussed on page 46 did the incident contain? Explain. How did the media portray the police? Was it a fair portrayal or was the media biased? Explain.
What other skills are important in building working : Is conflict resolution the most important skill that leaders need? Why or why not? What other skills are important in building working relationships?
What is the correct measure of the damages : difference between the value of the performance contracted for and the value of the performance actually rendered. What is the correct measure of the damages?
How could evidence be obtained to validate : How could evidence be obtained to validate the need for such controls, as distinct from just relying on 'best practice
Write a java program that achieves the rotation : Write a java program that achieves the rotation of a unit cube about an arbitrary fixed point (page 79 - first special case of 3D rotation)
How does private international law facilitate international : How does private international law facilitate international trade? Consider in your answer the agreements and entities which govern private international law
What are the major problems while using agile development : What are the major problems (or side-effects) while using Agile Development Methodology (for example Scrum and XP)? Include an example for each problem
What features are included in simulations and games have : What features are included in simulations and games have to help students improve their performance?

Reviews

Write a Review

Computer Engineering Questions & Answers

  Read in two numbers from keyboard with instructions

Read in two numbers from keyboard with instructions, one for index, one for the size of the array;

  Define the legislation governing web accessibility in europe

evalute and contrast the legislation governing Web accessibility in Europe with that in the US.

  Discuss the penetration testing with example

Penetration testing is a simulated cyberattack against a computer or network that checks for exploitable vulnerabilities. Pen tests can involve attempting.

  Discuss merits of asynchronous and synchronous memory access

The quoted physical address space of the 68000 is 16 Mbytes (i.e., 2 24 bytes). I could maintain that it is 64 Mbytes. What is the argument I might use.

  Estimate the cost of the containment efforts

Create an incident response plan that can immediately protect digital assets in the event of an attack, breach, or penetration. The incident response plan.

  Identify the security problems

What is a( IPSEC, SSL , VPN, DTLS , DMARC, PKI, PEM, SSH, Kerberos, DKIM) ?. Brifley and answer the following brief.

  Write regular expressions for the following languages

Write regular expressions for the following languages- The set of all strings over the alphabet {a, b} that contain an odd b's.

  Explain the key elements of jit manufacturing

Describe the elements of JIT. Explain the key elements of JIT manufacturing. Explain the elements of total quality management (TGM) and their role in JIT.

  What kind of nonvolatile information can an investigator get

What kinds of nonvolatile information can an investigator get from a system? What kinds of volatile information can an investigator get from a system?

  Describe the technology and approaches that would be used

Describe at least four, tools, technology, approaches, and/or methodology that would be used to accomplish the above project.

  Determine the overall system speedup

What are the challenges facing organizations that wish to move to a Cloud platform? What are the risks and benefits? Convert the following to binary. Show your.

  What metrics show increased utilization

Delete all of the resources you created in this project, including the VM, topic, and alarm. Check through your account to confirm that all related resources

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd