15

Updated 4 Oct 2026


🗺️ Big Picture

ISO 27001:2022 = International Standard for ISMS
│
├── Part I   — What is ISMS? + Clauses 0–10 Structure
├── Part II  — Gap Analysis, Risk Assessment, BIA, RTO/RPO
└── Part III — 93 Controls in 4 Themes
               ├── Organizational (5.x) — 37 controls
               ├── People (6.x)         —  8 controls
               ├── Physical (7.x)       — 14 controls
               └── Technological (8.x)  — 34 controls

ISMS=Establish+Implement+Monitor+Review+Maintain+Improve\boxed{\text{ISMS} = \text{Establish} + \text{Implement} + \text{Monitor} + \text{Review} + \text{Maintain} + \text{Improve}}


Part I — Introduction to ISO 27001

Three Perspectives of Information Security

PerspectiveFocus
BusinessHow does InfoSec support business goals?
Customer (End User)Data privacy and user rights
Service Provider / SupplierResponsibilities in security assurance

🍽️ Analogy: Like a restaurant — the owner (business) manages the operation, customers want their personal data safe, and the supplier must guarantee the quality of what they deliver.

What Is ISO/IEC 27001:2022?

  • International standard for establishing an Information Security Management System (ISMS)
  • Published by ISO (International Organization for Standardization) + IEC (International Electrotechnical Committee)
  • Covers all organization types and sizes — commercial, government, non-profit
  • Uses Plan–Do–Check–Act (PDCA) cycle for continuous improvement

🏭 Analogy: ISO 27001 is to information security what ISO 9001 is to quality management — a formal framework to prove you manage it properly.

Key Characteristics

  • Concerns management of information security, not just technical IT security
  • Implementation is scaled to the organization's size and needs
  • Thousands of organizations worldwide are certified compliant

How to Protect Information (Tools)

Controls / Policy / Procedures / Passwords / Encryption / Security Applications / Secure Coding / Legal frameworks / Training & Awareness


ISO 27001 Clauses Structure

ClauseTopicPDCA Phase
0Introduction—
1Scope—
2Normative references—
3Terms and definitions—
4Context of the organizationPlan
5LeadershipPlan
6Planning (risks + objectives)Plan
7Support (resources, awareness, docs)Do
8Operation (risk assessment + treatment)Do
9Performance evaluation (audit/review)Check
10Improvement (continuous improvement)Act
Annex AControls reference (Statement of Applicability)—

Output of risk assessment → Assessment report → Apply controls to mitigate risks → Document in Statement of Applicability (SoA)


ISO 27001 Certification Path (12 Steps)

① Plan the project
② Define scope and context of ISMS
③ Obtain management commitment
④ Establish Information Security Policy
⑤ Set ISMS objectives + management system
⑥ Conduct Risk Assessment
⑦ Produce Statement of Applicability (SoA)
⑧ Implement controls
⑨ Internal audit
⑩ Management review
⑪ External audit — Stage 1
⑫ External audit — Stage 2 (Certification) ✅

Part II — Gap Analysis & Risk Assessment

Gap Analysis vs. Risk Assessment

Gap AnalysisRisk Assessment
Tells youWhat you're missing to comply with ISO 27001What controls you should apply
Does NOT tell youWhich controls to apply to address identified risksWhat controls you already have

Gap Analysis = รู้ว่าขาดอะไร / Risk Assessment = รู้ว่าควรทำอะไร


What Is Risk?

Risk=Threat exploits Vulnerability→Adverse Impact on organization\boxed{\text{Risk} = \text{Threat exploits Vulnerability} \rightarrow \text{Adverse Impact on organization}}

TermDefinitionExamples
ThreatSomething that might cause harmFire, hacker, system failure
VulnerabilityWeakness that might be exploitedNo backup, weak password, untrained staff
ImpactResulting damageFinancial loss, reputational damage
Threat AgentThe actor behind the threatHuman / Machine / Nature

Risk Relationship:

Threat Agent → exploits → Vulnerability → affects → Information Asset
                                   ↑
                              Controls reduce this

Goals of Risk Analysis

  1. Identify assets and their value to the organization
  2. Identify vulnerabilities and threats (via VAPT — Vulnerability Assessment & Penetration Testing)
  3. Quantify probability and business impact of threats
  4. Provide economic balance between impact and cost of countermeasure

Risk Assessment Process (NIST SP 800-30)

① Identify assets
② Identify vulnerabilities and threats
③ Assess business impact on each vulnerability/threat
④ Conduct Risk Analysis
⑤ Provide controls / treatment plan
⑥ Evaluate the controls

Risk Analysis Approaches

ApproachMethodOutputExample
QuantitativeMonetary + numeric values assigned to all elements"This risk will cost $50,000"Asset value × threat frequency × vulnerability severity
QualitativeRatings based on expert judgmentRed/Yellow/Green or High/Medium/LowRisk matrix

Risk Calculation Methods

Method 1 (Addition): Risk=Consequences+Likelihood\boxed{\text{Method 1 (Addition): Risk} = \text{Consequences} + \text{Likelihood}} Method 2 (Multiplication): Risk=Consequences×Likelihood\boxed{\text{Method 2 (Multiplication): Risk} = \text{Consequences} \times \text{Likelihood}}

Detailed Risk Score: Risk=Asset Value+Threat Value+Vulnerability Value\text{Risk} = \text{Asset Value} + \text{Threat Value} + \text{Vulnerability Value}

Example (Laptop theft):

  • Asset value = 3, Threat value = 2, Vulnerability value = 2 → Risk = 7

Qualitative Risk Matrix

Likelihood ↓ \ Consequences →InsignificantMinorModerateMajorSevere
Almost certainMHHEE
LikelyMMHHE
PossibleLMMHE
UnlikelyLMMMH
RareLLMMH
LevelColorAction Required
E — Extreme🔴 RedImmediate action required
H — High🟠 OrangeSenior management attention needed
M — Medium🟡 YellowManagement responsibility specified
L — Low🟢 GreenManage by routine procedures

Asset–Threat–Vulnerability Examples

AssetThreatVulnerabilityCIA Impact
Paper documentFireNo fire-proof cabinetLoss of Availability
Paper documentUnauthorized accessNot lockedLoss of Confidentiality
Digital documentDisk failureNo backupLoss of Availability
Digital documentVirusOutdated antivirusLoss of CIA
Digital documentUnauthorized accessToo many access rightsLoss of CIA
System administratorUnavailabilityNo replacement personLoss of Availability
System administratorFrequent errorsLack of trainingLoss of Integrity + Availability

Risk Treatment Options

OptionWhat it means
AcceptAcknowledge and do nothing extra
MitigateImplement controls to reduce the risk
TransferShift risk to a third party (e.g., insurance)
AvoidStop the activity that causes the risk

Risk Acceptance Criteria

  • Define a risk acceptance threshold (e.g., if scale is 2–10, define acceptable = 7)
  • Only risks above threshold need treatment
  • Must be formally defined and documented

Business Impact Analysis (BIA)

Determines the Maximum Acceptable Outage for each service.

Question2 hrs4 hrs8 hrs24 hrs48 hrs1 week
Client reaction to disruption223344
Impact to other activities122334
Reputation damage122344
Backlog difficulty112233
Legal/contractual penalties (USD)01,0002,00030,00060,000210,000
Revenue loss (USD)00010,00020,00070,000

→ Maximum Acceptable Outage = between 8 and 24 hours → RTO is determined by examining dependencies on other activities


RTO & RPO

RTO (Recovery Time Objective)=Maximum time within which a service must be restored after a disaster\boxed{\text{RTO (Recovery Time Objective)} = \text{Maximum time within which a service must be restored after a disaster}}

RPO (Recovery Point Objective)=Maximum amount of data that might be lost due to a disruption\boxed{\text{RPO (Recovery Point Objective)} = \text{Maximum amount of data that might be lost due to a disruption}}

🕐 Analogy: RTO = "กลับมาทำงานได้ภายใน X ชั่วโมง" (how fast to recover). RPO = "ข้อมูลสูญหายได้ไม่เกิน X ชั่วโมงย้อนหลัง" (how much data can you afford to lose).

RPORequired Infrastructure
1–2 daysDaily backup via network or cloud replication
1–2 minutesMirrored disks

Standby Types (determined by RTO):

  • Cold standby — systems off, manual restart needed (longer RTO)
  • Hot standby — systems running and ready (shorter RTO)
  • Mirrored — real-time data mirroring (near-zero RTO/RPO)

⚠️ Key insight: Backup is NOT the real problem — being able to restore within the required timeframe is the real challenge.

Requirements for proper restore:

  • Know the timeframe + order of system restoration
  • Availability of systems + knowledgeable personnel + required software
  • Restore procedures + test procedures post-restore

Part III — ISO/IEC 27002:2022 — 93 Controls in 4 Themes

ISO 27002=93 Controls across 4 Themes: Organizational + People + Physical + Technological\boxed{\text{ISO 27002} = \text{93 Controls across 4 Themes: Organizational + People + Physical + Technological}}

ThemeSectionCount
OrganizationalSection 537
PeopleSection 68
PhysicalSection 714
TechnologicalSection 834

Control Attributes (5 Categories per control)

AttributeValues
Control typePreventive, Detective, Corrective
InfoSec propertiesConfidentiality, Integrity, Availability
Cybersecurity conceptsIdentify, Protect, Detect, Respond, Recover
Operational capabilitiesGovernance, Asset mgmt, IAM, Threat mgmt, Continuity, etc.
Security domainsGovernance & Ecosystem, Protection, Defense, Resilience

3.1 Organizational Controls — Section 5 (37 controls)

Full List

ControlName
5.1Policies for information security
5.2Information security roles and responsibilities
5.3Segregation of duties
5.4Management responsibilities
5.5Contact with authorities
5.6Contact with special interest groups
5.7Threat intelligence
5.8Information security in project management
5.9Inventory of information and other associated assets
5.10Acceptable use of information and other associated assets
5.11Return of assets
5.12Classification of information
5.13Labelling of information
5.14Information transfer
5.15Access control
5.16Identity management
5.17Authentication information
5.18Access rights
5.19Information security in supplier relationships
5.20Addressing information security within supplier agreements
5.21Managing information security in the ICT supply chain
5.22Monitoring, review and change management of supplier services
5.23Information security for use of cloud services
5.24Information security incident management planning and preparation
5.25Assessment and decision on information security events
5.26Response to information security incidents
5.27Learning from information security incidents
5.28Collection of evidence
5.29Information security during disruption
5.30ICT readiness for business continuity
5.31Legal, statutory, regulatory and contractual requirements
5.32Intellectual property rights
5.33Protection of records
5.34Privacy and protection of PII
5.35Independent review of information security
5.36Compliance with policies, rules and standards
5.37Documented operating procedures

Key Organizational Controls — Details

5.1 — Policies for Information Security

  • A document helping employees understand why InfoSec is important and what their role is
  • Includes the information security policy + its review process

5.7 — Threat Intelligence

Threat Data→Analysis→Intelligence→Action→Improved Security\text{Threat Data} \rightarrow \text{Analysis} \rightarrow \text{Intelligence} \rightarrow \text{Action} \rightarrow \text{Improved Security}

Three levels:

LevelAudienceContent
StrategicExecutivesHigh-level trends and risk landscape
TacticalSecurity teamsTTPs (Tactics, Techniques, Procedures)
OperationalSOC analystsSpecific IoCs for ongoing attacks

Good threat intelligence must be: Relevant, Insightful, Contextual, Actionable

5.9 / 5.10 / 5.11 — Asset Management

  • 5.9 Maintain an Asset Management DB (inventory of all assets)
  • 5.10 Define Acceptable Use Policy for assets
  • 5.11 Procedures for returning assets when employment ends

5.12 — Classification of Information ⭐ Exam Note

Q: What is the major benefit of information classification? A: We can apply/decide access controls appropriately for each class of information.

Classification LevelAccess
Highly ConfidentialOnly cleared individuals
ConfidentialRestricted distribution
PublicAnyone
  • Asset owners classify information based on impact of loss/damage/disclosure
  • Rules: e.g., confidential info must be encrypted or sent by registered mail

5.19–5.21 — Supplier Management

Supplier types: Software / Hardware / Facilities / BPO

Access LevelContract Type
Low accessSupplier Terms & Conditions (T&Cs)
High accessFull Contractual Agreement

5.29–5.30 — Business Continuity (Availability)

  • 5.29 — Security during disruption (BCM aspects) — continuity of security procedures during a crisis
  • 5.30 — ICT readiness — redundancy of ICT services (servers, network, applications)

BCP requirements:

  • Must be exercised periodically — must fully restore within RTO/RPO
  • All personnel must know their roles
  • Any organizational change must trigger BCP updates (via change management)

3.2 Physical Controls — Section 7 (14 controls)

Full List

ControlName
7.1Physical security perimeters
7.2Physical entry
7.3Securing offices, rooms and facilities
7.4Physical security monitoring
7.5Protecting against physical and environmental threats
7.6Working in secure areas
7.7Clear desk and clear screen
7.8Equipment siting and protection
7.9Security of assets off-premises
7.10Storage media
7.11Supporting utilities
7.12Cabling security
7.13Equipment maintenance
7.14Secure disposal or re-use of equipment

Key Physical Controls — Details

7.1 — Physical Security Perimeters

  • Divide physical areas into zones (Public vs. Restricted)
  • Perimeter protection: Landscaping, Fences, Gates, Bollards, CCTV, Perimeter IDS

7.2 — Physical Entry & Biometrics

3-Step Access Control:

① Identification  — Who are you?   (badge, user ID, biometrics)
② Authentication  — Prove it!      (have / know / are)
③ Authorization   — What can you do? (ACL-based)
Auth FactorExamples
Something you haveBadge, key, token
Something you knowPIN, password
Something you areFingerprint, iris scan, face

Biometrics Errors:

Error TypeWhat happens
False Negative (Type I)Legitimate user is rejected
False Positive (Type II)Unauthorized user is accepted

7.6 — Working in Secure Areas

  • Nobody may work alone in secure areas

7.11 — Supporting Utilities

  • UPS (Uninterruptible Power Supply) — for short outages
  • Generators / no-break systems — for longer outages

7.14 — Secure Disposal of Equipment

  • Procedures + technical tools for secure disposal of media (paper, disks) with classified data

Physical Controls Guidance

  • Zoning determines which areas need strict entry controls
  • Access rights must interface tightly with HR (onboarding, offboarding, role changes)
  • Check legislation before installing surveillance cameras (privacy laws)
  • Physical controls managed by facilities management — must collaborate with ICT + security
  • IT systems are vulnerable to electrical problems → backup power always required
  • Physical barriers must not block emergency exits

3.3 People Controls — Section 6 (8 controls)

Full List

ControlName
6.1Screening
6.2Terms and conditions of employment
6.3Information security awareness, education and training
6.4Disciplinary process
6.5Responsibilities after termination or change of employment
6.6Confidentiality or non-disclosure agreements
6.7Remote working
6.8Information security event reporting

Key People Controls — Details

6.1 — Screening

  • Especially for high-risk positions (financial, high confidentiality)
  • In case of fraud: investigating the employee's workstation may be the only legal option

6.3 — Information Security Awareness, Education & Training

Three aspects of InfoSec awareness:

AspectMeaning
KnowledgeUnderstanding the rules
AttitudeWillingness to cooperate
BehaviorActually obeying the rules

Tools: Class-based training, e-learning, one-to-one talks, gaming, discussion Key: Behavioral change only occurs when people understand why controls exist

6.6 — NDA / Confidentiality Agreements

  • Clarifies legal responsibilities for protecting confidential information

6.8 — Event Reporting

  • Clarifies responsibilities for reporting security events

People Controls Guidance

  • Four-eye principle: Admins should only use admin rights when another admin is present
  • Duties should be separated to reduce risk
  • Access rights reviewed periodically, especially when employees change roles
  • Key issues: Background screening / Clear job descriptions / Segregation of duties / Training

3.4 Technological Controls — Section 8 (34 controls)

Full List

ControlName
8.1User endpoint devices
8.2Privileged access rights
8.3Information access restriction
8.4Access to source code
8.5Secure authentication
8.6Capacity management
8.7Protection against malware
8.8Management of technical vulnerabilities
8.9Configuration management
8.10Information deletion
8.11Data masking
8.12Data leakage prevention
8.13Information back-up
8.14Redundancy of information processing facilities
8.15Logging
8.16Monitoring activities
8.17Clock synchronization
8.18Use of privileged utility programs
8.19Installation of software on operational systems
8.20Networks security
8.21Security of network services
8.22Segregation of networks
8.23Web filtering
8.24Use of cryptography
8.25Secure development life cycle
8.26Application security requirements
8.27Secure system architecture and engineering principles
8.28Secure coding
8.29Security testing in development and acceptance
8.30Outsourced development
8.31Separation of development, test and production environments
8.32Change management
8.33Test information
8.34Protection of information systems during audit testing

Key Technological Controls — Details

8.5 — Secure Authentication

Authentication method must match risk level:

Access TypeMethod
Internal web portalUsername + Password + MFA
VPN AccessCertificate + OTP Token
Developer APIOAuth 2.0 with scoped tokens
Service-to-ServiceMutual TLS with rotated certificates
Admin DashboardHardware Token + Biometric

8.7 — Protection Against Malware

  • Malware spreads via USB sticks and infected websites
  • Detection: signature-based OR behavior-based
  • May generate false positives; may fail to detect all malware
  • Logical bombs (hidden code that triggers later) — sometimes only detectable by human code review

8.11 — Data Masking

Purpose: Protect sensitive data (PII, financial, credentials) while preserving usability in non-production environments.

Masking Techniques:

TechniqueDescription
Static MaskingMasked data stored permanently in non-prod environments
Dynamic MaskingMasked on-the-fly during access via proxy/middleware
TokenizationValue replaced with token; original stored in secure vault
SubstitutionReplaced with realistic fake values (e.g., fake names)
ShufflingRandomly rearranges values within a column
Nulling / RedactionReplaces with blanks, NULL, or ****

Masking Example:

FieldOriginalMasked
Name"John Smith""Alex Lee" (substituted)
Credit Card"4111-1111-1111-1234""4111---1234"
Email"jane.doe@company.com""j***.***@company.com"
National ID"1234567890123""1234******123"

Masking vs. Tokenization vs. Encryption:

PropertyMaskingTokenizationEncryption
Reversible?❌ No (static)✅ Yes (via vault)✅ Yes (via key)
Format preserved?✅ Yes✅ Yes (configurable)❌ No
Primary use caseDev/test environmentsPayment processing (PCI)Data in transit/at rest

8.12 — Data Leakage Prevention (DLP)

What is data leakage? Unauthorized transfer of info outside org's boundaries.

TypeExample
UnintentionalMisdirected email, copy-paste into chat
MaliciousInsider threat, exfiltration via backdoor
Unsecured endpointUploading to personal cloud drive

DLP Implementation — 5 Steps:

① Identify Sensitive Data — classify, tag/label (e.g., MIP sensitivity labels)
② Deploy DLP Technologies
    ├── Network DLP  — monitors emails, web, FTP (data in motion)
    ├── Endpoint DLP — monitors USB, clipboard, print, screenshots
    ├── Cloud DLP    — SaaS protection (M365, Google Workspace)
    └── Content-Aware Inspection — regex/keyword (credit card numbers, national IDs)
③ Define DLP Policies — rules by content, context, channel
④ User Awareness & Training — educate on data handling
⑤ Monitor & Respond — log events, alert teams, integrate with SIEM/SOAR

DLP Policy examples:

  • Block documents labelled "Confidential" from being emailed to personal addresses
  • Block upload of spreadsheets with >10 SSNs to public cloud
  • Alert when >100 files are downloaded by one employee in 1 hour

8.15 — Logging

Events that must be logged:

  • Unauthorized access attempts
  • Changes to configuration or data
  • Privileged access attempts
  • Creation / modification / deletion of user IDs
  • System alarms

⚠️ Not all events = incident, but all events must be analyzed. All logs must be protected to preserve their own CIA (logs are evidence!).

8.19 — Software Installation on Operational Systems

  • Only authorized admins may install software
  • All software must be verified and tested for vulnerabilities first
  • Use CMDB (Configuration Management DB) to track installed software and versions
  • Use automated patch management to deploy vendor patches promptly

8.23 — Web Filtering

Purpose: Restrict access to malicious or non-business websites.

Implementation:

  • DNS filtering — intercepts DNS queries, evaluates against threat intel + policy + content categories
  • URL filtering + Secure Web Gateways
  • Maintain logging and monitoring of all web access

DNS Filtering Flow:

User types URL → DNS query sent → DNS filter intercepts →
checks against blacklists / org policy / content categories →
Allow ✅ or Block ❌

Best practices: Principle of least privilege for web access; regularly update blacklists/whitelists; combine technical + administrative controls.

8.24 — Use of Cryptography

Cryptography achieves:

GoalMeaning
ConfidentialityOnly authorized parties can read the data
IntegrityData has not been tampered with
Non-repudiationSender cannot deny sending the message
AuthenticationVerify identity of parties

Cryptography policy must define:

  • Principles for protecting information
  • Link to data classification (which classification requires encryption)
  • Encryption on specific vulnerable devices (phones, USB sticks)
  • Standards: algorithm, key length, key management

Hardware Security Module (HSM)

A dedicated hardware device that protects encryption keys and accelerates cryptographic operations.

Software Cryptography Weaknesses vs. HSM Strengths:

IssueSoftwareHSM
Memory protectionKeys in memory can be read by other processesDedicated internal memory — inaccessible to outsiders
Integrity assuranceCode can be tampered withTamper-proof hardware
Reverse engineeringCode can be decompiledNo external access
OS dependencyDepends on OS securityOwn micro-controller + crypto processor
Key storageSubject to brute-forceTamper-proof; key generation + usage + storage + destruction all within HSM
PerformanceUnpredictablePurpose-built cryptographic processor

HSM FIPS Standards: ⭐ Exam Note

  • FIPS 140-1 Level 2
  • FIPS 140-2 Level 3 (higher assurance)

HSM Types:

TypeExample
General PurposeLuna SA
Network AttachedLuna SA
Payment HSMLuna EFT2
Authentication TokeniKey 5110
PCI CardLuna PCI-E / Protect Server External (PSE)

8.20–8.22 — Network Security

Firewall Type Recap (from ISO perspective):

Firewall TypeHow It Works
Packet FilteringInspects header only; drops/rejects based on src/dst addr, protocol, port; no state tracking
StatefulRecords all connections; determines if packet is new/existing/unrelated; rules can include state
Application LayerUnderstands app protocols (FTP, DNS, HTTP); detects protocol abuse or bypass attempts

8.31 — Separation of Dev / Test / Production Environments

  • Authorization required every time data is moved:
    • Production → Test
    • Test → Production
  • Increases data integrity and ensures alignment with InfoSec policy

Service Oriented Architecture (SOA) & Security

  • Architecture where apps use services available in the network
  • Two roles: Service Provider (publishes services + contract) / Service Consumer (uses services)
  • InfoSec team must be involved when designing SOA-based systems

Common Criteria (ISO/IEC 15408) — EAL Levels

  • Framework for evaluating security products (firewalls, access control equipment)
  • Three parties: Users (specify requirements) / Vendors (make claims) / Testing Labs (evaluate)
  • Products receive an Evaluation Assurance Level (EAL):
EAL LevelAssurance
EAL 1Basic (lowest)
EAL 4Methodically designed, tested, reviewed
EAL 7Formally verified design and tested (most stringent)

5 Tips for Successful ISO 27001 Implementation

  1. Get senior management involved — policy enforcement + budget allocation
  2. Produce a gap analysis — may need professional consultants
  3. Gain cross-functional support from colleagues across departments
  4. Develop a project plan with key milestones
  5. Focus on continual improvement — PDCA never stops

⚡ Key Facts to Remember

FactDetail
ISO 27001 usesPDCA cycle — Plan (4–6) → Do (7–8) → Check (9) → Act (10)
93 controls in4 themes: Org(37) + People(8) + Physical(14) + Tech(34)
SoAStatement of Applicability — documents which controls are applied
Gap AnalysisTells you what's missing vs. ISO 27001
Risk AssessmentTells you what controls to apply
Risk treatment optionsAccept / Mitigate / Transfer / Avoid
RTOMax time to restore a service after disaster
RPOMax data loss acceptable (how old the backup can be)
BIADetermines Maximum Acceptable Outage → feeds RTO
Data classification benefit ⭐Allows appropriate access control per class
Information classification levelsPublic / Confidential / Highly Confidential
Threat intelligence levelsStrategic (exec) / Tactical (TTPs) / Operational (IoCs)
Four-eye principleAdmin actions require a second admin present
HSM FIPS 140-2 Level 3 ⭐High assurance hardware key protection standard
Static maskingPermanently replaces data in non-prod env — not reversible
TokenizationReversible via vault — used in payment processing (PCI)
EncryptionReversible via key — used in transit/at rest — does NOT preserve format
DLP =Prevent unauthorized data from leaving the org
Logging ruleAll events must be analyzed; logs must be protected (CIA)
Biometric Type I errorFalse Negative — legitimate user rejected
Biometric Type II errorFalse Positive — unauthorized user accepted
EAL 7Most stringent Common Criteria assurance level
CMDBConfiguration Management DB — tracks installed software versions
Backup ≠ restoreBackup is only part of the solution — restore within RTO is the real challenge