
Security toolbox protects organizations from cyber-attacks
Geneva, Switzerland, 2015-12-17 - Cyber-attacks are among the greatest risks an organization can face. Having standards and systems in place to keep information safe has therefore never been more important than in today's digital world. This is why the ISO/IEC 27000 series on security techniques for information technology has been updated to provide organizations with that added value and confidence.
In a global survey conducted by ISACA in 129 countries, only 38 % of respondents felt they were prepared for a cyber-attack - even though 83 % believed these are among the top three threats facing organizations today. With so much personal and sensitive information being handled electronically, there is a lot at stake if it were to be compromised.
Prof. Edward Humphreys, convenor of ISO/IEC Joint Technical Committee (JTC) 1 SC 27: IT security techniques, WG 1: Information security management systems (ISMS), emphasizes, To ensure security in today's digital landscape, all organizations, irrespective of size, should put in place a management framework as a starting point to manage cyber risks. ISO/IEC 27001 was designed to help organizations do just that. The Standard is the world's common language' when it comes to assessing, treating and managing information-related risks.
Below are the latest revisions and additions to the ISO/IEC 27000 series - all published in 2015 - which form part of the ISO/IEC 27001 cyber risk toolbox , to help keep these risks in check.
Protecting information in the cloud (ISO/IEC 27017)
A new code of practice for information security controls for cloud services, ISO/IEC 27017, has just been published. The cloud is one of the most widely used innovations in today's fast-paced world of commerce and business. As the service gains currency, users are demanding assurances that data stored and processed in the cloud is safe. Because of its very nature, the marketplace for cloud services is global, with providers dispersed across wide geographical areas, and data is routinely transferred across national boundaries. International guidance is therefore key.
According to Satoru Yamasaki, one of editors who worked on the Standard, ISO/IEC 27017 will help service providers come to a common understanding with their customers regarding adequate security controls and their implementation guidance. This International Standard for cloud security controls will facilitate the development and expansion of secure cloud computing systems.
The new guidelines are the result of a joint initiative by the world's main developers of International Standards - IEC, ISO, and ITU - to guarantee maximum outreach.
Integrated solutions for services (ISO/IEC 27013)
More organizations are choosing to combine an information security management system (ISO/IEC 27001) with a service management system (ISO/IEC 20000-1). An integrated system means an organization can efficiently manage the quality of its services, handle customer feedback and solve problems, while keeping information safe. ISO/IEC 27013 offers a systematic approach to facilitate the integration of an information security management system with a service management system, which results in lower implementation costs and avoids duplication efforts as only one audit, instead of two, is needed when seeking certification.
Inter-sector and inter-organizational communications (ISO/IEC 27010)
When an organization shares information with another organization, how can they be sure that their data will be kept safe? ISO/IEC 27010 is a sector-specific addition to the ISO/IEC 27000 toolbox, which guides the initiation, implementation, maintenance and improvement of information security in inter-organizational and inter-sector communications. It includes general principles on how to meet these requirements using established messaging and other technical methods. The Standard is expected to encourage the growth of global information-sharing communities.
As Dr. Mike Nash, an editor of ISO/IEC 27010, explains, ISO/IEC 27010 basically customizes and applies ISO/IEC 27001 and ISO/IEC 27002 to communication between organizations. Having the Standard in place gives an organization confidence that the information it has shared with another organization will not be inadvertently disclosed.
The Standard is particularly relevant for the protection of critical national infrastructure, where exchanging sensitive information securely is of utmost importance. It is also widely used by security incident response teams.
Detecting and preventing cyber-attacks (ISO/IEC 27039)
How can organizations detect and prevent cyber intrusions to their networks, systems and applications? Best practice shows that they have to be able to know when, if and how an intrusion into their network, system or application occurs. They should also be ready to identify what vulnerability was exploited and what controls should be implemented to prevent similar intrusions from taking place in the future. One way to do this is through an Intrusion Detection and Prevention Systems (IDPS).
ISO/IEC 27039 gives guidelines to prepare and deploy an IDPS, covering such crucial aspects as selection, deployment and operation. The Standard is particularly useful in today's market where there are many commercially available and open-source IDPS products and services based on different technologies and approaches. ISO/IEC 27039 will guide organizations throughout the process.
Audit and certification (ISO/IEC 27006)
More and more organizations are turning to third-party certification audits to demonstrate that they have in place a solid information security management system (ISMS) that conforms to the requirements of ISO/IEC 27001. ISO/IEC 27006 gives the requirements that certifi
Most recent headlines
01/04/2025
USHER's London takeover is in full swing. After kicking off his sold-out run of shows at the O2 Arena to rave reviews, the R&B icon joined forces with Spoti...
01/04/2025
Innovative program empowers partners with growth, efficiency and collaboration
Herndon, Va., April 1, 2025 ST Engineering iDirect, a global leader in satelli...
01/04/2025
MELBOURNE, Fla., April 1, 2025 - L3Harris Technologies (NYSE: LHX) will release its first quarter 2025 financial results before the market opens on Thursday, Ap...
01/04/2025
Calrec Craft Interview: Aston Fearon, Sound Supervisor In this craft interview, Aston Fearon speaks to us about how his career in sound started, projects he'...
01/04/2025
MONT-SAINT-GUIBERT, Belgium Telestream has integrated intoPIX's JPEG XS technology into Telestream's PRISM waveform monitors, which Telestream says will...
01/04/2025
BURLINGTON, Mass. Avid has signed a strategic collaboration agreement with Amazon Web Services (AWS), to deliver a cloud-based production framework that helps f...
01/04/2025
LONDON and NEW YORK The United Football League (UFL) has signed a new global partnership with sports broadcaster DAZN to broadcast every game of the UFL's 2...
01/04/2025
In a groundbreaking bid to streamline and democratize the production process, Netflix has laid out how it is developing a new Media Production Suite, that t...
01/04/2025
PHILADELPHIA Comcast Business has announced that it has completed its acquisition of Nitel, a U.S. managed services provider headquartered in Chicago, from inte...
01/04/2025
NEW YORK A team of research industry veterans, led by Tod Johnson have launched a new consumer insights and analytics platform, Tenetic, that offers both local ...
01/04/2025
V-Nova, a leading provider of compression solutions, today announced its inaugural participation in a patent pool, joining the Access Advance HEVC Patent Pool. ...
01/04/2025
Cinnafilm, a global leader in video optimization solutions, today announced that it will launch Tachyon LIVE, its groundbreaking live IP standards and format co...
01/04/2025
HighField AI, an advanced AI-powered solution designed to automate repetitive tasks within the media production workflow, today announced that it will demonstra...
01/04/2025
Globecast has expanded its use of Net Insight's Nimbra technology by deploying Nimbra Edge, significantly streamlining its media transport operations. This ...
01/04/2025
EdgePeak enables software architects and developers to design and build their own content delivery network (CDN) while reducing streaming costs, fighting video...
01/04/2025
Cinnafilm to preview the innovation at the 2025 NAB Show
Cinnafilm, a global leader in video optimization, has collaborated with NVIDIA to unveil a groundbreak...
01/04/2025
Leading video software provider Synamedia, will showcase its innovation-driven approach to solving the biggest challenges facing customers today and in the futu...
01/04/2025
AJA Debuts IP and 12G-SDI Innovations Ahead of NAB 2025
Brie Clayton April 1, 2025
0 Comments
New tools optimize media and entertainment and proAV wo...
01/04/2025
Bit Part Introduces bitbox mini, the Smallest and Lightest Solution for Ultra-Lo...
01/04/2025
IABM Unveils Bold Transformation at NAB Show, Prioritizing Member Value
Brie Clayton April 1, 2025
0 Comments
IABM is delivering a strategic transform...
01/04/2025
OOONA Introduces Multilingual QC Tool for Subtitling Workflows
Brie Clayton April 1, 2025
0 Comments
See OOONA on booth W4209 at the NAB Show, Las Veg...
01/04/2025
Adopting open standards, the solution aims to provide workflow standardisation, allowing for automation and other innovations across a diverse range of markets
...
01/04/2025
Submissions will be accepted up until 23:59 PST on 2nd April
By Jenny Priestley
Published: March 24, 2025 Updated: April 1, 2025
Submissions will be acc...
01/04/2025
The AI issue takes a look at how AI is reshaping broadcasting, including areas such as sports commentary and archiving and storage, plus we discover how Norways...
01/04/2025
Joining the company with more than two decades of experience forging and scaling alliances in the industry, Wastcoats role will support TVUs strategic developme...
01/04/2025
At the beginning of the year, Rich Welsh, senior vice president with Deluxe, was appointed the new president of Society of Motion Picture and Television Enginee...
01/04/2025
STAMFORD, Conn. and NEW YORK Charter's Spectrum pay TV operations are continuing its previously announced strategy of adding more streaming services to its ...
01/04/2025
HUNT VALLEY, Md. Sinclair, Inc. and its subsidiary, ONE Media Technologies, have announced that members of their leadership team will be participating in multip...
01/04/2025
01 04 2025 - Media release Bus Stop Films' first feature Boss Cat to begin production in June
Boss Cat cast (L-R): Olivia Hargroder, Penny Downie and Juli...
01/04/2025
PremiumBeat - Flexible, Unlimited Music For Creators
Brie Clayton March 31, 2025
0 Comments
Back in November of 2024, PremiumBeat made a bold move tha...
01/04/2025
MLB 2025: TNT Sports Chooses Remote Production for MLB Tuesday,' Upgrades C...
01/04/2025
SVG All-Stars: Francisco Contreras, Executive Director, Field Operations, FOX Sp...
01/04/2025
MILTON drones get a boost with Rohde & Schwarz SIGINT integration Rohde & Schwarz and MILTON have partnered to integrate advanced signals intelligence technol...
01/04/2025
Rohde & Schwarz presents comprehensive R&S ELEKTRA portfolio for reproducible, s...
01/04/2025
Create Complex Compositions with Unlimited Layers with FOR-A MixBoard Powered by ClassX...
01/04/2025
Article courtesy of Digital Production Germany
Read the article
Digital Production Germany magazine editor, Bela Beier, recently talked to Nara's Steve Br...
01/04/2025
Article courtesy of Digital Media World
Read the article
Light Iron uses Nara to handle file navigation, content streaming and information sharing workflow ef...
01/04/2025
Article courtesy of British Cinematographer
Read the article
DoP Don Burgess, VFX supervisor Kevin Baillie and colourist Maxine Gervais pulled their talents t...
01/04/2025
Polesi ski made a name for himself early in his career. Renowned for his attention to detail and ability to mix his creative and technical skills, Polesi ski st...
01/04/2025
visionOS 2.4 is available today, bringing the first set of powerful Apple Intelligence features that help users communicate, write, and express themselves on Ap...
01/04/2025
Facebook
Twitter
LinkedIn
Defence Science and Technology Agency (DSTA) and...
31/03/2025
Ready, set, Party Time!' SBS News empowers young voters with a new politica...
31/03/2025
31 January, 2024
Company News
Tokyo, January 31, 2024 - Hitachi, Ltd. (TSE:6501) today announced the following executive
changes to improve corporate value....
31/03/2025
MELBOURNE, Fla., March 31, 2025 - L3Harris Technologies (NYSE: LHX) has complete...
31/03/2025
Vice Admiral Jan Willem Hartman, commander of the Dutch Materiel and IT Command, and Chris Aebli, President, Tactical Communications, L3Harris Technologies, sig...
31/03/2025
The L3Harris team visited HMS GLASGOW, the first T26 Global Combat Ship, current...
31/03/2025
SEATTLE As the WNBA prepares to kick off the 2025 season, the Seattle Storm WNBA team has announced a multi-year deal with Sinclair's KOMO and KUNS station...
31/03/2025
Digital Nirvana, a provider of leading-edge AI-powered media solutions, today announced a global Alliance Partnership with Avid to bring advanced AI metadata c...
31/03/2025
BeckTV, a premier systems integrator for the broadcast media industry, today announced that Kate Gazdic has joined the company as a senior procurement specialis...
31/03/2025
MainConcept, a leading provider of video and audio codecs, has announced a series of key codec advancements that enable customers to realize significant time an...