← Back to courses

Information Security Management: Module 4

Security Management Frameworks and Controls Management

Learn about the different security management frameworks and controls frameworks.

Estimated reading time

12 minutes

What are security management frameworks?

According to Rhodes, security management frameworks provide a structured management of information security for companies and organisations. These frameworks offer a starting point for organisations that do not have information management or have a disorganised information management. It is also used to plan information security in the workplace and inform stakeholders that risks are being managed properly.

ISO 27001 Information Security Management Systems

According to Rhodes, this framework contains the requirements for implementing an Information Security Management System (ISMS). It aims to align risk management with the organisation's goals, so it works best with any organisation.

This is a framework often used in countries like the UK and Australia, but is less popular in the United States. In fact, most Queensland State Government agencies are required to have an ISMS based on the framework stated in ISO 27001.

ISO 27002

This is a popular framework that also pairs well with ISO 27001. It is also known for covering controls that are not necessarily technology-based.

However, both ISO 27001 and 27002 costs money to own. Moreover, ISO 27002 requires an information security professional to apply it since implementation of the controls are difficult to understand. It also does not provide mappings to other well-known frameworks.

NIST Cybersecurity Framework

While this framework was made by the US Government, it can be used by any sector from any industry. This framework also focuses on the big picture of cybersecurity. The NIST documents are available without cost and has been frequently reviewed and updated by the US government and industry professionals. It also comes with special publications to allow the organisation to customise their own information security program.

Cloud Security Alliance Cloud Controls Matrix

The Cloud Security Alliance (CSA) Cloud Controls Matrix is a controls management framework for cloud service providers. However, it is not suited for other organisations. While it is not an information security management framework, it does supply third-party risk management.

What are security controls frameworks?

Security controls frameworks have a baseline standard to measure the maturity of implemented controls. They are an ideal choice for professionals who are not experts in information security, especially when the current controls implemented are disorganised or minimal. They also ensure that all possible controls are regarded while planning and performing risk assessments.

ISO 27002

ISO 27002 not only supplements the security framework ISO 27001, it also has a list of controls for implementing an information security management system. It also has controls for managing risk.

Secure Controls Framework (SCF)

The SCF is a list of about 750 catalogued controls that allows businesses to create and maintain secure processes and systems. Designed by information security and privacy professionals, it provides controls suitable for both cybersecurity and privacy, and covers 32 domains such as asset management, cloud security and more. The controls listed also may not involve technology.

Moreover, it is free to view and implement and can be customised to the business's needs. It also contains questions for performing a maturity assessment. However, this framework requires an information security professional to apply the controls.

The Center for Internet Security (CIS)

Contains practical resources such as

  • CIS Controls
  • CIS Benchmarks
  • CIS Hardened Images

The CIS Controls are a list of 20 controls that should be prioritised, and are based on the best defences against common attacks. However, it is best used when it is customised to the business's priorities and which assets require the most security. CIS also has a free risk assessment in CIS Risk Assessment Method (CIS RAM) to allow users to knows which controls to prioritise. The CIS Controls is not only free, but it also has many accessible educational resources for implementing them. However, it only has technology controls and not a lot of information on how to map it to other controls frameworks.

The benchmarks were created as a configuration guide for many devices, software and operating systems. The hardended images referred to versions of an operating system were unused features are disabled. These are available for deployment in AWS, Google Cloud, Azure and Oracle Cloud.

Sources

Rhodes, A. (2023). IFN541 Information Security Management: Security Management Frameworks. [Presentation]. Canvas.
Previous Next