Risk-Based Security
What is Risk-Based Security?
An approach to security that prioritizes investments and efforts based on the level of risk to the organization rather than applying uniform controls.
Frameworks that govern risk-based security
What the standards actually require on risk-based security
Requirements naming risk-based security across 2 standards, quoted from the control text.
Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or...
JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience · Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pseudonymisation + Risk-Based Security →Separate trusted from untrusted networks into risk-based security zones, configure physical and virtual networks to restrict and monitor those connections, reassess that design at least annually, and periodically re-justify every service, port and protocol in...
C5-COS-03 · Monitoring of connections in the Cloud Service Provider's network →Questions people ask about risk-based security
What is Risk-Based Security?
Why is Risk-Based Security important for compliance?
Which compliance frameworks address Risk-Based Security?
Where can I learn more about Risk-Based Security?
See how Risk-Based Security applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.