27010-10.1 | Cryptographic Protection | 137 |
27010-11.1 | Physical Protection | 27 |
27010-12.1 | Operational Procedures | 3 |
27010-12.2 | Protection from malware | 36 |
27010-13.1 | Communications Security | 65 |
27010-13.2 | Information transfer | 5 |
27010-14.1 | Supplier and Third Party Handling | 0 |
27010-15.1 | Incident Management | 75 |
27010-16.1 | Continuity of Sharing | 142 |
27010-17.1 | Compliance | 34 |
27010-18.1 | Review and Improvement | 0 |
27010-19.1 | Trust Anchors and Reputation | 0 |
27010-4.1 | Information Sharing Community | 0 |
27010-4.2 | Sharing Agreements | 0 |
27010-5.1 | Management Direction | 3 |
27010-5.2 | Information sharing community policies | 0 |
27010-6.1 | Roles and Responsibilities | 2 |
27010-6.2 | Contact with Authorities | 3 |
27010-7.1 | Information Classification for Sharing | 17 |
27010-7.2 | Handling Shared Information | 0 |
27010-8.1 | Membership Onboarding | 28 |
27010-8.2 | Membership Termination | 51 |
27010-9.1 | Access Control to Shared Information | 126 |
27010-9.2 | Authentication of Sources | 135 |
27010-A | Benefits of information sharing | 0 |
27010-B | Trust assessment guidance | 0 |
27010-C | Traffic Light Protocol | 0 |
27010-D | Information sharing community models | 0 |
1-3 | Scope, normative references, terms and definitions | 0 |
10.1 | Cryptographic controls | 0 |
10.1.1 | Policy on the use of cryptographic controls | 0 |
10.1.2 | Key management | 0 |
12.2 | Protection from malware | 0 |
12.2.1 | Controls against malware | 0 |
12.4 | Logging and monitoring | 0 |
12.4.1 | Event logging | 0 |
12.4.2 | Protection of log information | 0 |
12.4.3 | Administrator and operator logs | 0 |
12.4.4 | Clock synchronization | 0 |
12.7 | Information systems audit considerations | 0 |
12.7.1 | Information systems audit controls | 0 |
12.7.2 | Community audit rights | 0 |
13.2 | Information transfer | 0 |
13.2.1 | Information transfer policies and procedures | 0 |
13.2.2 | Agreements on information transfer | 0 |
13.2.3 | Electronic messaging | 0 |
13.2.4 | Confidentiality or non-disclosure agreements | 0 |
15.1 | Information security in supplier relationships | 0 |
15.1.1 | Information security policy for supplier relationships | 0 |
15.1.2 | Addressing security within supplier agreements | 0 |
15.1.3 | Information and communication technology supply chain | 0 |
16.1 | Management of information security incidents and improvements | 0 |
16.1.1 | Responsibilities and procedures | 0 |
16.1.2 | Reporting information security events | 0 |
16.1.3 | Reporting information security weaknesses | 0 |
16.1.4 | Assessment of, and decision on, information security events | 0 |
16.1.5 | Response to information security incidents | 0 |
16.1.6 | Learning from information security incidents | 0 |
16.1.7 | Collection of evidence | 0 |
16.1.8 | Early warning system | 0 |
17.1 | Information security continuity | 0 |
17.1.1 | Planning information security continuity | 0 |
17.1.2 | Implementing information security continuity | 0 |
17.1.3 | Verify, review and evaluate information security continuity | 0 |
18.1 | Compliance with legal and contractual requirements | 0 |
18.1.1 | Identification of applicable legislation and contractual requirements | 0 |
18.1.2 | Intellectual property rights | 0 |
18.1.3 | Protection of records | 0 |
18.1.4 | Privacy and protection of personally identifiable information | 0 |
18.1.5 | Regulation of cryptographic controls | 0 |
18.1.6 | Liability to the information sharing community | 0 |
4.1 | Introduction to the concepts | 0 |
4.2 | Information sharing communities | 0 |
4.3 | Community management | 0 |
4.4 | Supporting entities | 0 |
4.5 | Inter-sector communication | 0 |
4.6 | Conformity: interpreting ISO/IEC 27001:2013 for a community | 0 |
4.7 | Communications model | 0 |
5.1 | Management direction for information security | 0 |
5.1.1 | Policies for information security | 0 |
5.1.2 | Review of the policies for information security | 0 |
7.1 | Prior to employment | 0 |
7.1.1 | Screening | 0 |
8.1 | Responsibility for assets | 0 |
8.1.3 | Acceptable use of assets | 0 |
8.1.4 | Return of assets | 0 |
8.2 | Information classification | 0 |
8.2.1 | Classification of information | 0 |
8.2.2 | Labelling of information | 0 |
8.2.3 | Handling of assets | 0 |
8.4 | Information exchanges protection | 0 |
8.4.1 | Information dissemination | 0 |
8.4.2 | Information disclaimers | 0 |
8.4.3 | Information credibility | 0 |
8.4.4 | Information sensitivity reduction | 0 |
8.4.5 | Anonymous source protection | 0 |
8.4.6 | Anonymous recipient protection | 0 |
8.4.7 | Onwards release authority | 0 |
ANNEXES | Annexes A to D (informative) | 0 |