2. ISO 2700x
The International Organization for Standardization (ISO)
publishes around a dozen mutually complementary
standards on cybersecurity. These are referred to as the
‘2700x family’. The best-known of these is ISO 27001.
It specifies the requirements for setting up, implementing,
maintaining and continuously improving a documented
information security management system compatible with
the context of the organisation concerned.5
3. COBIT
Control Objectives for Information and Related Technology
(COBIT) 6
4. ENISA Good Practice Guide on National Cyber Security
Strategies.7
5. Federal Office for Information Security (Germany),
BSI 100-2.8
1.5 Introducing the Minimum ICT Standard
This section presents the key issues addressed by the Minimum
ICT Standard.
1.5.1 Principles of cybersecurity
A business must first define its cybersecurity principles before
it can put them into effect in its operations. Specifically, it must
answer the following questions:
•
•
•
•
What is to be done?
How is it to be done?
Who is responsible?
How will the outcome be measured?
Cybersecurity principles set out the rules, procedures, metrics
and organisational structures which are required for effective
planning and control.
1.4.2 Principles
1.5.2 Organisation and responsibilities
1. Independent responsibility: operators of critical infrastructures have a fundamental independent responsibility
to maintain their critical ICT processes.
As a basis for cybersecurity, a business must have a general
security organisation which defines clear tasks, responsibilities
and authorities. This should also provide the framework for defining and implementing the defence-in-depth strategy. Cyber
risks should form part of global risk management. This is key
to recognising potential cyber threats and to defining the appropriate action. The security organisation must enable senior
management to decide on the necessary resources. This level of
management must also equip the security organisation with the
proper powers to perform their core tasks without limitation in
close cooperation with the various areas of the business.
2. Business continuity management: all aspects of
cybersecurity should be integrated into an overarching
business continuity management structure.
3. Risk management: those applying these standards must
assess possible cyber risks – such as impairments to
availability, integrity and confidentiality – on an ongoing
basis. The business must judge which risks should be
mitigated, and which it is willing to bear.
1.4.3 Measures and references in this document
Wherever possible, the authors have avoided duplicating information. Instead, they refer to other cybersecurity standards.
Those applying this Standard are advised to consult the stated
sources where necessary.
5
https://www.iso.org/standard/66435.html
6
http://www.isaca.org/COBIT/Pages/default.aspx
7
https://www.enisa.europa.eu/topics/national-cyber-security-strategies
8
https://www.bsi.bund.de/EN/TheBSI/thebsi_node.html;jsessionid=
1.5.3 Policy, directives and guidelines
Before a cybersecurity strategy (such as a defence-in-depth strategy) can be put into effect, the policy, procedures and working
directives of an organisation must be identified, or in some cases
defined.
Those responsible for cybersecurity must be notified of the business requirements of the various business units. These requirements must also be documented. They might be legal, financial,
strategic or operational in nature, for example.
2012D9CA020E153625E39AFEE673D910.1_cid341
Minimum ICT standard 2018
5