ANSWERS WITH COMPLETE SOLUTIONS GRADED A++
3 main categories of CSMS:
- Risk Analysis
- Addressing risk with the CSMS
- Monitoring and improving the CSMS
Elements of the "risk analysis" CSMS category:
- Business rationale
- Risk identification, classification and assessment
3 element groups of the "assessing risk with the CSMS" category:
- Security policy, organization and awareness
- Selected security countermeasures
- Implementation
CSMS > Addressing risk with the CSMS > Security policy, organization, and
awareness > 5 elements?
- CSMS scope
- Organize for security
- Staff training and security awareness
- Business continuity plan
- Security policies and procedures