Table 7.

ISO/IEC controls classification for SCP ‘S3 Reduce the Rewards’.

SCP TechniqueClause TypeISO/IEC Control
#11 Conceal TargetsOrganizational5.12 Classification of information
#11 Conceal TargetsPhysical7.07 Clear desk and clear screen
#11 Conceal TargetsTechnological8.03 Information access restriction
#11 Conceal TargetsTechnological8.04 Access to source code
#11 Conceal TargetsTechnological8.11 Data masking
#11 Conceal TargetsTechnological8.24 Use of cryptography
#12 Remove TargetsPhysical7.14 Secure disposal or re-use of equipment
#12 Remove TargetsTechnological8.10 Information deletion
#13 Identify PropertyOrganizational5.09 Inventory of information and other associated assets
#13 Identify PropertyOrganizational5.13 Labelling of information
#14 Disrupt MarketsOrganizational5.05 Contact with authorities
#14 Disrupt MarketsOrganizational5.14 Information transfer
#14 Disrupt MarketsOrganizational5.26 Response to information security incidents
#15 Deny BenefitsOrganizational5.30 ICT readiness for business continuity
#15 Deny BenefitsTechnological8.06 Capacity management
#15 Deny BenefitsTechnological8.13 Information backup
#15 Deny BenefitsTechnological8.14 Redundancy of information processing facilities
SCP TechniqueClause TypeISO/IEC Control
#11 Conceal TargetsOrganizational5.12 Classification of information
#11 Conceal TargetsPhysical7.07 Clear desk and clear screen
#11 Conceal TargetsTechnological8.03 Information access restriction
#11 Conceal TargetsTechnological8.04 Access to source code
#11 Conceal TargetsTechnological8.11 Data masking
#11 Conceal TargetsTechnological8.24 Use of cryptography
#12 Remove TargetsPhysical7.14 Secure disposal or re-use of equipment
#12 Remove TargetsTechnological8.10 Information deletion
#13 Identify PropertyOrganizational5.09 Inventory of information and other associated assets
#13 Identify PropertyOrganizational5.13 Labelling of information
#14 Disrupt MarketsOrganizational5.05 Contact with authorities
#14 Disrupt MarketsOrganizational5.14 Information transfer
#14 Disrupt MarketsOrganizational5.26 Response to information security incidents
#15 Deny BenefitsOrganizational5.30 ICT readiness for business continuity
#15 Deny BenefitsTechnological8.06 Capacity management
#15 Deny BenefitsTechnological8.13 Information backup
#15 Deny BenefitsTechnological8.14 Redundancy of information processing facilities
Table 7.

ISO/IEC controls classification for SCP ‘S3 Reduce the Rewards’.

SCP TechniqueClause TypeISO/IEC Control
#11 Conceal TargetsOrganizational5.12 Classification of information
#11 Conceal TargetsPhysical7.07 Clear desk and clear screen
#11 Conceal TargetsTechnological8.03 Information access restriction
#11 Conceal TargetsTechnological8.04 Access to source code
#11 Conceal TargetsTechnological8.11 Data masking
#11 Conceal TargetsTechnological8.24 Use of cryptography
#12 Remove TargetsPhysical7.14 Secure disposal or re-use of equipment
#12 Remove TargetsTechnological8.10 Information deletion
#13 Identify PropertyOrganizational5.09 Inventory of information and other associated assets
#13 Identify PropertyOrganizational5.13 Labelling of information
#14 Disrupt MarketsOrganizational5.05 Contact with authorities
#14 Disrupt MarketsOrganizational5.14 Information transfer
#14 Disrupt MarketsOrganizational5.26 Response to information security incidents
#15 Deny BenefitsOrganizational5.30 ICT readiness for business continuity
#15 Deny BenefitsTechnological8.06 Capacity management
#15 Deny BenefitsTechnological8.13 Information backup
#15 Deny BenefitsTechnological8.14 Redundancy of information processing facilities
SCP TechniqueClause TypeISO/IEC Control
#11 Conceal TargetsOrganizational5.12 Classification of information
#11 Conceal TargetsPhysical7.07 Clear desk and clear screen
#11 Conceal TargetsTechnological8.03 Information access restriction
#11 Conceal TargetsTechnological8.04 Access to source code
#11 Conceal TargetsTechnological8.11 Data masking
#11 Conceal TargetsTechnological8.24 Use of cryptography
#12 Remove TargetsPhysical7.14 Secure disposal or re-use of equipment
#12 Remove TargetsTechnological8.10 Information deletion
#13 Identify PropertyOrganizational5.09 Inventory of information and other associated assets
#13 Identify PropertyOrganizational5.13 Labelling of information
#14 Disrupt MarketsOrganizational5.05 Contact with authorities
#14 Disrupt MarketsOrganizational5.14 Information transfer
#14 Disrupt MarketsOrganizational5.26 Response to information security incidents
#15 Deny BenefitsOrganizational5.30 ICT readiness for business continuity
#15 Deny BenefitsTechnological8.06 Capacity management
#15 Deny BenefitsTechnological8.13 Information backup
#15 Deny BenefitsTechnological8.14 Redundancy of information processing facilities
Close
This Feature Is Available To Subscribers Only

Sign In or Create an Account

Close

This PDF is available to Subscribers Only

View Article Abstract & Purchase Options

For full access to this pdf, sign in to an existing account, or purchase an annual subscription.

Close