Domain 1—Information Security Governance Establish and maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives, information risk is managed appropriately and program resources are managed responsibly.
Domain 2—Information Risk Management and Compliance Manage information risk to an acceptable level to meet the business and compliance requirements of the organization.
Domain 3—Information Security Program Development and Management Establish and manage the information security program in alignment with the information security strategy.
Domain 4—Information Security Incident Management Plan, establish and manage the capability to detect, investigate, respond to and recover from information security incidents to minimize business impact.
Сургалтын зорилго
Governance of Information Security
Information Risk Management and Compliance
Information Security Incident Management
Information Security Program Development and Management