Udemy
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
Development
Web Development Data Science Mobile Development Programming Languages Game Development Database Design & Development Software Testing Software Engineering Software Development Tools No-Code Development
Business
Entrepreneurship Communication Management Sales Business Strategy Operations Project Management Business Law Business Analytics & Intelligence Human Resources Industry E-Commerce Media Real Estate Other Business
Finance & Accounting
Accounting & Bookkeeping Compliance Cryptocurrency & Blockchain Economics Finance Finance Cert & Exam Prep Financial Modeling & Analysis Investing & Trading Money Management Tools Taxes Other Finance & Accounting
IT & Software
IT Certifications Network & Security Hardware Operating Systems & Servers Other IT & Software
Office Productivity
Microsoft Apple Google SAP Oracle Other Office Productivity
Personal Development
Personal Transformation Personal Productivity Leadership Career Development Parenting & Relationships Happiness Esoteric Practices Religion & Spirituality Personal Brand Building Creativity Influence Self Esteem & Confidence Stress Management Memory & Study Skills Motivation Other Personal Development
Design
Web Design Graphic Design & Illustration Design Tools User Experience Design Game Design 3D & Animation Fashion Design Architectural Design Interior Design Other Design
Marketing
Digital Marketing Search Engine Optimization Social Media Marketing Branding Marketing Fundamentals Marketing Analytics & Automation Public Relations Paid Advertising Video & Mobile Marketing Content Marketing Growth Hacking Affiliate Marketing Product Marketing Other Marketing
Lifestyle
Arts & Crafts Beauty & Makeup Esoteric Practices Food & Beverage Gaming Home Improvement & Gardening Pet Care & Training Travel Other Lifestyle
Photography & Video
Digital Photography Photography Portrait Photography Photography Tools Commercial Photography Video Design Other Photography & Video
Health & Fitness
Fitness General Health Sports Nutrition & Diet Yoga Mental Health Martial Arts & Self Defense Safety & First Aid Dance Meditation Other Health & Fitness
Music
Instruments Music Production Music Fundamentals Vocal Music Techniques Music Software Other Music
Teaching & Academics
Engineering Humanities Math Science Online Education Social Science Language Learning Teacher Training Test Prep Other Teaching & Academics
Web Development JavaScript React Angular CSS Node.Js PHP HTML5 Vue JS
AWS Certification Microsoft Certification AWS Certified Solutions Architect - Associate AWS Certified Cloud Practitioner CompTIA A+ Amazon AWS Cisco CCNA Microsoft AZ-900 AWS Certified Developer - Associate
Microsoft Power BI SQL Tableau Data Modeling Business Analysis Business Intelligence MySQL Qlik Sense Blockchain
Unity Unreal Engine Game Development Fundamentals C# 3D Game Development C++ Unreal Engine Blueprints 2D Game Development Virtual Reality
Google Flutter Android Development iOS Development React Native Swift Dart (programming language) Mobile App Development Kotlin SwiftUI
Graphic Design Photoshop Adobe Illustrator Drawing Digital Painting Canva InDesign Character Design Procreate Digital Illustration App
Life Coach Training Neuro-Linguistic Programming Personal Development Personal Transformation Life Purpose Mindfulness Meditation CBT Cognitive Behavioral Therapy Sound Therapy
Entrepreneurship Fundamentals Business Fundamentals Freelancing Business Strategy Startup Business Plan Online Business Blogging Home Business
Digital Marketing Social Media Marketing Marketing Strategy Internet Marketing Google Analytics Copywriting Email Marketing YouTube Marketing Drop Servicing

BusinessManagementISO/IEC 27001

ISO 27001 - Cryptography - Info. Security Management System

Learn about cryptography as it relates to Clause 10 of ISO 27001:2013 Annex A Controls
Rating: 4.1 out of 54.1 (37 ratings)
7,270 students
Created by ISO Horizon
Last updated 11/2021
English
English [Auto]

What you'll learn

  • Learn about ISO 27001:3013 guidelines concerning cryptography
  • Obtain general knowledge about cryptography
  • Familiarize yourself with common cryptographic techniques
  • Understand the purpose of cryptography: confidentiality, integrity, authentication, non-repudiation
  • Gain a general understanding of symmetric/asymmetric keys & digital signitures

Requirements

  • An overview of ISO 27001:2013 is recommended, but not required,

Description

In this course, we'll explore an overview of what cryptography is and how it relates to Clause 10 of ISO 27001:2013 Annex A Controls. I'll be teaching using slides and explaining some notes about the topic. In addition to reading the notes on the screen and listening to the lecture, you can take notes if you wish. This course is less about cryptography itself and more about the requirement of ISO 27001:2013 Annex A Controls with regards to cryptography. Therefore we won't be discussing any particular cryptographic control at great length.

Here's a summary of what you can expect to learn from this course:

Section 1:

Cryptography has been around for ages. It means scrambling data so that it's unreadable to people who don't know how to decrypt it. When computers became a thing and there was a whole bunch of information out there, we needed more encryption. Since then it's really taken off and people have come up with really sophisticated ways to encrypt data.

Section 2:

So, what does ISO 27001:2013 Annex A say about this? It says that you have to have a cryptographic policy. This basically means that you have to prepare a document that's going to govern how you use encryption in your organization. It answers the who what where when and how questions. This means the policy should answer the following questions:

  • Who is going to implement the policy? (The roles and responsibilities)

  • What data needs to be encrypted? (Sensitive data needs to be encrypted)

  • Where is the data that needs to be encrypted? (In transit, at rest, or in processing)

  • When should the organization encrypt? (Only when it is effective)

  • How they will encrypt their data? (The ciphers they'll use, how they'll manage their keys, permissions, etc.)

Section 3:

The strength of encryption controls relies heavily on the effective implementation of key management. You need the keys to gain access to your data so if you lose your keys or they get destroyed then you won't have access to your data anymore. Also, if a thief gets your keys and they have access to your encrypted files, they can easily steal or alter your data.

Therefore, an organization has to create an effective key management policy that's going to force them to decide how keys will be generated, backed up, stored, protected, retired, and deleted. They can use key management solutions and implement their policy themselves or they can outsource this process to another specialized organization.

Who this course is for:

  • Anyone who wants to know more about this area of ISO 27001:2013

Instructor

ISO Horizon
Instructor/ Accountant
ISO Horizon
  • 4.2 Instructor Rating
  • 484 Reviews
  • 31,024 Students
  • 11 Courses

I make courses related to business studies that can cover various areas such as environmental management systems, quality assurance, and occupational health and safety. I'm an accountant by profession and play a leading role in my organization. It's my goal and passion to share my knowledge and understanding of different topics with a worldwide audience on Udemy.

Top companies choose Udemy Business to build in-demand career skills.
NasdaqVolkswagenBoxNetAppEventbrite
  • Udemy Business
  • Teach on Udemy
  • Get the app
  • About us
  • Contact us
  • Careers
  • Blog
  • Help and Support
  • Affiliate
  • Investors
  • Impressum Kontakt
  • Terms
  • Privacy policy
  • Cookie settings
  • Sitemap
  • Accessibility statement
Udemy
© 2022 Udemy, Inc.