Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security objective "authenticity" #287

Open
KonzeptAcht opened this issue May 8, 2020 · 4 comments
Open

security objective "authenticity" #287

KonzeptAcht opened this issue May 8, 2020 · 4 comments

Comments

@KonzeptAcht
Copy link

Describe the solution you'd like
ISO 27001 and ISO 27005 generally assume the three protection objectives "confidentiality", "integrity" and "availability" in their risk analyses.

However, the "IT Security Act" applicable in Germany requires the additional protection objective of " authenticity" for the operators of critical infrastructures.

We would be pleased if "authenticity" (in German: Authentizität) were included as a fourth protection objective in the MONARC methodology.

@KonzeptAcht
Copy link
Author

Is there already a decision here? In the meantime, the security objective of authenticity is also required in the banking sector (BAFIN, MARISK, ...).

@cedricbonhomme
Copy link
Member

An important development that we are about to start is the configuration of the impact scales. The first step for the operational risks. So we could consider this later (modifiable impact, if this is what you mean ?) but I cannot provide a precise time estimate.

@KonzeptAcht
Copy link
Author

The German financial regulatory authorities and the BSI require in their standards BAFIN, MARISK, IT-Grundschutz and in §8a of the BSI Act that authenticity is also taken into account. This makes it necessary to supplement CIA with CIAA.

MONARC_authenticity

@ruslanbaidan
Copy link
Contributor

Related:
#196

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants