UNE EN ISO/IEC 27041:2016
Information technology - Security techniques - Guidance on assuring suitability and adequacy of incident investigative method (ISO/IEC 27041:2015) (Endorsed by AENOR in December of 2016.)
Tecnología de la información. Técnicas de seguridad. Directrices para garantizar la idoneidad y adecuación del método de investigación de incidentes (ISO/IEC 27041:2015) (Ratificada por AENOR en diciembre de 2016.)
| Standard number: | UNE EN ISO/IEC 27041:2016 |
| Pages: | 31 |
| Released: | 2016-12-01 |
| Status: | Standard |
UNE EN ISO/IEC 27041:2016
This International Standard provides guidance on mechanisms for ensuring that methods and processes used in the investigation of information security incidents are fit for purpose . It encapsulates best practice on defining requirements, describing methods, and providing evidence that implementations of methods can be shown to satisfy requirements. It includes consideration of how vendor and third-party testing can be used to assist this assurance process. This document aims to provide guidance on the capture and analysis of functional and non-functional requirements relating to an Information Security (IS) incident investigation, give guidance on the use of validation as a means of assuring suitability of processes involved in the investigation, provide guidance on assessing the levels of validation required and the evidence required from a validation exercise, give guidance on how external testing and documentation can be incorporated in the validation process.
