LOGBOOK

HELP

1 / 283
time's up — finish this card
Other keys: showSpace: good1-4: rate0: skip5: flag
Topic Standards & Frameworks I (ISO, BSI)

Question

What are "Scope" and "Statement of Applicability" (SoA) in the context of ISO 27001 certification?

Answer

The Scope defines what part of the organization the ISMS covers, and the SoA lists which ISO 27002 controls apply — together they define the certification boundary.

Scope — the area the ISMS applies to:

  • Entire company
  • A single department
  • A specific location
  • Part of the infrastructure (e.g., the DMZ)

Statement of Applicability (SoA) — lists which controls from ISO 27002 the ISMS addresses, with justification for any exclusions.

Why this matters: A company with an ISO 27001 certificate might only have certified a small part of its operations. Always check the scope! A certificate for "the DMZ" doesn't mean the entire organization meets the standard.

Tip: Think of it like this — Scope = "where does the ISMS apply?", SoA = "what controls does it include?"

or press any other key
Topic IT-Grundschutz (BSI)

Question

How is the layer model (Schichtenmodell) of the IT-Grundschutz-Kompendium structured?

Answer

Ten block families in two groups: process blocks (ISMS, ORP, CON, OPS, DER) and system blocks (IND, APP, SYS, NET, INF) — a "function-oriented" structure.

Tree: the Kompendium splits into process Bausteine (ISMS, ORP, CON, OPS, DER) and system Bausteine (IND, APP, SYS, NET, INF); SYS drills down into SYS.1 Server → SYS.1.1 General server.

* The Schichtenmodell — process Bausteine (ISMS, ORP, CON, OPS, DER) and system Bausteine (IND, APP, SYS, NET, INF), with each Baustein decomposing into sub-Bausteine (e.g. SYS → SYS.1 Server → SYS.1.1 General server). *

The block families:

Process blocks (Prozess-Bausteine) — organizational/overarching:

Code Meaning
ISMS Security management
ORP Organization & personnel
CON Concepts & procedures
OPS Operational security aspects
DER Detection & reaction (to security incidents)

System blocks (System-Bausteine) — concrete technology:

Code Meaning
IND Industrial IT (SCADA etc.)
APP Applications
SYS IT systems and components
NET Networks
INF Physical security / infrastructure

The old catalogs were system-oriented; the new model is function-oriented: overarching/process aspects are separated from systems, and responsibilities are bundled — another deliberate step toward the structure of ISO 27001.

Tip: Mnemonic for the process side: "ISMS ORganizes CONcepts, OPerates, DEtects & Reacts."

Go deeper:

or press any other key