{"id":324180,"date":"2024-10-19T22:28:20","date_gmt":"2024-10-19T22:28:20","guid":{"rendered":"https:\/\/pdfstandards.shop\/product\/uncategorized\/bs-311112018\/"},"modified":"2024-10-25T21:03:51","modified_gmt":"2024-10-25T21:03:51","slug":"bs-311112018","status":"publish","type":"product","link":"https:\/\/pdfstandards.shop\/product\/publishers\/bsi\/bs-311112018\/","title":{"rendered":"BS 31111:2018"},"content":{"rendered":"
This British Standard provides guidance on cyber risk management and resilience for societal, regulatory, governance and behavioural risks that need to be understood, assessed, quantified, qualified and addressed, and overseen by the governing body and executive management of an organization.<\/p>\n
This British Standard helps the governing body and executive management manage cyber risk and resilience, explaining the various approaches to making an organization cyber resilient. It is applicable to public, private and not-for-profit organizations of all sizes, and provides guidance on the essential features of cyber risk and resilience management to ensure that cyber resilience is built into decision making.<\/p>\n
This is not a technical cyber security or risk management standard. It is intended for a non-technical audience, although some of the relevant standards with more technical content are listed in Annex A.<\/p>\n
PDF Pages<\/th>\n | PDF Title<\/th>\n<\/tr>\n | ||||||
---|---|---|---|---|---|---|---|
4<\/td>\n | Foreword <\/td>\n<\/tr>\n | ||||||
5<\/td>\n | 0 Introduction 0.1 General 0.2 Purpose and benefits of this British Standard <\/td>\n<\/tr>\n | ||||||
6<\/td>\n | 1 Scope 2 Normative references <\/td>\n<\/tr>\n | ||||||
7<\/td>\n | 3 Terms and definitions <\/td>\n<\/tr>\n | ||||||
9<\/td>\n | 4 Building cyber resilience: Core principles 4.1 General <\/td>\n<\/tr>\n | ||||||
10<\/td>\n | Figure 1 \u2014 Building cyber resilience 4.2 Maximizing potential benefits while minimizing threats <\/td>\n<\/tr>\n | ||||||
12<\/td>\n | 4.3 Capabilities for a cyber-resilient organization 5 The organizational foundations for cyber risk and resilience <\/td>\n<\/tr>\n | ||||||
13<\/td>\n | 5.1 Culture 5.2 Ownership and leadership 5.3 Trust and transparency 5.4 Decision making <\/td>\n<\/tr>\n | ||||||
14<\/td>\n | 5.5 Regulation 6 Building cyber risk management and resilience capability 6.1 General 6.2 Risk management 6.3 Collaboration and engagement <\/td>\n<\/tr>\n | ||||||
15<\/td>\n | 6.4 Business transformation 6.5 Adaptability and agility 6.6 Monitoring and threat intelligence 6.7 Response and planning 7 Assessing the resilience of the organization 7.1 General <\/td>\n<\/tr>\n | ||||||
16<\/td>\n | 7.2 Maturity model\/assessment framework 7.3 Evaluation 7.4 Monitoring <\/td>\n<\/tr>\n | ||||||
17<\/td>\n | 7.5 Communication 7.6 Assurance 7.7 Awareness and training <\/td>\n<\/tr>\n | ||||||
18<\/td>\n | 7.8 Continual review and improvement Figure 2 \u2014 Developing resilience <\/td>\n<\/tr>\n | ||||||
19<\/td>\n | Annex A (informative)\u2002 Useful documents <\/td>\n<\/tr>\n | ||||||
21<\/td>\n | Annex B (informative)\u2002 Suggested assessment questions for executive management and\/or governing body <\/td>\n<\/tr>\n | ||||||
24<\/td>\n | Annex C (normative)\u2002 Embedding assurance and governance <\/td>\n<\/tr>\n | ||||||
25<\/td>\n | Annex D (informative)\u2002 Understanding cyber culture <\/td>\n<\/tr>\n | ||||||
26<\/td>\n | Bibliography <\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":" Cyber risk and resilience. Guidance for the governing body and executive management<\/b><\/p>\n |