| |
|
Risk / Security Threat (Driver) |
Risk (Assessment) |
| |
|
Risk (Assessment) |
Risk Control Objective (Goal) |
| |
|
Security aspect (ISO 27001) |
Information Security Principle |
| |
|
Security aspect (ISO 27001) |
Information security Requirement |
| |
|
Security aspect (ISO 27001) |
Security Control Objective (Goal) |
| |
|
Security Control Objective (Goal) |
Risk Control Objective (Goal) |
| |
|
Information Security Principle |
Security Control Objective (Goal) |
| |
|
Information security Requirement |
Information Security Principle |
| |
|
Information security Requirement |
Security Control Objective (Goal) |
| |
|
Control Measure (Requirement) |
Risk Control Objective (Goal) |
| |
|
Control Measure (Requirement) |
Information security Requirement |
| |
|
<<EA element>> |
Control Measure (Requirement) |