Live data from Hacker News

Understanding Cybersecurity Frameworks: NIST, ISO, and More

thefinalhop.com

1–10 of 52 posts

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#4
post #3
post #2

No, no to all of this.

What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)

Those are pervasive because they provide a universal baseline for security requirements across the world.

Those frameworks should be treated as guidelines to build a mature security programme, and not just tickbox exercise.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#5
post #3
post #2

No, no to all of this.

What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)

They're a pervasive indicator of performative security that intersects with serious practice in very few places.

By a wide margin, their most impactful designed purpose is to sell security products and services.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#6
post #3
post #2

No, no to all of this.

What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)

they are popular because insurance, law, and regulations. it's hard to measure a corps security posture in a way that can apply to everyone and every thing. read them, know them, and if you are required to, meet them. but don't think for a second having all the boxes ticked gets you secure.

in fact I would suggest cis controls over nist and iso for pretty much everyone, but nothing beats knowing your environment inside and out, and striving for 100% visibility.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#8
post #6
post #3

Earlier quoted context omitted.

What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)

they are popular because insurance, law, and regulations. it's hard to measure a corps security posture in a way that can apply to everyone and every thing. read them, know them, and if you are required to, meet them. but don't think for a second having all the boxes ticked gets you secure. in fact I would suggest cis controls over nist and iso for pretty much everyone, but nothing beats knowing your environment insi…

One indicator of the intellectually bankruptcy of this article's summary is the equivalence it draws between NIST's framework (which is really just an index of other frameworks), ISO 27001 (a certification), and PCI (a domain-specific audit program). It's an incoherent way to think about frameworks, even if you think there's value in them (I think it's probably clear to everybody that I don't).

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#9
My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your organization is approaching security - basically regardless of what type of company you run.

That's where the value stops - once you give lawyers, policymakers, and insurance companies access to these documents it becomes an unending game of regulatory capture, responsibility derogation, and box-ticking.

You end up with people who have zero context for technology running around demanding to see evidence that your smart toaster implements 12.2.14.1.5b "The centralized time server must enforce separation of duties" before it can be added to the network or some other such incoherent nonsense.

These standards always start in the right place, but they get used in the most frustrating ways because people who don't understand how technology works are, invariably, the auditors and assessors who apply these standards since true technologists can easily find more gratifying jobs doing literally anything else.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#10
post #7

Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.

I'd push back on this, and say it's a pretty distinctively bad place to start, unless you're starting at Allstate in a parallel universe where Allstate hasn't spent the last 20 years doing this stuff and indirectly influencing these frameworks.
Post reply on HN