Understanding Cybersecurity Frameworks: NIST, ISO, and More
thefinalhop.com
Understanding Cybersecurity Frameworks: NIST, ISO, and More
1–10 of 52 posts
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#2Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#3No, no to all of this.
(I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#4No, no to all of this.
What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)
Those frameworks should be treated as guidelines to build a mature security programme, and not just tickbox exercise.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#5No, no to all of this.
What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)
By a wide margin, their most impactful designed purpose is to sell security products and services.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#6No, no to all of this.
What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)
in fact I would suggest cis controls over nist and iso for pretty much everyone, but nothing beats knowing your environment inside and out, and striving for 100% visibility.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#7Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#8Earlier quoted context omitted.
What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)
they are popular because insurance, law, and regulations. it's hard to measure a corps security posture in a way that can apply to everyone and every thing. read them, know them, and if you are required to, meet them. but don't think for a second having all the boxes ticked gets you secure. in fact I would suggest cis controls over nist and iso for pretty much everyone, but nothing beats knowing your environment insi…
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#9That's where the value stops - once you give lawyers, policymakers, and insurance companies access to these documents it becomes an unending game of regulatory capture, responsibility derogation, and box-ticking.
You end up with people who have zero context for technology running around demanding to see evidence that your smart toaster implements 12.2.14.1.5b "The centralized time server must enforce separation of duties" before it can be added to the network or some other such incoherent nonsense.
These standards always start in the right place, but they get used in the most frustrating ways because people who don't understand how technology works are, invariably, the auditors and assessors who apply these standards since true technologists can easily find more gratifying jobs doing literally anything else.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#10Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.