Earlier quoted context omitted.
What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)
They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.
Understanding Cybersecurity Frameworks: NIST, ISO, and More
11–20 of 52 posts
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#12Earlier quoted context omitted.
What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)
They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.
The cyber causality dilemma - which came first, the vendor or the framework?
I think there's some use for the framework to make people think about which controls and concepts might work for a given situation, but certainly they need the real world to be examined in parallel to be useful
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#13My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#14Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#15Earlier quoted context omitted.
What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)
They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.
If a big company can’t explain why they aren’t doing the bare minimum defined in a framework, that’s a red flag.
There are open source solutions for the majority of controls in these frameworks. It isn’t 1995.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#16Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.
I've gotten into breathless arguments with "cyber experts" who really don't understand this simple point. I've met people in industry who literally think that "filling out the paperwork and having a risk committee accept risks or prioritize a schedule to get into compliance" equals "our systems are now secure".
It's a massive self-serving industry incentivized to enrich itself and not secure systems. If they were successful at designing, deploying, and maintaining secure systems, there wouldn't be an industry.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#17My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#18Earlier quoted context omitted.
They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.
You know these are the floor of what you should do, not the ceiling. If a big company can’t explain why they aren’t doing the bare minimum defined in a framework, that’s a red flag. There are open source solutions for the majority of controls in these frameworks. It isn’t 1995.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#19No, no to all of this.
Speaking from experience
1.) At their worst - many industry-prescribed standards act to move liability from the poor Visa of the world onto smaller businesses. For example, being visa in this scenario - Why should I develop a better solution to credit card/identity theft? We have PCI!! I can even help sell training out of the goodness of my heart! This, of course, stagnates the industry, both through lost leaders thinking this piece of paper will protect them or to the parasitic cottage industries that capitalize on the fact nobody knows better and takes what could have been an investment in solving fundamental security problems. Ultimately accountability goes back to Visa / SWIFT and whatever body that cba’d on fixing the problem they created.
HOWEVER
2.) At their best many of these standards invite operational rigor required when you want to move past the “3 people in a basement” stages of your startup and have to make grown-up decisions if someone is hit by a train. Furthermore, security is often considered a cost center; attaining specific certifications can be one of the few indirect ways to attribute as a measurable product differentiator in whatever space you’re in.
The author's argument that these frameworks are a decent place to start to work on the comprehensive “cyber security” strategy is excellent for the neophyte looking to understand better one of the many elements that go into running a security program, but it’s far from comprehensive. It’s sad to think, but sometimes these compliance-driven certifications often become one of the few forcing functions you have as a security engineer/leader to get someone to do something that closely resembles the right thing. I’m sure many roll their eyes reading this comment, but - I’ve had countless interactions with engineers who could give less of a shit if their product is insecure just as long as they can ship it on time and be offline by 4, and my only option is to get the legal department to chase them because we will fail an audit if they don’t change course.
Either way. I’d recommend anyone reading the article to have an open mind to understanding many of these frameworks, what they are used for, and how you might use them effectively until we figure out something better. Don’t just cargo cult “standards r bad”, “Jira is dumb”. Try to ask the broader question of why they are needed in the first place.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#20ISO 27001 = Not super familiar with this one.
COBIT = The management/process focused version of NIST CSF. Great if you have an executive suite CTO, CISO, CRiskO, CPrivacyO, and want to coordinate their efforts in a program that divides responsibilities among them and associated committees. Includes maturity modeling, which gives it a +1, but it is distant from anything technology related. Instead, it is all about which committees should be formed to decide on risk management strategies etc...
PCI-DSS = You'll do this one because VISA makes you do it. Much more actionable than NIST or COBIT, but it depends on the third-party auditor who is issuing your attestation of compliance. "Your label maker has it's default password?" = audit finding.
CIS18 Controls = The most actionable/lightweight framework now that they have incorporated maturity levels (aka implementation groups). Not as thorough as NIST or COBIT. Well implemented, CIS18 is enough for most organizations provided they do not have a specific security standard or requirement in their industry.