Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.
These frameworks don’t guarantee security, but there is a stark difference between companies that do this and those who don’t. Companies that follow these frameworks are at least attempting to be secure.
Understanding Cybersecurity Frameworks: NIST, ISO, and More
21–30 of 52 posts
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#22NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…
27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous.
Ironically, COBIT is the IT-focused equivalent of COSO --- in other words, it's the ostensibly more technical set of controls. But SOC2 keys off of COSO, and is audited by accountants, so practitioners are more likely to have experience with the fuzzier COSO controls.
PCI-DSS is an industrywide joke; it's a checklist audit performed by race-to-the-bottom consultancies, which have invariably PCI-certified all of the most egregious payment card breach shops since PCI was standardized. Ironically, as bad as PCI is, it's the controls standard that has probably had the most practical impact, because of how prescriptive it is, and how rote the audits have become. Its impact is still malign!
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#23https://owaspsamm.org/blog/2020/10/29/comparing-bsimm-and-sa...
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#24NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…
Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#25Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#26Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#27Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.
> Being compliant within any of those frameworks does not make an organization secure. I've gotten into breathless arguments with "cyber experts" who really don't understand this simple point. I've met people in industry who literally think that "filling out the paperwork and having a risk committee accept risks or prioritize a schedule to get into compliance" equals "our systems are now secure". It's a massive self-…
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#28It is so utterly ridiculous that anybody cares about these standards when literal clown shows get full marks.
The sign of a good standard is one that effectively and accurately predicts outcomes. A standard can be validated experimentally by evaluating if the certified targets conform to the stated predictions of the standard. A standard that fails to discriminate between good and bad is useless and the results of such certifications can be safely ignored.
The vast majority of cybersecurity frameworks have failed in these respects. Basically, if a standard gives Microsoft top marks, it is a lousy standard. That is not a necessary condition, but it is certainly sufficient along with anything certifying plenty of other security messes.
[1] https://www.schellman.com/certificate-directory?certificateN...
[2] https://www.oxebridge.com/emma/equifax-held-iso-27001-certif...
[3] https://www.bleepingcomputer.com/news/security/trend-micro-f...
[4] https://www.trendmicro.com/en_us/about/trust-center/complian...
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#29My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…
The other bad thing they do is encourage technologists who aren't security subject matter experts to invest in programs and tools that aren't valuable, either at their current state or, in some cases, ever. They create the impression that there is an important checklist of things that most companies need to have, and if such a checklist exists, not one of these frameworks captures it.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#30NIST isn't a maturity framework, it doesn't tell you that you need x control in place to be x level of maturity. It gives you control objectives that you need to design and operate effectively over time.
You might have a great set of controls across penetration testing and vulnerability management today, but if you fail to perform one of these controls tomorrow you will be vulnerable.
For example, I have performed controls assessments against organisations that have implement CIS controls. I have seen more often than not, CIS controls not being fully implemented as per the wording of the control AND the control not having been performed appropriately.
This is where using a cyber security standard and obtaining controls assurance is very important.