Live data from Hacker News

Understanding Cybersecurity Frameworks: NIST, ISO, and More

thefinalhop.com

21–30 of 52 posts

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#21
post #7

Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.

These frameworks don’t guarantee security, but there is a stark difference between companies that do this and those who don’t. Companies that follow these frameworks are at least attempting to be secure.

Even that is false. Companies that follow these frameworks are performing security, at the expensive actually building security.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#22

NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…

Additional color commentary:

27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous.

Ironically, COBIT is the IT-focused equivalent of COSO --- in other words, it's the ostensibly more technical set of controls. But SOC2 keys off of COSO, and is audited by accountants, so practitioners are more likely to have experience with the fuzzier COSO controls.

PCI-DSS is an industrywide joke; it's a checklist audit performed by race-to-the-bottom consultancies, which have invariably PCI-certified all of the most egregious payment card breach shops since PCI was standardized. Ironically, as bad as PCI is, it's the controls standard that has probably had the most practical impact, because of how prescriptive it is, and how rote the audits have become. Its impact is still malign!

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#24
post #22

NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…

Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…

Agree 100% with this and your other comments. These frameworks often create risks by obscuring reality behind procedure. Sucking up all the air that would go towards more direct security objectives. Businesses think they are done with cybersecurity because they are done with the checklist. Believing we are safe because a non-technical auditor said so, can be a risky spot. Specially if that is used to overrule subject matter experts.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#27
post #16
post #7

Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.

> Being compliant within any of those frameworks does not make an organization secure. I've gotten into breathless arguments with "cyber experts" who really don't understand this simple point. I've met people in industry who literally think that "filling out the paperwork and having a risk committee accept risks or prioritize a schedule to get into compliance" equals "our systems are now secure". It's a massive self-…

I’ve really been of the opinion as of late that if we took just a small fraction of the time and manpower we waste on pedantic security framework adherence and put it towards training actual staff to and experts to be better cybersecurity professionals, we’d be better off.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#28
We can tell how good these cybersecurity frameworks are by seeing how hard it is to breach the organizations certified at the highest levels such as SolarWinds [1], Equifax [2], Trend Micro [3][4], Cisco [5], and so many more.

It is so utterly ridiculous that anybody cares about these standards when literal clown shows get full marks.

The sign of a good standard is one that effectively and accurately predicts outcomes. A standard can be validated experimentally by evaluating if the certified targets conform to the stated predictions of the standard. A standard that fails to discriminate between good and bad is useless and the results of such certifications can be safely ignored.

The vast majority of cybersecurity frameworks have failed in these respects. Basically, if a standard gives Microsoft top marks, it is a lousy standard. That is not a necessary condition, but it is certainly sufficient along with anything certifying plenty of other security messes.

[1] https://www.schellman.com/certificate-directory?certificateN...

[2] https://www.oxebridge.com/emma/equifax-held-iso-27001-certif...

[3] https://www.bleepingcomputer.com/news/security/trend-micro-f...

[4] https://www.trendmicro.com/en_us/about/trust-center/complian...

[5] https://blogs.cisco.com/tag/iso-27001-certification

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#29
post #13

My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…

The other bad thing they do is encourage technologists who aren't security subject matter experts to invest in programs and tools that aren't valuable, either at their current state or, in some cases, ever. They create the impression that there is an important checklist of things that most companies need to have, and if such a checklist exists, not one of these frameworks captures it.

Yeah, unfortunately a lot of checkboxes only serve to expand the attack surface in many cases.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#30
Having worked performing assessments against these frameworks and standards. The important thing people need to know particularly for NIST, is that you could have a clean bill of health today. But if one or two of your controls fails tomorrow, then you may run into trouble.

NIST isn't a maturity framework, it doesn't tell you that you need x control in place to be x level of maturity. It gives you control objectives that you need to design and operate effectively over time.

You might have a great set of controls across penetration testing and vulnerability management today, but if you fail to perform one of these controls tomorrow you will be vulnerable.

For example, I have performed controls assessments against organisations that have implement CIS controls. I have seen more often than not, CIS controls not being fully implemented as per the wording of the control AND the control not having been performed appropriately.

This is where using a cyber security standard and obtaining controls assurance is very important.

Post reply on HN