Understanding Cybersecurity Frameworks: NIST, ISO, and More
41–50 of 52 posts
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#42My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#43We can tell how good these cybersecurity frameworks are by seeing how hard it is to breach the organizations certified at the highest levels such as SolarWinds [1], Equifax [2], Trend Micro [3][4], Cisco [5], and so many more. It is so utterly ridiculous that anybody cares about these standards when literal clown shows get full marks. The sign of a good standard is one that effectively and accurately predicts outcome…
What is true is that if you do very little on them, you are much more likely to be hacked.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#44NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…
Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…
We ended up with a consultants from a former Eastern Europe country that charge less per hour then local cashiers make (which is NOT a statement to the quality of said consultants).
I (irregular) deal with PCI-DSS and never ever felt so close to quit my job and become a full time lawn mower.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#45NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…
Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#46Earlier quoted context omitted.
These frameworks don’t guarantee security, but there is a stark difference between companies that do this and those who don’t. Companies that follow these frameworks are at least attempting to be secure.
Even that is false. Companies that follow these frameworks are performing security, at the expensive actually building security.
Everyone here is correct that you need more than just these frameworks/audits to be secure. However, most companies that are secure following these frameworks. If you're secure, these frameworks are a no-brainer to certify against.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#47Earlier quoted context omitted.
Even that is false. Companies that follow these frameworks are performing security, at the expensive actually building security.
In my experience, the companies not following these frameworks aren't even _performing_ security. Everyone here is correct that you need more than just these frameworks/audits to be secure. However, most companies that are secure following these frameworks. If you're secure, these frameworks are a no-brainer to certify against.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#48NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…
Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…
Things needing to be done a certain way for the auditors was a major hamper in our processes.
I'm now consulting and I have seen people do changes to their policies in such strange ways because they have to jump through ridiculous hoops for their industry regulator.
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#49Earlier quoted context omitted.
Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…
Worked at a bank for years. So many things we wanted to do to really get our firewall policies modern and more actionable for the SOC. Layer 7 enforcement, user-based policies, deduplication of rules, more aggressive cleanup. Things needing to be done a certain way for the auditors was a major hamper in our processes. I'm now consulting and I have seen people do changes to their policies in such strange ways because…
Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More
#50Earlier quoted context omitted.
You know these are the floor of what you should do, not the ceiling. If a big company can’t explain why they aren’t doing the bare minimum defined in a framework, that’s a red flag. There are open source solutions for the majority of controls in these frameworks. It isn’t 1995.
My argument is that they're lower than the floor, which makes using them to try to detect the floor dangerous.