Live data from Hacker News

Understanding Cybersecurity Frameworks: NIST, ISO, and More

thefinalhop.com

41–50 of 52 posts

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#42

My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…

Recognise!

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#43
post #28

We can tell how good these cybersecurity frameworks are by seeing how hard it is to breach the organizations certified at the highest levels such as SolarWinds [1], Equifax [2], Trend Micro [3][4], Cisco [5], and so many more. It is so utterly ridiculous that anybody cares about these standards when literal clown shows get full marks. The sign of a good standard is one that effectively and accurately predicts outcome…

I disagree. Cyber security frameworks do not provide a guarantee of not being hacked even if you do everything in them.

What is true is that if you do very little on them, you are much more likely to be hacked.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#44
post #22

NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…

Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…

> PCI-DSS is an industrywide joke; it's a checklist audit performed by race-to-the-bottom consultancies

We ended up with a consultants from a former Eastern Europe country that charge less per hour then local cashiers make (which is NOT a statement to the quality of said consultants).

I (irregular) deal with PCI-DSS and never ever felt so close to quit my job and become a full time lawn mower.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#45
post #22

NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…

Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…

I had a pci shop try to make us turn _off_ 2fa because it’s not required for our certification level.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#46
post #21

Earlier quoted context omitted.

These frameworks don’t guarantee security, but there is a stark difference between companies that do this and those who don’t. Companies that follow these frameworks are at least attempting to be secure.

Even that is false. Companies that follow these frameworks are performing security, at the expensive actually building security.

In my experience, the companies not following these frameworks aren't even _performing_ security.

Everyone here is correct that you need more than just these frameworks/audits to be secure. However, most companies that are secure following these frameworks. If you're secure, these frameworks are a no-brainer to certify against.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#47
post #21

Earlier quoted context omitted.

Even that is false. Companies that follow these frameworks are performing security, at the expensive actually building security.

In my experience, the companies not following these frameworks aren't even _performing_ security. Everyone here is correct that you need more than just these frameworks/audits to be secure. However, most companies that are secure following these frameworks. If you're secure, these frameworks are a no-brainer to certify against.

No, I reject your premise, for all the reasons I've stated on this thread.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#48
post #22

NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkil…

Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…

Worked at a bank for years. So many things we wanted to do to really get our firewall policies modern and more actionable for the SOC. Layer 7 enforcement, user-based policies, deduplication of rules, more aggressive cleanup.

Things needing to be done a certain way for the auditors was a major hamper in our processes.

I'm now consulting and I have seen people do changes to their policies in such strange ways because they have to jump through ridiculous hoops for their industry regulator.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#49
post #22

Earlier quoted context omitted.

Additional color commentary: 27001 is Euro-SOC2. Technically, 27001 is a certification, and SOC2 is just an attestation --- there is an external ground truth that 27001 is matching security programs to, where SOC2 is just validating internal consistency. But the subject matter is the same and they're generally thought of as equivalents for each other, with 27001 being the more rigorous. Ironically, COBIT is the IT-fo…

Worked at a bank for years. So many things we wanted to do to really get our firewall policies modern and more actionable for the SOC. Layer 7 enforcement, user-based policies, deduplication of rules, more aggressive cleanup. Things needing to be done a certain way for the auditors was a major hamper in our processes. I'm now consulting and I have seen people do changes to their policies in such strange ways because…

Yes. I've come to believe that much of the skill involved in doing security compliance work is in managing (strangling) down the scope of the framework, and almost none of it is in using the framework to inform and improve real security practices. This is what I mean when I keep saying here that these frameworks are not a "good first step". If you don't actually have to engage with them, because your customers aren't demanding it, you should actively avoid them and use that precious time to build a real security practice.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#50
post #18
post #15

Earlier quoted context omitted.

You know these are the floor of what you should do, not the ceiling. If a big company can’t explain why they aren’t doing the bare minimum defined in a framework, that’s a red flag. There are open source solutions for the majority of controls in these frameworks. It isn’t 1995.

My argument is that they're lower than the floor, which makes using them to try to detect the floor dangerous.

Having worked with a number of different companies, and these frameworks are the floor of best practices, these frameworks are far above the subterranean caverns many companies operate their security postures from.
Post reply on HN