Live data from Hacker News

Understanding Cybersecurity Frameworks: NIST, ISO, and More

thefinalhop.com

51–52 of 52 posts

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#51
post #50
post #18

Earlier quoted context omitted.

My argument is that they're lower than the floor, which makes using them to try to detect the floor dangerous.

Having worked with a number of different companies, and these frameworks are the floor of best practices, these frameworks are far above the subterranean caverns many companies operate their security postures from.

You can do worse than The Frameworks! But it doesn't follow logically that The Frameworks are a good starting place --- they can be (really: are) worse than the outcome from simply ignoring The Frameworks altogether.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#52
post #51
post #50

Earlier quoted context omitted.

Having worked with a number of different companies, and these frameworks are the floor of best practices, these frameworks are far above the subterranean caverns many companies operate their security postures from.

You can do worse than The Frameworks! But it doesn't follow logically that The Frameworks are a good starting place --- they can be (really: are) worse than the outcome from simply ignoring The Frameworks altogether.

Can you provide some examples?
Post reply on HN