ISO27001 for policy development. CIS benchmarks for configuration. CIS controls for assessments. NIST for guidelines.
this post was submitted on 11 Apr 2024
3 points (80.0% liked)
cybersecurity
3257 readers
2 users here now
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Enjoy!
founded 1 year ago
MODERATORS
How far do you guys go?
'All of it's or until it's inconvenient?
What's the pain tolerance for when everyone says it makes the job too hard?
Ever compared CIS controls to STIG ACAP?
I've only ever used SCAP for a few reasons z but one being it's free.
In my experience the difference between theory and practice is that in theory and organisation claims to be certified in all the right ways, but in practice the CEO has a nephew who is "good with computers".
What I've yet to see in 40 years in this profession is anything that assumes that you will be compromised and what you might put in place before that actually happens.