Which Cybersecurity Framework is Right for You?

SOC 2, CIS, NIST, ISO27001, PCI and more. How do you choose?
Given the growing amount of information and data that businesses of all sizes are having to manage, great cybersecurity is increasingly the most critical element of IT. Accenture estimat… Continue reading Which Cybersecurity Framework is Right for You?

2019 Update on frameworks, standards, and regulations for infosec

At the 2019 BSides Tampa Security conference I did a talk on 2019 Updates on frameworks, standards, and regulations for infosec.  Over the last year several new and updated frameworks and regulations have come out, as well as are being updated.
Mo… Continue reading 2019 Update on frameworks, standards, and regulations for infosec

2018 NIST Cybersecurity Risk Management Conference

Back in October I was in Baltimore for NIST’s 2018 Cybersecurity Risk Management Conference.  For those not aware, let me break this down.  NIST is the National Institute of Standards and Technology, a non-regulatory research arm of the Depar… Continue reading 2018 NIST Cybersecurity Risk Management Conference

Framework/standard updates coming

Well, it’s early 2018 and there are several information security framework/standards being updated:

NIST CSF v1.1.  The second draft was released at the end of 2017, and we just wrapped up the comment period on this.  I believe the plans ar… Continue reading Framework/standard updates coming