The cautious seldom err.
Confucius, 551–479 BC
Security Control Frameworks Defined
Control frameworks and security standards are often interchangeable terms depending upon the creator. Just to confuse things further, ISO 27001, from the International Organization for Standardization, posits an information security management “system” (ISMS) and the controls are contained within the ISO 27002 Code of Practice (ISO, 2005). The National Institute of Standards and Technology (NIST) Special Publication 800-53 (NIST, 2009), titled Recommended Security Control for Federal Information Systems, breaks the controls into 18 control families and 3 classes (managerial, operational, and technical) of ...