The cautious seldom err.

Confucius, 551–479 BC

Security Control Frameworks Defined

Control frameworks and security standards are often interchangeable terms depending upon the creator. Just to confuse things further, ISO 27001, from the International Organization for Standardization, posits an information security management “system” (ISMS) and the controls are contained within the ISO 27002 Code of Practice (ISO, 2005). The National Institute of Standards and Technology (NIST) Special Publication 800-53 (NIST, 2009), titled Recommended Security Control for Federal Information Systems, breaks the controls into 18 control families and 3 classes (managerial, operational, and technical) of ...

Get Information Security Governance Simplified now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.