SMALL BUSINESS CYBERSECURITY

Simple, Easy to Follow Help
For the Small Business

Certified Information Systems Security Professional
ISC2 CISSP #473513 Since 2013

Home Credentials Coaching Contact

Clean Definitions

What is Cyber

What is Risk

What is a Threat

What is a Framework

What is the Cloud

What is a CISO or BISO

What is a decent Plan?

What is AI?



Resources

Measuring and Manageing Information Risk,
a FAIR Approach
1st Edition

Authors: Jack Freund and Jack Jones
Published by: Butterworth-Heinemann, Oxford, UK
2015
ISBN: 978-0-12-420231-3 (Paperback)

How to Measure Anything in Cybersecurity Risk

Authors: Douglas W. Hubbard and Richard Seiersen
Published by: John Wiley and Sons, Inc., Hoboken, New Jersey, USA
2023
ISBN: 978-0-11-1989230-4 (Hardback)
ISBN: 978-0-11-1989232-8 (ePDF)
ISBN: 978-0-11-1989231-1 (ePub)

What is a Framework?

A framework is a shell of ideas or things to worry about and plan for, with out any values to set, or processes and programs to do the work. In information security, there are lots of frameworks: NIST, ISO, CIS, SOC2, PCI-DSS, COBIT, HITRUST, CCM, CMMC, and so forth. Note that some of these are more standard-like than a framework because they contain values to reach, and not just areas to cover. Frameworks are very convenient to help you brainstorm what you might need to cover, but are not forced to necessarily follow. HITRUST is more of a declared set of standards. NIST, ISO and others are great frameworks for cybersecurity without set standards. There are also frameworks that cover topics related to cybersecurity, such as privacy. Remember that most are frameworks and include the notion "Have something that covers this topic." You are going to need to decide how you want to cover each area of cybersecurity that concerns your business. I can help you evaluate that and create the controls (rules) if you need.

When you look at any framework, keep in mind that just because they mention an area to consider does not mean that you must cover it all. In a very large business that I worked for, they only chose 200 of the 1100 possible NIST 800-53 controls to work with because it would be totally overwhelming to do more. The NIST 800-171 controls recommended for some vendors of government services are actually just a 110 control subset of the NIST 800-53 master list. I will help you in that area as well.

Which One do I Use?

As I've said before, it's up to you. Find one or parts of many that fit what you think you need. Depending on your industry, regulators may require one or the other. I can help you figure that out, or ask your regulator. There are also great lists on the Internet that show how and where many of the standards overlap. This can be very helpful to organize your efforts should you re required to use many frameworks.

Testimonials

NULL at the moment.

Please email ronald@weist.net to schedule an appointment to talk about your information (not physical...well, maybe not) security.