SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Cybersecurity Framework or ISO 27001

  Quote
Guest
Guest user Created:   Jan 16, 2018 Last commented:   Jan 16, 2018

Cybersecurity Framework or ISO 27001

Thank you for your videos on IT security. I work for an institution with about 500 employees where most of these IT security systems and standards are not in place or documented. I have been appointed to lead the ICT security department and I'm now conflicted on whether to start with a Cybersecurity Framework or ISO 27001. From my research these are both important please advise how I can get started
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 16, 2018

Answer: First of all you should consider your needs:
- If you need quick wins to handle risks promptly and demonstrate the value of security, then you should start with Cybersecurity Framework, since it is better when it comes to structuring the areas of security that are to be implemented and when it comes to defining exactly the security profiles that are to be achieved.
- If you have to ensure the implementation will be well integrated to other aspects and areas of your organization, and you have time to plan and implement, then you should go first for ISO 27001, since it can provide a holistic picture for the designing of the security system and how it can be managed in the long run.
- The Cyber Security Framework is a legal issue in the United States - if you are a government agency from that country, you will need to implement it.

If your choice is to go first for Cybersecurity Framework, it is possible to integrate the implemented controls to the future implementation of ISO 27001, so you will not lose time and effort.

These articles will provide you further explanation about Cybersecurity Framework and ISO 27001:
- Which one to go with – Cybersecurity Framework or ISO 27001? https://advisera.com/27001academy/blog/2014/02/24/which-one-to-go-with-cybersecurity-framework-or-iso-27001/
- How to implement the NIST Cyber Security Framework using ISO 27001 https://info.advisera.com/27001academy/free-download/how-to-implement-nist-cyber-security-framework-using-iso-27001

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 16, 2018

Jan 16, 2018

Suggested Topics