Expert Advice Community

Guest

NIST framework

  Quote
Guest
Guest user Created:   May 19, 2020 Last commented:   May 19, 2020

NIST framework

I am working on a project to provide an easy to use yet comprehensive approach for supporting boards to monitor their cyber risk responsibilities. We are thinking of using the NIST framework as a base because of it simplicity and fitting a set of best practices around it. You do such a great job of simplifying the complexity of ISO.  Is there a slimed down set of practices based on ISO standards we might consider? Thanks!!!

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 19, 2020

I'd suggest you t take a look at ISO 27004 (https://www.iso.org/standard/64120.html), a supporting standard that provides guidelines to help organizations in evaluating the performance and the effectiveness of an ISMS.

These articles will provide you a further explanation about performance evaluation:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 19, 2020

May 19, 2020

Suggested Topics