<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: References to standards and frameworks in CISSP Study Group</title>
    <link>https://community.isc2.org/t5/CISSP-Study-Group/References-to-standards-and-frameworks/m-p/60975#M872</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great explanation!&amp;nbsp; Especially relevant in a global economy.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2023 20:14:13 GMT</pubDate>
    <dc:creator>tldutton</dc:creator>
    <dc:date>2023-07-19T20:14:13Z</dc:date>
    <item>
      <title>References to standards and frameworks</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/References-to-standards-and-frameworks/m-p/60950#M866</link>
      <description>&lt;P&gt;I have noted that throughout the course (in particular Chapter 7) a lot of standards and frameworks published by NIST, ISO and others are referenced. This material seems to feature in the practice assessment and chapter review questions. This seems like a kind of rote learning where I need to memorise information rather than understanding processes and principles. Can anyone comment on whether I should be investing the time so I can recall things like what 'NIST SP 800-xxx' means ?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 01:08:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/References-to-standards-and-frameworks/m-p/60950#M866</guid>
      <dc:creator>scottadamson</dc:creator>
      <dc:date>2023-07-19T01:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: References to standards and frameworks</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/References-to-standards-and-frameworks/m-p/60961#M869</link>
      <description>&lt;P&gt;While you don't have to fully understand what they &lt;EM&gt;do&lt;/EM&gt;, you should understand what they &lt;EM&gt;are&lt;/EM&gt;, and how a framework, standard or governing principle would apply to how an org conducts its business.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Your company may elect to use SP 800-53 to create a security framework, but if it's in defense, it has to follow 800-171.&lt;/LI&gt;&lt;LI&gt;Would your company do business in Europe?&amp;nbsp; Then it may require GDPR compliance.&lt;/LI&gt;&lt;LI&gt;Will it accept credit card payments online?&amp;nbsp; You must comply with PCI.&lt;/LI&gt;&lt;LI&gt;Publicly traded companies require SOX compliance.&amp;nbsp; Healthcare requires HIPAA compliance.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;To some degree, it is memorization.&amp;nbsp; In your own enterprise, you may not require many frameworks -- or in some cases, &lt;EM&gt;any&lt;/EM&gt; frameworks.&amp;nbsp; But your IT strategy follows the leadership of your board, so you should know what influences their decisions.&amp;nbsp; As the professional security person, you'll need to know how to advise your org and steer security.&amp;nbsp; Big or small, frameworks are a great way to begin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(edited)&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 02:14:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/References-to-standards-and-frameworks/m-p/60961#M869</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-07-20T02:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: References to standards and frameworks</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/References-to-standards-and-frameworks/m-p/60975#M872</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great explanation!&amp;nbsp; Especially relevant in a global economy.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 20:14:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/References-to-standards-and-frameworks/m-p/60975#M872</guid>
      <dc:creator>tldutton</dc:creator>
      <dc:date>2023-07-19T20:14:13Z</dc:date>
    </item>
  </channel>
</rss>

