<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Controls Framework (SCF) in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Security-Controls-Framework-SCF/m-p/42346#M5250</link>
    <description>&lt;P&gt;Just came across &lt;A href="https://www.securecontrolsframework.com/" target="_blank"&gt;https://www.securecontrolsframework.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Holy crow! That is &lt;STRONG&gt;enormous&lt;/STRONG&gt;! 32 domains! 750 plus controls! Holistic! Compliance! (With absolutely everything!) A metaframework! The CIA triad expanded to the CIAS quadrants (adding Safety)!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I &lt;STRONG&gt;do&lt;/STRONG&gt; rather like the fact that it is volunteer run. But I suspect that it is already too unwieldy to be a decent guide, and may become even more so. On the other hand, I've always said that, whatever you learn can be used in security, so ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect it would make a rather good study guide for those going for the CISSP exam. If you are familiar with all of this, you're ready.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:45:42 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2023-10-09T09:45:42Z</dc:date>
    <item>
      <title>Security Controls Framework (SCF)</title>
      <link>https://community.isc2.org/t5/Industry-News/Security-Controls-Framework-SCF/m-p/42346#M5250</link>
      <description>&lt;P&gt;Just came across &lt;A href="https://www.securecontrolsframework.com/" target="_blank"&gt;https://www.securecontrolsframework.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Holy crow! That is &lt;STRONG&gt;enormous&lt;/STRONG&gt;! 32 domains! 750 plus controls! Holistic! Compliance! (With absolutely everything!) A metaframework! The CIA triad expanded to the CIAS quadrants (adding Safety)!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I &lt;STRONG&gt;do&lt;/STRONG&gt; rather like the fact that it is volunteer run. But I suspect that it is already too unwieldy to be a decent guide, and may become even more so. On the other hand, I've always said that, whatever you learn can be used in security, so ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect it would make a rather good study guide for those going for the CISSP exam. If you are familiar with all of this, you're ready.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:45:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Security-Controls-Framework-SCF/m-p/42346#M5250</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T09:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security Controls Framework (SCF)</title>
      <link>https://community.isc2.org/t5/Industry-News/Security-Controls-Framework-SCF/m-p/42349#M5251</link>
      <description>&lt;P&gt;Safety -&amp;nbsp;&lt;SPAN&gt;Safety addresses reducing risk associated with embedded technologies that could fail or be manipulated by nefarious actors.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;^By that definition, that feature already falls under a security control family in NIST SP 800-53 (series).&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2021 02:53:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Security-Controls-Framework-SCF/m-p/42349#M5251</guid>
      <dc:creator>Until_then</dc:creator>
      <dc:date>2021-01-09T02:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Security Controls Framework (SCF)</title>
      <link>https://community.isc2.org/t5/Industry-News/Security-Controls-Framework-SCF/m-p/42367#M5254</link>
      <description>&lt;P&gt;Very cool!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2021 15:38:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Security-Controls-Framework-SCF/m-p/42367#M5254</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2021-01-10T15:38:58Z</dc:date>
    </item>
  </channel>
</rss>

