Many orgs use a control framework (NIST 800-53, HITRUST CSF, COBIT, SIG, ISF SoGP, ISO 27002, CSA CCM) that doesnt completely express that orgs security/privacy/risk mgmt posture.
It behooves those orgs to use a hybrid mapped back to those frameworks.
No comments:
Post a Comment