Are NIST CSF assessments audits?

Broadly speaking, I’ve understood it as a broad framework where people use it to guide their cyber program maturity, but recently my organization has been treating them intensive audits/assessments.

like
Posting as :
works at
You are currently posting as works at

Got it, it sounds like my company delivers NIST as an audit offering, but typically NIST shouldn’t be an audit

like

You can use whatever you like as an audit as long as the audit committee are happy with it. From a delivery perspective it’s more subjective in comparison to CIS but with the right team it can be more valuable.

like

Not good for traditional audits.

like

Related Posts

Porsche IPO worth buying now amid market and economy turbulence?

like

Looking to buy an 💍. Might make a trip to India in 6 months. Any advice on helping me make the decision to buy in US vs India?

like

Most effective ab workouts to do at home? I know a bunch of different ones but looking to do more impactful moves in a shorter amount of time

like

What's the biggest life lesson joining the military taught you?

like

Are any of you sleeping all the time? Like all the time? I wake up, get some coffee and then I have no idea what to do from there. I have no reason to be awake.

like

What are good resources to find apartments in DC. I’m looking to live on my own, no roommates

like

What are my rights as a citizen during a random traffic stop?

like

My male SO was recently introduced to Le Labo and has been dropping hints. I want to get a cologne for him- what’s your fave at LL? I have a few faves, but I want to get more opinions

I’ve been seeing a lot of product roles lately and I’m just wondering if this was a good path to pursue (In terms of career growth, salary, etc.) I’ve working as a data analyst and am thinking of trying something else but I’m not sure what types of roles are really out there.

like

How much salary does jp pay to promoted associates in India? Which are not in tech

like

Any good book recommendations that helped give you the confidence and tactics required for a transition to leadership role? Newly promoted SM looking for inspirational reads.

like

Thoughts on taking a position in the same practice group and same class as your spouse?

like

*New Opening*
NYC Senior EA role supporting Head of Banking. In office role. Remote once a week.
Banking/Financial/Capital Markets experience highly preferred. Must be very polished. $115-130k yearly salary. Background cannot be jumpy.

DM if you have experience that lines up.

likefunny

Do you guys go into the office while on the bench

I'm in a litigation, about 9 months in. Is it normal that I spend majority of my time making bundles for my partners (printing, binding, moving docs in a different order whenever there are new documents or he wants to add stuff) reviewing documents and making tables (e.g. dates, which documents are from where), and the only legal work is like notices of admission, list of documents, the occasional research? I'm so bored and I want to quit but I don't know if I have unrealistic expectations.

like

How valuable or important are scrum skills in the current market?

like

Hi Fishes! I am searching for an opportunity in Financial Planning and Analysis role (Finance) with 7.7 years of experience. Any leads ? Appreciations in advance !!

like

Any one from Justworks willing to refer me?

Hi Fishes,

I have received an email from HR that you have been selected at citi and asking to send few documents like id, salary slip,few other forms that need to filled and scanned. It does not have compensation offered in any of the attached document. Can you help when they will release compensation offered part? What will be the further process? Will they call me and discuss? How does it go in citi?

like

How much actual court experience should a junior litigator expect to get in the first year? I've been my firm 6 months as a civil litigator not and have yet to go to a hearing. There have been a few (all relatively minor) but each time the partner tells me it's not important enough for me to attend. As a junior, I feel like I need to learn and no hearing is to minor. How else am I supposed to learn?

like

Additional Posts in Cyber Security Bowl

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Anyone else at CyberArk Impact this week? Anything exciting going on?

Thinking of moving from Big4 cyber to Accenture cyber. Any major differences (other than no channel restrictions).

like

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

Has anyone gone through the deloitte cyber risk interview process recently? How many interviews did you have and how was the process?? Salary?

like

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

How did you decide your speciality in Cybersecurity? Did you naturally gravitate towards one area?

like

New to the U.S., is the Healthcare Industry (via HIPAA), the only industry in the U.S. that legally mandates having a designated Privacy Officer? So for example, although GLBA has obvious privacy requirements, unlike with healthcare, financial institutions in the U.S. are not mandated by law to have a designated Privacy Officer?

like

Views on carbon black as a product?

helpful

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Anyone ever heard of or worked for Sygnia?

like

Any company is hiring EU citizens and helping with visa? interested in moving to USA. I'm lawyer, cissp, cisa, cipp/e and specialized n data privacy, cybersec ops and risk management with 8+ years exp

Anyone had success with CISSP audiobooks to study? I got a long commute!

We’re hiring across the board at KPMG for cyber / cyber risk work - shoot me a DM if interested. (Pays well!)

likehelpful

Has anyone made the move from cyber security at the Big4 to cyber security for media companies? For example Disney or Warner Bros.

How did you manage it?

like
like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

Laterals to Deloitte Cyber from other B4: Can you describe your interview process and what each one entailed? TIA!

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal