Related Posts
More Posts
GDS didn’t receive this message…

Additional Posts in Consulting
Why does my bed feel extra warm right now?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.





Why are you interviewing for a job in industry if you don't do a fundamental skill that it may require?
Recruiter said the manager liked me and I'm gonna be considered for the role! Seems like the holidays will drag this whole process out tho into 2017
Just say "per nist" a lot
Haha I wanna get out of doing the techy work and be involved in issues that C-suite care about. I know I can do it, it's simply understanding a bigger approach.
Congrats, OP
Not a risk guy, trying to gain an understanding of the approach
ISO 27001/2
You use industry frameworks and/or the organization's policies, procedures and standards to determine which "key controls" (or just all controls) that need to be assessed. If you're taking it a step further for control compliance, then it will require validation and possibly testing. A 'framework' is so vague, but typically involves a charter of some sort, defining risk thresholds, risk acceptance processes, policy exceptions, etc.
How do you do it, now?
Dont reinvent the wheel. Is it a financial institution? Use FDIC intrex guidance. Not a bank? Maybe try ISACA cyber framework/cobit.
^Nope.
Consulting is fake it 'til you make it. Industry isn't. Learn all the frameworks you want, but if you're in CYBER type role, you'll need to manage and execute beyond the framework.
COBIT/NIST/ISO go study up
Concur with EY2. Also read up on the EUs newish cyber security law.