Is NIST CSF the responsibility of the CISO or IT Auditors? I’ve typically seen it fall under Audit vs Cyber function, but curious if that’s common.

like
Posting as :
works at
You are currently posting as works at

Implementation of controls per NIST CSF and other best practices is the responsibility of the CISO, auditing the information security controls based on NIST CSF is the IT auditor’s responsibility.

like

If you have a traditional 3LoD model then:

Design of controls and assurance of their operation would be the CISO (a 2nd line)
Implementation of the controls and monitoring of their performance would be operational and the CIOs responsibility (1st line)
Assurance for both would be done by the Auditor (3rd line).

If they chose to base some of that on a framework like CSF then all the roles can fit in there.

Sounds like it depends on the org.

Most of the time, it does sound like IT Auditors typically drives the NIST CSF audit and CISO is a key player in their interviews.

CISO takes the NIST CSF framework guidance though and uses it to drive security program activities.

like

Exactly

helpful

Both

likesmart

CISO

like

And if they’re astute enough, a 3rd party advisor assists to reduce the internal friction. 😉

helpful

Related Posts

Healthcare consulting practice. Deloitte vs Accenture vs other players. Thoughts on who has the best practice overall?

And any insight/who has the best practice in the provider space specifically?

like

How is work life balance at Citi Risk Team?

like
like

Why does everyone say the work in FDD is so much better than audit? I’ve been in the group for a few months now, and it seems to be just as bad if not worse.

likefunny

How is KPMG Advisory on the Cloud ? Is this more strategy side or tech side ?

like

I work at HCL as a Pre sales consultant which involves technical understanding and being in touch with latest technologies, I have got an offer from Genpact Bid Management team which I heard offer BPO services, should I join or stay in a techno functional role and how is the bid Management department in Genpact Genpact HCL Technologies

Bid Management Pre Sales

Any insight into STB’s tax group?

like

What does a manager in big4/protiviti internal audit consulting do? I’m an experienced bank senior auditor and looking to make the switch to IA advisory. Do managers work on outsourced/co-source IA engagements and are they still preparing work papers?

like

What are people’s thoughts on Infosys for Finance consulting? A friend has an offer and is wondering what their finance consulting practice is like /if it’s worth taking?

likefunny

How is SAP practice in LTI... Do we have ample implementation projects?

Will the learning be good and how about firm culture , onsite opportunities?

like

Does anyone have an opinion on the media team/s at General Mills?

like

What is the difference between FAAS and consulting?

like

What kind of skills would be considered key to a CN role as MC L9 in Accenture Strategy?

Any comparison of M&A in practice vs in-house?

like

need review on Work life balance and work culture at Bank of America Global Banking and Markets FP&A Projects team, Gurgaon.

Please reply. I need to make a decision.

like

Started at firm in second week of March and am at 1,700 right now, on pace for 2,000+. M&A 7th year. Who else is this busy? Keep reading M&A down across the board, but not feeling it here…

Obviously love the job security, but am at lockstep bonus firm and pretty sure at this point bonus will be on base scale last year, so kinda bummed about that.

like
like

Anyone with insight into the real estate group in Orrick’s LA office?

like

Could anybody provide any insights about the role of an acon in the deal advisory- deal origination team at KPMG

like

Between PwC, Deloitte, & EY. Which has the best NYC Tax Practice when it comes to comp and promotions?

like

More Posts

I joined pwc last month, and absolutely hating it here. Each weekend has been working, 12-15 hours work day is minimum expectation. And there's extreme hierarchy, where even after you spend 24 hours working on something, the director decides he wants something completely different and you delete and restart. (Note that you request them to review and give their pov earlier on, but they never take the time out)

like

I've gotten feedback that I'm too honest in my interviews, is that really a con for future employers? 🫤 How do I refrain from doing that anymore?

like

Is there a time limit on unemployment, 6months-1year? If I get the boot how long does it last? Thank you in advance for any help.

like

What’s the best grocery delivery service in the city? TIA

like

What is the experience required to become senior manager in US taxation

Anyone had success with CISSP audiobooks to study? I got a long commute!

Cissp cert is as much hard as it seems? Much more than cisa?

like

Anyone working in Pharma industry?

like

Help!! My bestfriend is doing two months abroad and was trying to fly into turkey when they told her she couldn't because her passport expired within three months.

She went to the US Embassay in Athens knowing she had a month left of traveling, and gave her an emergency passport and punched holes in her exsisting one. Now no country will let her in with her emergency passport.

Can her mom get her a passport in the US and ship it to her? Is there anyway around this?

Thank you!!

like

We as the armed forces of the United States have a research department, but the greatest advances at the armament level come from private sectors, this could not be something counterproductive because if they sell a product to us, what deprives them of selling it to other countries?

like

Healthcare consulting practice. Deloitte vs Accenture vs other players. Thoughts on who has the best practice overall?

And any insight/who has the best practice in the provider space specifically?

like

I’m looking for some ideas for informational texts beyond just an essay. My students will be comparing the theme of a short work of fiction with the central idea of a nonfiction text.

like

Anyone else here just chooses not to eat when too lazy to cook? 😅

likefunnyupliftinghelpful

Legit excuse to cover moonlighting 🤣

Post Photo
funnylike

Currently 1 YOE tech consulting at Deloitte looking to make a hop to more strategy type roles and came across the strategy analyst development program- 1. is this only for fresh undergrads from specific schools or would I be able to apply? 2. What’s the compensation at this level? (worried I might have to take a pay cut). Also would appreciate any remarks regarding the program in general. Thanks!

like

Always see people at the airport bar next to my gate at 9 am on Monday. Who the hell drinks on a Monday morning???

like

M/SM and above, why do you label a meeting as “touch point” or ask if you can have a “quick chat” when it’s something serious? Millennials like us always assume we’re about to get fired - I actually have been laid off in a meeting with that title. But at my new job, my boss asked for a “quick chat” to literally ask me to change the title of a meeting and then chat about christmas. Now that I’m in management, I want to understand it better.

like

Question: an employee was asked by his boss for same day turn around on responses/deliverables on a days he requested PTO. He completed the work. The manager wants to know if she can still deduct PTO time for the days requested, even though he completed work on those days. Help.

Hoping to get my PHR in the next year or so. Outside of employer reimbursement, are there other opportunities for this to get funded? I know SHRM Foundation offers scholarships for the CP, but I am looking for PHR specific help. Thank you! :)

Additional Posts in Cyber Security Bowl

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

What’s a good taxonomy for defining requirements for logging & monitoring? (i.e., apps, db, infra, etc.)

likefunny

New to the U.S., is the Healthcare Industry (via HIPAA), the only industry in the U.S. that legally mandates having a designated Privacy Officer? So for example, although GLBA has obvious privacy requirements, unlike with healthcare, financial institutions in the U.S. are not mandated by law to have a designated Privacy Officer?

like

Anyone had success with CISSP audiobooks to study? I got a long commute!

Cissp cert is as much hard as it seems? Much more than cisa?

like

Anyone working in Pharma industry?

like

Anyone else at CyberArk Impact this week? Anything exciting going on?

Any tips or tricks for CSX certification?

like

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

Curious how MBB's cybercapabilities are viewed within the cyber world. Experiences, thoughts?

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

For those who have passed the CIPM exam, what is it like (and how does it compare to the CIPP/US exam)?

What are exit ops for Big 4 Cybersecurity Consultants that are non technical (Strategy/Risk)?

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

What other professional services firms have people who have technical skills. Most the people I work with are security paper pushers who couldn’t tell you basic security shit.

like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

Exit opps at a manager level - Big4 vs industry jobs? Security Architect at FAANG vs the normal career path at PwC. If compensation being slightly better at FAANG, which one would you pick and why

like

Today I passed CIPP/US, and earned Security+ in early August. Interviewing for a cybersecurity role at Deloitte tomorrow! Super excited! Interested to connect with fish at Deloitte, especially Deloitte Global. Thanks!

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal