One Mans Frustrations With Risk Management
...writes
2. What are the controls that we have to employ
800-53, ISO 27001, PCI, etc
Still kinda good, but we basically know that ISO is relatively voluntary and NIST supplies a control catalog and not policies. So here we have to take the control catalog, and mash our policies into it
I wouldnt call this kinda good at all :) These control...
