Standards and frameworks for information security and risk abound. ISO 27001, ISO 31000, NIST, ISACA, and others. While a standard and complete approach to cybersecurity is needed, do you see any significant differentiation between them? Does the CSF add anything new?
You need to be a member of Global Risk Community to add comments!
Replies