In the 1990s government agencies, industry groups, and cybersecurity researchers started creating cybersecurity standards and these standards led to cybersecurity regulations and laws that dictate to organizations what they must do to protect their data. Today, there are now dozens of standards that organizations can consider when building their cybersecurity plans and more are released every year. To make the problem even more challenging, no two standards are the same, nor do they even cover the same scope of defenses.
This reality has led to confusion and frustration for organizations seeking to build comprehensive cybersecurity programs. What should we do, what can we do, or must do to protect own information systems? Until recently there has not been a Cyber Rosetta Stone for security and privacy professionals to use to compare these standards. Most organizations have limited resources and must choose which controls to implement and which to ignore. We haven’t had risk or threat models to demonstrate why certain cybersecurity controls are important and what should be prioritized.
In this webcast, James Tarala, Senior Faculty at the SANS Institute and Principal Consultant at Enclave Security, will explain the state of cybersecurity standards in 2021 with a scorecard comparison of popular standards bases on specific, measurable research performed just this year to compare and contrast each of the most popular cybersecurity standards available to organizations today. He will also introduce a Cyber Rosetta Stone that simplifies building a cybersecurity control libraries across all the standards. Attendees will leave this webcast with a clear understanding of the differences and gaps in cybersecurity standards that will support their informed decisions about which standards to use when building their own cybersecurity programs.