- You have started to use Info-Tech’s information security control framework to assess the maturity of your information security program.
- Your compliance, internal controls, or other similar department requires you to use an industry standard control framework for compliance purposes.
- Depending on your geographic location and industry, you may be required to use one or more NIST, ISO, or other framework.
- You need to understand how your security strategy assessment aligns to one of these frameworks.
Our Advice
Critical Insight
- Focus on the risk that the control is addressing rather than getting caught up in the weeds.
- When it comes to compliance, use these tools as a starting point but always verify your compliance requirements using the target framework.
Impact and Result
- Don’t reinvent the wheel by reassessing your security program using a new framework.
- Instead, use the tools in this blueprint to align your current assessment outcomes to required standards.