Session
Insert Coin: Frameworks Turn Risk Into Reality (Part II)
Subtitle: CIS Controls first, then prove it across everything else.
In Part I, we said it out loud: if you’re not keeping score, you’re just playing games with cyber risk.
Missed that session? No problem. This is where you learn how to actually keep score.
You start with something that defines “good.” For most organizations, that means CIS Controls v8.1.
Because without a framework, you’re guessing. With one, you’re measuring.
From there, it scales. NIST CSF 2.0, NIST 800-53, 800-171, CMMC, HIPAA, PCI, etc... they don’t replace each other. They layer. And done right, they don’t create more work, they give you clarity.
We’ll walk through how to build a baseline, map across frameworks, and turn control gaps into business risk decisions leadership actually understands.
And yes, your score includes more than just you.
We will touch on Third Party Risk Management (TPRM) as well.
You can keep guessing… or you can start keeping score.
Brad Mathis
Brad Mathis, CISSP | vCISO, Senior Information Security Consultant with Keller Schroeder
Evansville, Indiana, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top