Posts: 44
Threads: 14
Joined: Feb 2019
Reputation:
4
The SOC-CMM is currently aligned with NIST CSF 1.0 and NIST CSF 1.1. Indirectly, this connects the SOC-CMM to other standards, such as: COBIT 5, ISO/IEC 27001:2013 and NIST SP 800-536. What additional alignments could be valueable to the SOC-CMM community?
Keep calm and share knowledge
Posts: 1
Threads: 0
Joined: Jun 2019
Reputation:
0
Could be interesting if we could consider: https://www.cisecurity.org/controls/
The 20 controls probably are really basic, but when you go deep, you will found there are some interesting controls associated.
Posts: 44
Threads: 14
Joined: Feb 2019
Reputation:
4
Hi Jquin,
Sorry for the late reply. I've never considered the CSC before. Mostly because of the fact that it's too high level. But I agree that there's more to CSC than just the high level part of it. I'm going to take a more detailed look. Even if it's not fit for mapping purposes, it may still be useful for further improving the capability side of the SOC-CMM.
Regards,
Rob.