3 ms·
I've worked on a couple of these NIST or ISO 27001 assessments and I would bet that even this company would meet some standard of "have access control". The aud
by txcwpalpha 6y ago
I've worked on a couple of these NIST or ISO 27001 assessments and I would bet that even this company would meet some standard of "have access control". The audit/certification often won't care that the access control you have is "the bucket allows public access", it's still an access control!
For that matter, it's entirely possible they had security testing "controls" too. But again, the audit/certification probably won't even care that the security testing team is one guy who sometimes tests the app login every couple of weeks. "Oh, Jim tested to make sure that the app only allows 3 password attempts? Security Testing: Check!"
Don't get me wrong, the ISO/NIST frameworks are absolutely a good thing. For a lot of my work, they've been my bible. They are fantastic guides to help companies who want to be more secure focus their efforts and understand how they measure up. But that's only for companies that really want to be more secure. For all of the companies out there that just want to check a checkbox or pass an audit, these frameworks are way way too easy to give a "false positive".