
#112 - Attack Surface Management (with Richard Ford)
CISO Tradecraft®
00:00
You Get What You Measure, Right?
The NIST Cybersecurity Framework, ISO 27001 are some of the best practices. Do they all provide the same level of if you will structure to create the programs? Or is it just kind of potluck pick what everyone you like? I firmly believe you get what you measure, right? This is a fundamental truth of life. And so if you pick the wrong metrics for your program, you will end up getting whatever that metric, behavior drives.
Transcript
Play full episode