
Penetration Testing Stories w/ Emilie St-Pierre - PSW #788
Paul's Security Weekly (Audio)
00:00
CISA and NIST: A Comparison
CISA has a lot of influence. Yes. But where does there are authority law? I feel like they can make a lot of recommendations. It's left to other branches and government entities to be the stick. NIST is not the force meant right. Creates the standard but even then it was originally focused on public sector but somehow the private sector has embraced NIST. CISA may say NIST may say you must as a government agency run up to date software patch within a certain window yet some companies were running six year old version of Microsoft IAS.
Transcript
Play full episode