Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

How are we doing

  • Where are our gaps? — ISO/IEC 27001 2022

    Work through what ISO 27001:2022 actually asks for and see which parts you would struggle to evidence. For an organisation working towards certification, holding it, or answering a customer who has asked.

    118 requirements · ISO/IEC 27001 2022 · 11 clauses and control themesAbout 70 minutesNo account needed

  • Where are our gaps? — NIST Cybersecurity Framework 2.0

    A broad look at how your organisation manages cyber risk, covering governance and recovery as thoroughly as defences. No certification in view — NIST CSF is free to read and there is nothing to pass.

    106 requirements · NIST Cybersecurity Framework 2.0 · 6 functionsAbout 65 minutesNo account needed

  • How mature is our vulnerability management?

    Answer questions about how your vulnerability programme actually works, from which systems are scanned to what management decides. You get the three changes most likely to reduce risk, each with the document that helps.

    28 questions · 8 parts of a programmeAbout 15 minutesNo account needed

More are being written, framework by framework. The framework library covers the same ground in writing in the meantime.