<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>comparison Archives -</title>
	<atom:link href="https://zymitry.com/tag/comparison/feed/" rel="self" type="application/rss+xml" />
	<link>https://zymitry.com/tag/comparison/</link>
	<description>Tech &#38; Other Stuff</description>
	<lastBuildDate>Thu, 05 Jun 2025 22:55:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://i0.wp.com/zymitry.com/wp-content/uploads/2016/11/favicon.png?fit=32%2C32&#038;ssl=1</url>
	<title>comparison Archives -</title>
	<link>https://zymitry.com/tag/comparison/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">120106411</site>	<item>
		<title>Primary Advantages of COBIT, ISO 27000, and NIST</title>
		<link>https://zymitry.com/primary-advantages-cobit-iso-27000-nist/</link>
					<comments>https://zymitry.com/primary-advantages-cobit-iso-27000-nist/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Tue, 23 Jan 2018 04:01:31 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[advantages]]></category>
		<category><![CDATA[COBIT]]></category>
		<category><![CDATA[comparison]]></category>
		<category><![CDATA[frameworks]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[similar]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=896</guid>

					<description><![CDATA[<p>The following is a list of the primary benefits of the COBIT, ISO 27000, and NIST frameworks: COBIT COBIT allows much broader scope and takes into account all IT management processes. Geared towards a method of successfully executing key policies and procedures. It is often used to tie together controls, technical issues and risks, within… <span class="read-more"><a href="https://zymitry.com/primary-advantages-cobit-iso-27000-nist/">Read More: Primary Advantages of COBIT, ISO 27000, and NIST &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/primary-advantages-cobit-iso-27000-nist/">Primary Advantages of COBIT, ISO 27000, and NIST</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The following is a list of the primary benefits of the COBIT, ISO 27000, and NIST frameworks:</p>
<p><span style="text-decoration: underline;">COBIT<br />
</span></p>
<ul>
<li>COBIT allows much broader scope and takes into account all <a href="https://zymitry.com/leaderships-role-information-security/" target="_blank" rel="noopener">IT management</a> processes.</li>
<li>Geared towards a method of successfully executing key <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policies</a> and procedures. It is often used to tie together controls, technical issues and risks, within an organization.</li>
<li>COBIT is managed by the Information Systems Audit and Control Association (ISACA) so it is kept up to date with current technology, and is globally accepted.</li>
<li>Allows scope to extend beyond IT and into management of the organization.</li>
</ul>
<p><span style="text-decoration: underline;">ISO 27002</span></p>
<ul>
<li>ISO 27002 provides best practice recommendations for an Information Security Management System (ISMS) standard. The 27001 and 27002 are used together to provide a management system, and specify industry-related controls. The ISO 27002 is an IT department focused standard.</li>
<li>Allows system managers to identify and mitigate gaps and overlaps in coverage.</li>
<li>Limited in scope compared to other standards.</li>
</ul>
<p><span style="text-decoration: underline;">NIST</span></p>
<ul>
<li>NIST is a Federal Government standard that covers a Risk Management Framework which addresses security controls in accordance with the Federal Information Processing Standard (FIPS) 200. This means that the standard has been through a very stringent review process and is very thorough.</li>
<li>Provides a level of detail for organizations not wanting to do a lot of customization. Comprehensive.</li>
<li>Like the ISO standard, NIST is limited in scope to information security.</li>
</ul>
<p>&nbsp;</p>
<p>When comparing COBIT to the other standards, it does have some appealing advantages. Since it allows for a wide-scope to include management outside of IT, it makes it easier to customize and integrate into the organization. COBIT is a good choice for an organization-wide framework allowing flexibility. Both ISO and NIST are restricted in scope to IT, and are not as flexible. A notable point is that all Government agencies and contractors must adhere to NIST standards. Much depends on the organization, its purpose, and if it is private or Government affiliated. For large private enterprises with no Government ties, COBIT is a desirable framework because of its broad scope, and flexibility.</p>
<p>&nbsp;</p>
<p>References</p>
<p>Agnosticator. (2013, December 09). <em>A Comparison of COBIT, ITIL, ISO 27002 and NIST. </em>Retrieved September 9, 2017, from <a href="http://agnosticationater.blogspot.com/2013/12/a-comparison-of-cobit-itil-iso-27002.html" target="_blank" rel="noopener">http://agnosticationater.blogspot.com/2013/12/a-comparison-of-cobit-itil-iso-27002.html</a>.</p>
<p>Gallagher, P. D. (2013, April). <em>NIST Special Publication 800-53 Revision 4. Security and </em><em>Privacy Controls for Federal Information Systems and Organizations.</em> Retrieved September 9, 2017, from <a href="https://web.archive.org/web/20250531222210/https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-53r4.pdf" target="_blank" rel="noopener">http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf</a>.</p>
<p>The post <a href="https://zymitry.com/primary-advantages-cobit-iso-27000-nist/">Primary Advantages of COBIT, ISO 27000, and NIST</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/primary-advantages-cobit-iso-27000-nist/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">896</post-id>	</item>
		<item>
		<title>Information Security Publication Comparison</title>
		<link>https://zymitry.com/information-security-publication/</link>
					<comments>https://zymitry.com/information-security-publication/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 26 Nov 2016 04:18:17 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[comparison]]></category>
		<category><![CDATA[Handbook AS-805]]></category>
		<category><![CDATA[ISO27002]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[publication]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=297</guid>

					<description><![CDATA[<p>Information Security Publication Comparison: Chart comparing major sections of the USPS Handbook AS-805 - Information Security to NIST Special Publications; 800-12, 800-14, 800-18, 800-26, and 800-30.</p>
<p>The post <a href="https://zymitry.com/information-security-publication/">Information Security Publication Comparison</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>Information Security Publication Comparison</h1>
<p>&nbsp;</p>
<p><strong>Information Security Publication Comparison</strong></p>
<h4>Chart comparing major sections of the USPS Handbook AS-805 &#8211; Information Security to NIST Special Publications; 800-12, 800-14, 800-18, 800-26, and 800-30.</h4>
<table style="height: 1437px;" width="911">
<tbody>
<tr>
<td width="319"><strong>Handbook AS-805 &#8211; Information Security (USPS, 2015)</strong></td>
<td width="319"><strong>NIST Special Publications</strong></td>
</tr>
<tr>
<td width="319">Introduction: Corporate Information Security</td>
<td width="319">Generally Accepted System Security Principles (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Security Roles and Responsibilities</td>
<td width="319">System Security Plan Responsibilities <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a>,  (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Information Designation and Control</td>
<td width="319">Generally Accepted System Security Principles (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Security Risk Management</td>
<td width="319">Guide for Conducting Risk Assessments. <a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-30) </a>(NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Acceptable Use</td>
<td width="319">Generally Accepted System Security Principles (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Personnel Security</td>
<td width="319">Generally Accepted System Security Principles (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Physical and Environmental Security</td>
<td width="319">3.10 Physical and Environmental Security (NIST SP 800-14), Physical and Environmental Security (NIST SP 800-12),</td>
</tr>
<tr>
<td width="319">Development and Operations Security</td>
<td width="319">1.5 Major Applications, General Support Systems, and Minor Applications <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a>, 3.9 Security Considerations in Computer Support and Operations (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Information Security Services</td>
<td width="319">3.14 Minimum Security Controls <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a></td>
</tr>
<tr>
<td width="319">Hardware and Software Security</td>
<td width="319">Several chapters (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Network Security</td>
<td width="319">2.3 General Support Systems <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a> Management Control (NIST SP 800-12)</td>
</tr>
<tr>
<td width="319">Business Continuity Management</td>
<td width="319">3.6 Preparing for Contingencies and Disasters (NIST SP 800-14),</td>
</tr>
<tr>
<td width="319">Security Incident Management</td>
<td width="319">12.0 Computer Security Incident Handling (NIST SP 800-12), 3.7 Computer Security Incident Handling (NIST SP 800-14)</td>
</tr>
<tr>
<td width="319">Security Compliance and Monitoring</td>
<td width="319">3.16 Ongoing System Security Plan Maintenance <a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">(NIST SP 800-18)</a></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<h4>Chart comparing the ISO/IEC 27002 with NIST Publications</h4>
<table style="height: 1740px;" width="917">
<tbody>
<tr>
<td width="235"><strong>ISO27002 </strong><a href="https://web.archive.org/web/20220702104124/https://www.praxiom.com/iso-27002.htm" target="_blank" rel="noopener noreferrer">(Praxiom web, 2013)</a></td>
<td width="83"><strong>NIST 800-12</strong></td>
<td width="79"><strong>NIST 800-14</strong></td>
<td width="78"><a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer"><strong>NIST 800-18</strong></a></td>
<td width="90"><strong>NIST 800-26</strong></td>
<td width="96"><a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer"><strong>NIST 800-30</strong></a></td>
</tr>
<tr>
<td width="235">Security Policy Management</td>
<td width="83">Covered. NIST is more of an overview</td>
<td width="79">Covers many aspects such as security program management.</td>
<td width="78">Covered. Both cover same aspects.</td>
<td width="90">Not directly covered. Program management briefly covered.</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Corporate Security Management</td>
<td width="83">Covered. NIST is more of an overview</td>
<td width="79">Covered in depth.</td>
<td width="78">Covers duties and responsibilities.</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Personal Security Management</td>
<td width="83">Covers personnel/user issues</td>
<td width="79">Both cover same aspects</td>
<td width="78">Not covered</td>
<td width="90">Covered only as a checklist item</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Organizational Asset Management</td>
<td width="83">Covered</td>
<td width="79">Not covered</td>
<td width="78">Not Covered</td>
<td width="90">Covered</td>
<td width="96">Not Covered</td>
</tr>
<tr>
<td width="235">Information Access Management</td>
<td width="83">Covered Chapter 17</td>
<td width="79">Covered Chapter 3</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Cryptography Policy Management</td>
<td width="83">Covered Chapter 19</td>
<td width="79">Covered briefly Chapter 3.14</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Physical Security Management</td>
<td width="83">Covered Chapter 15</td>
<td width="79">Covered Chapter 3.10</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not Covered</td>
</tr>
<tr>
<td width="235">Operational Security Management</td>
<td width="83">Covered</td>
<td width="79">Covered. ISO 27002 offers more detail</td>
<td width="78">Covered</td>
<td width="90">Covered</td>
<td width="96">Covered</td>
</tr>
<tr>
<td width="235">Network Security Management</td>
<td width="83">Covered only as a control</td>
<td width="79">Covered only as a system</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">System Security Management</td>
<td width="83">Not covered</td>
<td width="79">Not covered</td>
<td width="78">Covered Chapter 2.3</td>
<td width="90">Covered Chapter 3.1.2</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Supplier Relationship Management</td>
<td width="83">Covered as overview Chapter 10</td>
<td width="79">Not covered</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Not covered</td>
</tr>
<tr>
<td width="235">Security Incident Management</td>
<td width="83">Covered in detail 11 &amp; 12</p>
<p>&nbsp;</td>
<td width="79">Covered Chapter 3.7</td>
<td width="78">Not covered</td>
<td width="90">Not covered</td>
<td width="96">Covers threat events and response</td>
</tr>
<tr>
<td width="235">Security Continuity Management</td>
<td width="83">Not covered</td>
<td width="79">Covers security reassessment</td>
<td width="78">Covered Chapter 3.16</td>
<td width="90">Covered Chapter 4.3.1</td>
<td width="96">Covers assessment cycle</td>
</tr>
<tr>
<td width="235">Security Compliance Management</td>
<td width="83">Covered Chapter 6</td>
<td width="79">Covers as part of policy</td>
<td width="78">Covered Chapter 3.12</td>
<td width="90">Covers compliance reviews</td>
<td width="96">Covered</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<h4>References</h4>
<p><a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer">http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf</a></p>
<p><a href="https://web.archive.org/web/20220702104124/https://www.praxiom.com/iso-27002.htm" target="_blank" rel="noopener noreferrer">http://www.praxiom.com/iso-27002.htm</a></p>
<p><a href="https://csrc.nist.gov/publications/detail/sp/800-12/archive/1995-10-02" target="_blank" rel="noopener">https://csrc.nist.gov/publications/detail/sp/800-12/archive/1995-10-02</a></p>
<p><a href="http://csrc.nist.gov/publications/nistpubs/800-14/800-14.pdf" target="_blank" rel="noopener noreferrer nofollow">Click to access 800-14.pdf</a></p>
<p><a href="https://web.archive.org/web/20250529010625/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf" target="_blank" rel="noopener noreferrer">http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf</a></p>
<p>https://about.usps.com/handbooks/as805/welcome.htm</p>
<h4>Additional Articles</h4>
<p><a href="https://zymitry.com/byod-policies-practices/" target="_blank" rel="noopener">Bring Your Own Device (BYOD) Policies and Practices</a></p>
<p><a href="https://zymitry.com/governance-cloud-systems/" target="_blank" rel="noopener">The Governance of Cloud-Based Systems</a></p>
<p><a href="https://zymitry.com/cloud-computing-saas-paas-iaas/" target="_blank" rel="noopener">Cloud Computing Models -SaaS, PaaS, IaaS</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-implications-exploration/" target="_blank" rel="noopener">Exploring the Implications of Artificial Intelligence</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-texas-higher-ed/" target="_blank" rel="noopener">Artificial Intelligence in Texas Higher Education: Ethical Considerations, Privacy, and Security</a></p>
<p><a href="http://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></p>
<p><a href="https://zymitry.com/terms-conditions-use/" target="_blank" rel="noopener">Terms and Conditions of Use</a></p>
<p>&nbsp;</p>
<p>The post <a href="https://zymitry.com/information-security-publication/">Information Security Publication Comparison</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/information-security-publication/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">297</post-id>	</item>
	</channel>
</rss>
