All security programs depend on having some basic controls, called a control baseline, in place. After all, one would not deem a house or an office “secure” without locks on the doors to control entry.
There are many technical and nontechnical controls that a business could implement, but few businesses have the time, money, or inclination to implement them all. Some guidance is needed to determine which controls are most needed, and to that end the industry provides various standard control frameworks.
Some control frameworks – such as the International Organization for Standardization ...