|
|
|
|
|
by Spivak
2681 days ago
|
|
Sure but the point still stands. Why should anyone trust that you, or your company, is any good at security compared to say CIS? If you have homegrown security and can show your QSA your detailed policy document and that it's a superset of CIS, STIG, NIST, etc. with documented exceptions then it'll be no problem. I avoid homegrown whenever possible because it's a rabbit hole that never ends. If you instead say CIS level 2 then you can clearly define when you've done enough. |
|