Instruction
NIST is only one of many available frameworks companies can use to establish and manage their IT and security programs while meeting industry standards, regulations, compliance, and laws. This assignment will continue evaluating frameworks and the applicability.
In a two- to four-page paper, provide a comparison of five major frameworks. For each framework, identify the similarities and differences among each of the other frameworks in a matrix fashion.
Potential frameworks include: COSO, COBIT, ISO 27001, ITIL, NIST 800 Series, Risk Management Framework, Cybersecurity Framework, Factor Analysis of Information Risk (FAIR), Threat Agent Risk Assessment (TARA), or Operationally Critical Threat Asset and Vulnerability Evaluation (OCTAVE). Please note: Prince2, PMBOK, OPM3, SixSigma, and other Project Management based models are not applicable for this assignment
Include the following details as well:
Explain the purpose and how to apply each framework to a company.
List the similarities and differences among them.
Identify the advantages and disadvantages of each framework.
Provide your rationale about selecting a framework based on valuing human value and dignity vs. familiarity or for organization’s sake in light of Christian worldview.
Describe and provide example of industry or organization type the framework is best suited (i.e., hospital, banking, manufacturing, retail).
Briefly answer the questions below to explain the differences between the five frameworks selected and Access Control Models presented:
What is the difference between an Access Control Model and Security Framework?
Can Access Control Models and Frameworks be combined?
How does a framework impact an information system?
How does an Access Control Model impact an information system?