Educause Security Discussion mailing list archives

Re: ISO27001 vs NIST 800-171


From: James Farr <jfarr () UTICA EDU>
Date: Fri, 31 Aug 2018 09:34:43 -0400

Chris,



This email is not a direct answer, but have you looked at the Information
Security Program Assessment Tool?
https://library.educause.edu/resources/2015/11/information-security-program-assessment-tool

This can help you map your progress to NIST and ISO.   Any framework is
better than no framework.



James Farr ā€™05 Gā€™12

Director of Information Security and Network Specialist

Utica College

jfarr () utica edu

315-223-2386









*From:* The EDUCAUSE Security Constituent Group Listserv <
SECURITY () LISTSERV EDUCAUSE EDU> *On Behalf Of *Davis, Chris
*Sent:* Friday, August 31, 2018 9:21 AM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* [SECURITY] ISO27001 vs NIST 800-171



Can anyone provide me a quick and dirty compare/contrast between the two?
Which is more appropriate for a higher education setting seeking to comply
with the various regulatory requirements typically found in higher ed?



Thanks!



Chris





*Christopher Davis, Ph.D.*
Chief Information Officer
Assistant Professor of Education
Apple Teacher
Lourdes University
6832 Convent Blvd | REH 003P | Sylvania, OH 43560
cdavis () lourdes edu

*CyberAware ā€“ Be aware. Stay Secure!*
Lourdes University will never ask you to send sensitive information
through unsecure channels. Report any message that asks you to provide
or confirm personal information such as credit card and/or bank
account numbers, Social Security numbers, passwords, etc. or any
other suspicious activity to infosec () lourdes edu. For more information
please visit lourdes.edu/cyberaware.

*CONFIDENTIALITY NOTICE: *The contents of this email message and any
attachments are intended solely for the addressee(s) and may
contain confidential and/or privileged information and may be
legally protected from disclosure. If you are not the intended recipient of
this message or their agent, or if this message has been addressed to
you in error, please immediately alert the sender by reply email and then
delete this message and any attachments. If you are not the intended
recipient, you are hereby notified that any use, dissemination, copying, or
storage of this message or its attachments is strictly prohibited.

Current thread: