IDG Contributor Network: When it comes to security standards, one size doesn't fit all
The Defensive Security Podcast talked last week about comments made by the California attorney general in releasing a study of data breaches in that state. While the report itself did not include any earth-shattering insights, a related comment has caused quite a stir in the information security community. The AG indicated that those organizations not implementing the 20 controls discussed in the Center for Internet Security's Critical Security Controls document would not be considered to have "reasonable security."
To read this article in full or to leave a comment, please click here