Frameworks Provide Many Benefits, but Implementation Is Key
- By providing a standard against which you can measure, a framework enables a more scientific approach to security governance.
- Realizing the benefits of a standard framework depends on effective implementation, which is not always so easy.
“With a framework, you can be quantitative. You can use data to convince people why they should do something one way and not another. That’s the scientific way.”
Avinash Tiwari, who oversees information security and risk management at a financial services company based in the United States, says, “People are benefiting from several standard frameworks in the market today. If you are implementing a framework, there’s no need to reinvent the wheel.”