Framework vs Standard
Hello,
Just after some clarification regarding the above, I understand (I think!) concept in that a Framework is the collective term for a policy, standard, procedures and guidelines (please correct if wrong!).
What I am a little confused about is that, at least in my head is taking the ISO27000 vs ISO27001 as an example, to me the 27000 series is just that, a series which points towards different frameworks, 27001 been the PCI industry best practice framework, is that the case or is the 27000 a standard as well?
If the 27000 is a standard, can you please advise of the relevant framework for this?
Thanks!
Just after some clarification regarding the above, I understand (I think!) concept in that a Framework is the collective term for a policy, standard, procedures and guidelines (please correct if wrong!).
What I am a little confused about is that, at least in my head is taking the ISO27000 vs ISO27001 as an example, to me the 27000 series is just that, a series which points towards different frameworks, 27001 been the PCI industry best practice framework, is that the case or is the 27000 a standard as well?
If the 27000 is a standard, can you please advise of the relevant framework for this?
Thanks!
Comments
That's useful! Appreciate the clarification, That is what I thought but a few youtube videos were defining the ISO series as Frameworks..
Thanks,
Paul
standards give you a minimum level of things to do. they say you have to at least do x, y, and z. can also be vague, but not normally as vague as frameworks.