<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Yet another day in the life of a security consultant.]]></title><description><![CDATA[<p>Yet another day in the life of a security consultant. </p><blockquote><p>COO (and vCISO at ‘Client’): We should do NIST CSF assessments. Make it so.<br />Me and Team: Got it! Here we go, who will be the first client?<br />COO: We’ll be the first client!<br />Me: Great!<br />Me:  - Reminder: No wrong answers! The whole point is to see what you have in place when compared to the various domains and controls/requirements identified by NIST.<br />COO: WOAH WOAH WOAH this is NOT what I wanted. This scope is too broad! We gotta pare this down.<br />Me: …</p></blockquote><p><a href="https://infosec.exchange/tags/nist" rel="tag">#<span>nist</span></a> <a href="https://infosec.exchange/tags/csf" rel="tag">#<span>csf</span></a> <a href="https://infosec.exchange/tags/framework" rel="tag">#<span>framework</span></a> <a href="https://infosec.exchange/tags/assessment" rel="tag">#<span>assessment</span></a> <a href="https://infosec.exchange/tags/justdoit" rel="tag">#<span>justdoit</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/3077b405-e743-4138-99d2-c973a37caf81/yet-another-day-in-the-life-of-a-security-consultant.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 01:14:23 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/3077b405-e743-4138-99d2-c973a37caf81.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 14 Apr 2026 13:22:29 GMT</pubDate><ttl>60</ttl></channel></rss>