Your Cyber Path: How to Get Your Dream Cybersecurity Job · Kip Boyle

EP 114 - NIST CSF Versus The Top 18

January 19, 2024·50 min·5 clips
The show opens in holiday mode. Kit and Jason share a few December life updates, talk about twin girls turning nine, and mention end-of-year bookkeeping before the conversation settles into cybersecurity guidance. Then the lesson begins. The main comparison is between the cybersecurity framework and the Top 20 controls list, with the hosts describing one as something you adapt to your organization and the other as something you can start using right away. That distinction matters. They point out that practitioners often want a checklist because it cuts through the planning haze and gives them something concrete to do instead of another abstract exercise. Inventory comes first. That leads to the idea that if you do not know what assets you have, you cannot really protect them, which makes asset visibility the base for everything that follows. They keep it practical. The framework is presented as useful, but not something you should turn into a project plan without thought, because real security work still needs tailoring, context, and judgment. The controls skip some of that debate. That is part of why the list appeals to people who want to move quickly, since it tells them where to start without making them build every layer from scratch. The tone stays grounded. Even when the hosts are talking about standards and controls, they keep translating the ideas into everyday stakes, project-management reality, and the kind of decisions listeners actually face. It never gets too formal. Instead of sounding like a policy seminar, the episode keeps coming back to simple questions about what exists, what needs protection, and what kind of guidance helps a team get moving. That makes it easy to follow. The conversation is roomy and conversational, with enough context and repetition to help the comparison land for listeners who are still learning how the security landscape fits together. The finish is useful. By the end, the episode leaves a clear impression that the right tool depends on whether you need a broad framework to adapt or a tight list of controls to put into action immediately.

As heard by us

A practical comparison of a cybersecurity framework and a more prescriptive controls list, with inventory and asset visibility at the center.

It treats cybersecurity as a choice between a flexible framework and a more prescriptive set of controls, and it keeps that contrast tied to actual day-to-day work.

Read the full review in PlayNext →

Why you'd press play

Want the framework-versus-checklist answer without the jargon fog?

Read the full recommendation in PlayNext →
Listen to the show on