In today’s environment, every company looks to a security framework or certification to guide their progress. But with the number of options, requirements from customers and regulations can lead to chaos. Additionally, when recruiting new talent, an emphasis on the framework and certification used by the company is overemphasized. This can lead to not obtaining the best qualified candidates, simply because hiring managers and HR does not really understand other frameworks. This session intends to demystify some of the most prevalent security frameworks and certifications, to understand the strengths of each. Further a method to developing metrics from frameworks will be presented.