Explores the distinction between the two information security standards that companies new to security commonly encounter. The piece addresses whether the standards are identical, whether one supersedes the other, and whether organizations need to implement both.