Advisor
Wiki Standards, Frameworks & Models Security Frameworks

Security Frameworks 43 articles

01
Assurance & Attestation Frameworks Overview
Overview Assurance and attestation frameworks are structured methodologies designed to evaluate and validate the effectiveness of an organization's security controls and risk management practices. They help organizations demonstrate compliance, build…
02
BCP/DR Governance Framework
Overview The Business Continuity Planning and Disaster Recovery (BCP/DR) Governance Framework is a structured approach designed to ensure organizations maintain operational resilience in the face of disruptions. It addresses the…
03
Center for Internet Security Foundations
Overview The Center for Internet Security (CIS) Foundations is a cybersecurity framework designed to provide organizations with prioritized and actionable security controls to mitigate the most pervasive cyber threats. It…
04
CIS Benchmarks Framework
Overview The CIS Benchmarks Framework is a set of best practice guidelines designed to improve the security posture of IT systems through standardized configuration baselines. It helps organizations reduce vulnerabilities…
05
COBIT Governance Framework
Overview COBIT (Control Objectives for Information and Related Technologies) is a governance framework designed to help organizations manage and govern enterprise IT effectively. It addresses security and risk management challenges…
06
Control Mapping & Crosswalk Methodologies
Overview Control Mapping and Crosswalk Methodologies are systematic approaches used to align and correlate security controls across multiple standards, frameworks, or regulatory requirements. They help organizations streamline compliance efforts, reduce…
07
CSA Cloud Controls Matrix (CCM)
Overview The CSA Cloud Controls Matrix (CCM) is a cybersecurity framework designed to provide fundamental security principles for cloud providers and users. It addresses the challenge of establishing consistent security…
08
DORA ICT Risk Management Framework
Overview The DORA ICT Risk Management Framework is a regulatory-driven framework designed to enhance the management of information and communication technology (ICT) risks within financial institutions. It helps organizations identify,…
09
FFIEC Cybersecurity Assessment Tool
Overview The FFIEC Cybersecurity Assessment Tool is a standardized framework developed to help financial institutions identify their cybersecurity risks and determine their cybersecurity preparedness. It assists organizations in evaluating their…
10
GDPR Security & Accountability Framework
Overview The GDPR Security & Accountability Framework is a structured approach designed to help organizations comply with the data protection requirements set forth by the European Union’s General Data Protection…
11
HIPAA Security Rule Framework
Overview The HIPAA Security Rule Framework is a regulatory standard designed to protect electronic protected health information (ePHI) by establishing administrative, physical, and technical safeguards. It helps healthcare organizations and…
12
IEC 62443 Industrial Security Framework
Overview IEC 62443 is an international series of standards and technical reports that provide a comprehensive framework for securing industrial automation and control systems (IACS). It addresses cybersecurity challenges specific…
13
ISO 22301 Business Continuity Framework
Overview ISO 22301 is an international standard for Business Continuity Management Systems (BCMS) that provides a framework to help organizations prepare for, respond to, and recover from disruptive incidents. It…
14
ISO/IEC 27001 ISMS Framework
Overview ISO/IEC 27001 is an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It helps organizations systematically manage sensitive information…
15
ISO/IEC 27002 Controls Guidance
Overview ISO/IEC 27002 is an international standard providing guidelines and best practices for implementing information security controls within an organization. It helps organizations establish a comprehensive set of security measures…
16
ISO/IEC 27017 Cloud Security Controls
Overview ISO/IEC 27017 is an international standard providing guidelines for information security controls applicable to the provision and use of cloud services. It addresses the unique security challenges in cloud…
17
ISO/IEC 27018 Cloud Privacy Controls
Overview ISO/IEC 27018 is an international standard that provides a code of practice for protecting personally identifiable information (PII) in public cloud environments. It addresses privacy concerns by establishing controls…
18
ITIL Security Management Practices
Overview ITIL Security Management Practices are a set of guidelines within the ITIL framework focused on aligning IT security with business needs. They help organizations establish consistent security controls and…
19
Microsoft SDL (Secure Development Lifecycle) Overview
Overview The Microsoft Secure Development Lifecycle (SDL) is a software development process framework designed to integrate security and privacy considerations into every phase of software development. It helps organizations reduce…
20
MITRE ATT&CK as a Defensive Framework
Overview MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. As a defensive framework, it helps organizations enhance their cybersecurity posture by…
1 2 3 43 articles · page 1 of 3