Security Frameworks 43 articles
More in Standards, Frameworks & Models:
Architecture Models 66
Maturity Models 50
Security Frameworks 43
Threat Models 47
21
MITRE D3FEND Framework
Overview The MITRE D3FEND Framework is a knowledge base of cybersecurity countermeasures designed to complement attack frameworks by cataloging defensive techniques. It helps organizations systematically understand and implement defensive strategies…
22
MITRE Shield (Active Defense) Overview
Overview MITRE Shield is a knowledge base and framework focused on active defense and adversary engagement techniques in cybersecurity. It helps organizations enhance their defensive posture by providing structured methods…
23
NERC CIP Framework Overview
Overview The NERC CIP Framework is a set of mandatory cybersecurity standards developed by the North American Electric Reliability Corporation (NERC) to protect the bulk electric system (BES) from cyber…
24
NIST CSF Profiles & Implementation
Overview NIST Cybersecurity Framework (CSF) Profiles and Implementation provide a structured approach for organizations to align cybersecurity activities with business requirements, risk tolerance, and resources. They help organizations tailor the…
25
NIST Privacy Framework
Overview The NIST Privacy Framework is a voluntary tool designed to help organizations manage privacy risks effectively. It provides a structured approach to identify, assess, and mitigate privacy-related issues while…
26
NIST Risk Management Framework (RMF)
Overview The NIST Risk Management Framework (RMF) is a structured process developed by the National Institute of Standards and Technology to integrate security, privacy, and risk management activities into the…
27
NIST Secure Software Development Framework (SSDF)
Overview The NIST Secure Software Development Framework (SSDF) is a set of practices designed to integrate security into the software development lifecycle. It helps organizations reduce vulnerabilities and improve the…
28
NIST SP 800-171 for CUI
Overview NIST Special Publication 800-171 provides a set of security requirements designed to protect Controlled Unclassified Information (CUI) in non-federal systems and organizations. It addresses the need for safeguarding sensitive…
29
NIST SP 800-53 Control Framework
Overview NIST Special Publication 800-53 is a comprehensive control framework designed to guide federal agencies and organizations in managing information security risks. It provides a catalog of security and privacy…
30
OWASP API Security Top 10
Overview The OWASP API Security Top 10 is a focused security framework that identifies the most critical risks associated with Application Programming Interfaces (APIs). It assists organizations in recognizing and…
31
OWASP ASVS
Overview The OWASP Application Security Verification Standard (ASVS) is a framework designed to provide a basis for testing web application security controls and establishing security requirements. It helps organizations systematically…
32
OWASP MASVS (Mobile)
Overview The OWASP Mobile Application Security Verification Standard (MASVS) is a framework designed to provide a baseline for mobile app security requirements. It helps organizations systematically identify and mitigate security…
33
OWASP SAMM
Overview OWASP Software Assurance Maturity Model (SAMM) is a framework designed to help organizations formulate and implement a comprehensive software security strategy. It addresses the challenge of integrating security practices…
34
OWASP Top 10
Overview The OWASP Top 10 is a widely recognized standard that identifies the most critical security risks to web applications. It helps organizations prioritize their security efforts by highlighting common…
35
PCI DSS
Overview The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements designed to protect cardholder data and reduce credit card fraud. It provides a comprehensive…
36
SABSA Security Architecture Framework
Overview The SABSA (Sherwood Applied Business Security Architecture) Security Architecture Framework is a comprehensive methodology for developing risk-driven enterprise security architectures. It helps organizations align security strategies with business objectives…
37
SAFECode Fundamental Practices
Overview SAFECode Fundamental Practices is a set of industry-recognized secure software development practices designed to help organizations reduce vulnerabilities and improve the security posture of their software products. It addresses…
38
Secure Controls Framework (SCF)
Overview The Secure Controls Framework (SCF) is a comprehensive cybersecurity and privacy control framework designed to help organizations manage risk and achieve compliance with multiple regulatory requirements. It consolidates and…
39
Security Policy Framework Development
Overview Security Policy Framework Development is a structured approach to creating, maintaining, and enforcing organizational security policies. It addresses the challenge of establishing consistent and comprehensive security governance by defining…
40
SLSA Supply Chain Levels for Software Artifacts
Overview SLSA (Supply Chain Levels for Software Artifacts) is a security framework designed to protect the integrity of software supply chains by defining progressive levels of assurance for software artifacts.…