Security Frameworks (NIST, CIS, CSF)
About this topic
Security frameworks (NIST, CIS, CSF) refer to industry-standard models and best practices for establishing, managing, and improving cybersecurity programs. They provide structured guidance to strengthen security posture and ensure compliance.
Community Posts
Our organization is embarking on ISO certification for security and privacy in the cloud. We are looking for best practices to implement ISO whilst being mindful of the rigor needed to manage with multiple standards. From our initial review we were informed of BSI's PAS 99 and wanted to understand: 1. Pros and Cons 2. Adoption i.e. has it been widely adopted across business landscape, specifically in the insurance sector embarking on ISO certifications? 3. Are there alternatives or best practice recommendations when embarking on cloud ISO security and privacy certifications? Also, we understood that the current certification I.e. ISO/IEC 27017:2015 looks to be replaced by ISO/IEC DIS 27017 - Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services. Do you recommend waiting for the revision in its current stage or progress with the incumbent certification and have a subsequent review once the new version is published?
Limited resources10%
Siloed data38%
Lack of leadership25%
Poor data quality & context19%
Lack of data control5%
Other (please explain in the comments)
Drata7%
Vanta22%
Secureframe15%
KnowBe412%
Ostendio8%
AuditBoard8%
Something else -- I'll tell you in the comments6%
We’re not using a GRC platform20%
What are your thoughts on CMMC 2.0?
What are some critical NIST controls to focus on when building a cyber program for a new software startup?
Very positive – Offers more flexibility & personalization19%
Somewhat positive – Could enhance security if used correctly48%
Neutral – I doubt it will significantly impact security25%
Somewhat negative – May lead to predictable patterns7%
Very negative – Complicates password creation without much benefit