A cybersecurity framework is a structured blueprint of standards and controls used to build and organize an effective security program. Frameworks like NIST CSF, ISO 27001, SOC 2, PCI DSS, and CMMC are selected based on industry, organization type, and regulatory requirements.
Creating standards and controls for your cyber security program can be a very intensive process, especially if you have to create everything from scratch. So usually what you do is you start out with a framework, a blueprint.
When you're putting together your cyber security program, you're putting together your policies, standards, procedures, guidelines, and controls. It's a lot of work, and there's potential that you could miss certain areas out of it. So what we like to do when we're creating all of this is use a cyber security framework. And there's many different cyber security frameworks. The main focus of a cyber security framework is it gives a lot of standards and controls. It can also give some guidance and some policies, and it can help you develop all of that, but a lot of it is around standards and controls.
You can think of it as a blueprint. If you're doing some sort of construction, you have a blueprint to base the construction off of, and that allows you to build whatever it is that you're building efficiently. Well, that's the same thing with the cyber security framework: it is a structure, a blueprint, different tools and things that you can do. So it doesn't specify all the specifics of how you're going to implement it, but what it does is it gives you this framework, this blueprint, on how you can implement things.
There are a lot of different frameworks to choose from, and you would choose the framework based off of what kind of industry you're in, the type of organization you're working with, where in the world you are at. You know, the UK has some standards and the United States has some different standards. So it kind of depends, and there are some national standards as well.
An example is if you were a small business in the United States, one of the options that might be a good choice for you is the NIST cyber security framework. So it's a little more simplistic. It's more set up for small businesses or small federal agencies, and so that's a good one as kind of a starting block.
I worked extensively with the NIST 800-53, which is more for federal agencies within the United States, or if you're working with some federal agencies then they also may require that NIST 800-53.
This one right here is one of the most popular in the world: ISO 27,000, 27,0001, 27,0002. They each define something a little different, but that is one of the more popular ones.
And then one of the ones that I've had to work with is the SOC 2. So if you're looking for some sort of compliance and proof that you are reaching certain levels, this SOC 2 has an auditor that comes in. They analyze your controls to make sure that they're appropriate for the size of business you are, and make sure that you're following those controls. So that's the SOC 2.
If you're dealing with credit cards, then that's the PCI. If you're dealing with other government agencies, or you're a federal contractor contracting with federal agencies, then you'll need to be CMMC certified. So depending on what your scenario is, you would choose different ones.
So just as an example, this is the cyber security framework by NIST. It's broken down into five parts: identify, protect, detect, respond, and recover. And then there's a bunch of controls that are related to this.
So if you download the control document for this, I can scroll through here. I'm going to scroll to the end where some of the controls are at so you can see it. This is a high overall look into the controls. And there's the identify controls, the protect controls, the detect, the respond. They're each given some sort of code here. So for identify it's ID, so you can see all of these are ID. It's further broken down into categories. So ID AM is asset management, so these controls all have to do with asset management. These right here all have to do with the business environment. This has to do with governance. This has to do with risk assessment.
So then let's jump down into the individual controls. So if I scroll down here, here's the identify, here's the ID asset management, and there is a physical devices on the system within the organizations are inventoried. So this would be a control you would implement, and you would say, okay, I'm going to have to take an inventory of all the physical devices and all the systems within the organization. So that is the subcategory right there.
So you would write this down, and now you would further define this and say, well, how often are we going to do that? Are we going to do it on a yearly basis? Are we going to do it on a quarterly basis? Are we going to do it on a monthly basis, which would be kind of crazy, but I suppose some organizations might do that. So this is then the control that you would implement to enforce security.
So that's what a framework looks like. And as you can see, the NIST cyber security framework here is actually a shorter one. So you can see how many controls are involved with this one, and it's actually one of the shorter ones that are out there. It's more of kind of a starting point, and if you need to go more in depth, or work with certain customers that require more, then you may need to take it to the next level.
Here's the site where it's talking about the ISO 27000 family. So there's a whole series of standards that are here, and one of the most popular, well-known set of standards here. So I could actually click on here and say, okay, let's take a look at the family here. And it'll list out here's the 27,000. It looks like it's dated 2018. And then this is 27,01.
So this would be a framework that you would use and you would implement into your cyber security program. And how you would implement it would be you would first of all choose which cyber security framework is best for you. Once you've chosen that, you would take a look at the standards and download the standards, and then start changing the standards. There's some fill-in-the-blanks parts where you would fill it in with your own details of what you are going to implement, and then possibly you would remove some, possibly you would add some, you would change it to meet your organization's needs. So that's a cyber security framework.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →