TechKnowSurge
NIST CSF GV.PO-01 ISC2 CC 1.3 Cisco CCST Cybersecurity 4.3 NIST 800-53 PM-1 ISC2 CC 2.1 Cisco CCST Cybersecurity 5.3 NIST NICE K0879 NIST CSF GV.RM-01
VideoSecurityFree

Administrative Controls - What is a Security Frameworks

A cybersecurity framework is a structured blueprint of standards and controls used to build and organize an effective security program. Frameworks like NIST CSF, ISO 27001, SOC 2, PCI DSS, and CMMC are selected based on industry, organization type, and regulatory requirements.

Complete this video to capture a CTF flag worth 1 point.

About this video

Developing a cybersecurity program requires assembling policies, standards, procedures, guidelines, and controls across every area of an organization's security posture. That scope makes it easy to overlook critical areas, which is why cybersecurity frameworks exist. A framework functions as a blueprint—a structured set of pre-defined standards and controls that provides a starting point rather than a finished product. It defines what needs to be addressed without prescribing exactly how each control must be implemented, leaving room for organizations to tailor the framework to their own environment and risk tolerance. The choice of framework depends on factors such as industry, organization size, geographic location, and regulatory obligations. The NIST Cybersecurity Framework is a widely used starting point, particularly suited to small businesses and federal agencies in the United States, and is organized around five core functions: Identify, Protect, Detect, Respond, and Recover. NIST 800-53 goes deeper and is typically required for federal agencies and contractors. ISO 27001, part of the broader ISO 27000 family, is one of the most recognized frameworks internationally. SOC 2 involves third-party auditing to verify that controls are appropriate and being followed, while PCI DSS applies to organizations handling payment card data, and CMMC is required for contractors working with U.S. federal agencies. Once an appropriate framework is selected, implementation begins by reviewing and downloading the official standards documentation. Organizations then adapt the framework to their context—completing any fill-in-the-blank sections with organization-specific details, removing controls that do not apply, and adding controls needed to address gaps the framework does not cover. Even a relatively concise framework like the NIST CSF contains a substantial number of controls, and more comprehensive frameworks go considerably deeper. The process ultimately produces a customized, defensible security program grounded in recognized industry standards.

What you'll learn

Aligned to

NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders.
ISC2 CC
1.3 Understand governance concepts
2.1 Plan Governance, Risk, and Compliance (GRC)
Cisco CCST Cybersecurity
4.3 Explain risk management
5.3 Explain the impact of compliance frameworks on incident handling
NIST 800-53
PM-1 Information Security Program Plan
NIST NICE
K0879 Knowledge of industry cybersecurity models and frameworks

Key terms

Cybersecurity Framework
A structured blueprint of standards, controls, and guidance used as a baseline for developing an organization's security policies, procedures, and controls.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
NIST Cybersecurity Framework
NIST CSF
A voluntary framework developed by NIST that provides organizations with a policy framework of computer security guidance for identifying, protecting, detecting, responding to, and recovering from cyberattacks. Originally created for critical infrastructure, CSF 2.0 expanded to address organizations of all sizes and sectors and added a Govern function.
NIST 800-53
A NIST Special Publication that provides a comprehensive catalog of security and privacy controls for federal information systems, organized into control families such as access control, audit, and incident response. It is widely adopted beyond the federal sector as a baseline for security programs.
ISO 27001
An internationally recognized standard within the ISO 27000 family that specifies requirements for establishing, implementing, and managing an information security management system.
System and Organization Controls 2
SOC 2
An auditing standard developed by the American Institute of Certified Public Accountants (AICPA) that evaluates the security, availability, processing integrity, confidentiality, and privacy controls of service organizations. SOC 2 reports are widely used by cloud service providers to demonstrate the effectiveness of their security controls to customers.
Payment Card Industry Data Security Standard
PCI DSS
A set of security requirements mandated by major credit card brands that organizations must follow to process, store, or transmit cardholder data. PCI DSS covers controls such as encryption, access restriction, and regular security testing.
Cybersecurity Maturity Model Certification
CMMC
A U.S. Department of Defense program that establishes cybersecurity standards and a certification process for defense contractors to ensure they adequately protect sensitive unclassified information. It uses a tiered model requiring third-party assessments to verify compliance before award of DoD contracts.

Topics

Cybersecurity Frameworks Nist Csf Iso 27001 Pci Dss Cmmc Administrative Controls Governance Risk Compliance

Transcript

What a Cyber Security Framework Is

Creating standards and controls for your cyber security program can be a very intensive process, especially if you have to create everything from scratch. So usually what you do is you start out with a framework, a blueprint.

When you're putting together your cyber security program, you're putting together your policies, standards, procedures, guidelines, and controls. It's a lot of work, and there's potential that you could miss certain areas out of it. So what we like to do when we're creating all of this is use a cyber security framework. And there's many different cyber security frameworks. The main focus of a cyber security framework is it gives a lot of standards and controls. It can also give some guidance and some policies, and it can help you develop all of that, but a lot of it is around standards and controls.

You can think of it as a blueprint. If you're doing some sort of construction, you have a blueprint to base the construction off of, and that allows you to build whatever it is that you're building efficiently. Well, that's the same thing with the cyber security framework: it is a structure, a blueprint, different tools and things that you can do. So it doesn't specify all the specifics of how you're going to implement it, but what it does is it gives you this framework, this blueprint, on how you can implement things.

Choosing a Framework

There are a lot of different frameworks to choose from, and you would choose the framework based off of what kind of industry you're in, the type of organization you're working with, where in the world you are at. You know, the UK has some standards and the United States has some different standards. So it kind of depends, and there are some national standards as well.

An example is if you were a small business in the United States, one of the options that might be a good choice for you is the NIST cyber security framework. So it's a little more simplistic. It's more set up for small businesses or small federal agencies, and so that's a good one as kind of a starting block.

I worked extensively with the NIST 800-53, which is more for federal agencies within the United States, or if you're working with some federal agencies then they also may require that NIST 800-53.

This one right here is one of the most popular in the world: ISO 27,000, 27,0001, 27,0002. They each define something a little different, but that is one of the more popular ones.

And then one of the ones that I've had to work with is the SOC 2. So if you're looking for some sort of compliance and proof that you are reaching certain levels, this SOC 2 has an auditor that comes in. They analyze your controls to make sure that they're appropriate for the size of business you are, and make sure that you're following those controls. So that's the SOC 2.

If you're dealing with credit cards, then that's the PCI. If you're dealing with other government agencies, or you're a federal contractor contracting with federal agencies, then you'll need to be CMMC certified. So depending on what your scenario is, you would choose different ones.

Inside the NIST Cyber Security Framework

So just as an example, this is the cyber security framework by NIST. It's broken down into five parts: identify, protect, detect, respond, and recover. And then there's a bunch of controls that are related to this.

So if you download the control document for this, I can scroll through here. I'm going to scroll to the end where some of the controls are at so you can see it. This is a high overall look into the controls. And there's the identify controls, the protect controls, the detect, the respond. They're each given some sort of code here. So for identify it's ID, so you can see all of these are ID. It's further broken down into categories. So ID AM is asset management, so these controls all have to do with asset management. These right here all have to do with the business environment. This has to do with governance. This has to do with risk assessment.

So then let's jump down into the individual controls. So if I scroll down here, here's the identify, here's the ID asset management, and there is a physical devices on the system within the organizations are inventoried. So this would be a control you would implement, and you would say, okay, I'm going to have to take an inventory of all the physical devices and all the systems within the organization. So that is the subcategory right there.

So you would write this down, and now you would further define this and say, well, how often are we going to do that? Are we going to do it on a yearly basis? Are we going to do it on a quarterly basis? Are we going to do it on a monthly basis, which would be kind of crazy, but I suppose some organizations might do that. So this is then the control that you would implement to enforce security.

So that's what a framework looks like. And as you can see, the NIST cyber security framework here is actually a shorter one. So you can see how many controls are involved with this one, and it's actually one of the shorter ones that are out there. It's more of kind of a starting point, and if you need to go more in depth, or work with certain customers that require more, then you may need to take it to the next level.

The ISO 27000 Family

Here's the site where it's talking about the ISO 27000 family. So there's a whole series of standards that are here, and one of the most popular, well-known set of standards here. So I could actually click on here and say, okay, let's take a look at the family here. And it'll list out here's the 27,000. It looks like it's dated 2018. And then this is 27,01.

So this would be a framework that you would use and you would implement into your cyber security program. And how you would implement it would be you would first of all choose which cyber security framework is best for you. Once you've chosen that, you would take a look at the standards and download the standards, and then start changing the standards. There's some fill-in-the-blanks parts where you would fill it in with your own details of what you are going to implement, and then possibly you would remove some, possibly you would add some, you would change it to meet your organization's needs. So that's a cyber security framework.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →