Cybersecurity frameworks provide a structured blueprint for building an organizational security program, offering predefined standards and controls that teams customize to fit their specific environment. Common frameworks range from the broad NIST Cybersecurity Framework to the highly detailed NIST 800-53, with options in between suited to different organizational sizes and compliance requirements.
Cybersecurity Frameworks
When it comes to policy, standards, procedures and guidelines, there's a ton to create, and who's to say that we don't miss certain components of that? What we can do is start out with a framework. A framework helps set up how things are going to be organized and what we're going to create.
A cyber security framework comes with a bunch of standards and controls already in place, and so what we can do is use a framework to help develop our cyber security program. I like to think of the cyber security framework as being a blueprint for your full cyber security program, kind of similar to how we set up policies. That's going to establish what our cyber security program looks like. Same thing with the cyber security framework: it sets up that blueprint and it gives you already something to work with.
What will happen is you'll actually choose which cyber security framework you want to have, which blueprint you want to start out with, and then you're going to start filling in the details. It will have things like, you will perform patching on a something reoccurrence, and so then you'd have to fill it in with, we're going to do it on a monthly reoccurrence, we're going to patch on a monthly basis. So it will allow you to kind of fill in the details and build it specifically for your organization.
Some examples of frameworks could include the NIST Cybersecurity Framework. Even though it has the term cyber security framework, it's NIST CSF, or Cybersecurity Framework; it's a specific framework. We also have ISO 27000, we have the CIS controls, SOC 2, PCI DSS, COBIT, CMMC. These are just some of the examples of frameworks that are out there.
Now, some of these frameworks are a little more basic in nature, while others are more comprehensive, and depending on what your needs are, maybe you choose the NIST Cybersecurity Framework, also known as CSF. Or maybe you need something a little more advanced, so maybe it's FedRAMP and you have to comply with FedRAMP, or CMMC. There are some like this 800-53 that has a low baseline, a moderate baseline and high baseline depending on what your needs are.
Since NIST 800-53 is one of the more complex, more comprehensive programs, let's take a look at just the highlights of the NIST 800-53. If I scroll down, this is a Wikipedia and it's talking about 800-53. If I scroll down, it talks about the families, the control families. There's 18 control families. These are like categories here, so we've got access control, we got audit and accountability, we've got incident response, we've got program management, risk assessment. So there's different elements to this. Actually the newer one has 20 control families.
What I can do is actually do a search for NIST 800-53, and it will come up with this site right here, which is NIST. It's directly from NIST, so I can click and open this and I can download the control catalog spreadsheet.
So now I've got the document open. Here we have on the left hand side the controls family, so we see AC-1, and I look over here, AC is access control. So there's access control, and I've got to scroll down quite a bit before I get to the next one. I'm still in the AC's here, so I've got to go all the way to line, well here we are, AC 20 23 25 148. Then we switch to AT, and if I look at, is this awareness training, so now we're into the awareness training. So those are the control families, and then here is the actual controls, this middle section right here.
What I can do is I'm going to jump down to one that we can relate to here. This is IIA, so IIA is identification and authentication. So here's identification and authentication, and here's the control for it: implement multifactor authentication for — and then it gives us a selection, so we can choose it for the local, the network, the remote and access to, and is it the privileged accounts, the non-privileged accounts. So what are we going to set up for multifactor authentication? We're going to choose the one that's appropriate for the size of company that we have, and the device meets, and then has some sort of requirement there that you would fill in. So it's not giving you the answer, but you would fill it in with the appropriate answer there.
So what it's giving you is, this is what I would create. I copy and paste this into our policies, and then we would fill in the proper blanks for this to create it to meet the needs of our organization. So that is NIST 800-53.
The NIST Cybersecurity Framework is actually much more simplistic, so that's one that you use on smaller companies. Let's go to NIST Cybersecurity Framework and hit enter here, and we're going to go to this first one, and the number of categories that it has — it doesn't call it families, the number of categories that it has. Let's view the quick start guide, and let's see, maybe this is what we want to download.
So here is the categories for it. It has identify, protect, detect, respond and recover, and then there's this govern, and the govern is kind of the overall scoping idea of this. So those are the different categories that they have. If we scroll down, this does not give us examples, so maybe I can find one with an example. Here I found the full document for the NIST Cybersecurity Framework. I'm going to scroll all the way down to our controls, so we see our controls here, and let's take a look at one. Let's look at maybe one of the identifies. I can click identify, and in this identify the control is that inventories of hardware managed by the organization are maintained. So we're managing some sort of inventory here, and we have software, services, systems that we inventory. So we do some sort of inventory with this identify.
We can see that this is much more simplistic. The NIST 800-53, I can bring that up, we've got almost 1,200 lines to it, and each one of those has, look, in this one we have what looks like two different controls in it, or sub controls, whatever you want to call it, and this one also three there. So it actually is a lot more in depth, versus this one is much more simplistic. We can see the confidentiality, integrity and availability of data at rest are protected. So very much more simplistic.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →