TechKnowSurge
CompTIA Security+ 5.1 ISC2 CISSP 1.3 NIST CSF GV NIST 800-53 PM-1 CompTIA SecurityX 1.3 NIST NICE K0879 NIST NICE K0735
VideoSecurityFree

Cybersecurity Frameworks

Cybersecurity frameworks provide a structured blueprint for building an organizational security program, offering predefined standards and controls that teams customize to fit their specific environment. Common frameworks range from the broad NIST Cybersecurity Framework to the highly detailed NIST 800-53, with options in between suited to different organizational sizes and compliance requirements.

Complete this video to capture a CTF flag worth 1 point.

About this video

A cybersecurity framework provides the structural foundation on which an organization's entire security program is built. Rather than creating policies, standards, and procedures from a blank slate, organizations select a framework that supplies a predefined set of controls and categories, then customize those controls with the specific details that reflect their own environment, risk tolerance, and operational requirements. A simple example is patch management: a framework may specify that systems must be patched on a recurring schedule, and the organization fills in whether that cadence is monthly, quarterly, or otherwise. This approach reduces the likelihood of missing critical security components and ensures the resulting program aligns with recognized industry standards. The landscape of available frameworks spans a wide range of complexity and scope. The NIST Cybersecurity Framework, often called the CSF, is among the more accessible options and is well suited to smaller organizations or those beginning to formalize their security posture. It organizes controls into six functional categories: Identify, Protect, Detect, Respond, Recover, and Govern. At the other end of the spectrum, NIST 800-53 is one of the most comprehensive frameworks available, containing nearly 1,200 control entries organized across 20 control families that include access control, awareness and training, incident response, and risk assessment. It also offers low, moderate, and high baselines, allowing organizations to apply a level of rigor proportionate to their risk environment. Other prominent frameworks include ISO 27001, CIS Controls, SOC 2, PCI DSS, COBIT, CMMC, and FedRAMP, each carrying its own focus areas and compliance implications. Selecting the right framework is a strategic decision driven by organizational size, industry sector, and any regulatory or contractual obligations in play. A small business with limited resources may find the NIST CSF sufficient, while a federal contractor may be required to comply with CMMC or align to NIST 800-53. Regardless of which framework is chosen, the underlying process is the same: the framework supplies the structure, and the organization supplies the operational specifics, producing a tailored security program that is both defensible to auditors and actionable for internal teams.

What you'll learn

What's covered

Cybersecurity Frameworks

Aligned to

CompTIA Security+
5.1 Summarize elements of effective security governance.
ISC2 CISSP
1.3 Evaluate and apply security governance principles
NIST CSF
GV GOVERN — The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
NIST 800-53
PM-1 Information Security Program Plan
CompTIA SecurityX
1.3 Explain the importance of risk management for an enterprise.
NIST NICE
K0879 Knowledge of industry cybersecurity models and frameworks
K0735 Knowledge of risk management models and frameworks

Key terms

Cybersecurity Framework
A structured blueprint of standards, controls, and guidance used as a baseline for developing an organization's security policies, procedures, and controls.
NIST Cybersecurity Framework
NIST CSF
A voluntary framework developed by NIST that provides organizations with a policy framework of computer security guidance for identifying, protecting, detecting, responding to, and recovering from cyberattacks. Originally created for critical infrastructure, CSF 2.0 expanded to address organizations of all sizes and sectors and added a Govern function.
NIST 800-53
A NIST Special Publication that provides a comprehensive catalog of security and privacy controls for federal information systems, organized into control families such as access control, audit, and incident response. It is widely adopted beyond the federal sector as a baseline for security programs.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Incident Response
IR
A structured process for identifying, containing, eradicating, and recovering from security incidents.

Topics

Cybersecurity Frameworks Nist Csf Nist 800 53 Security Program Management Compliance Cybersecurity

Transcript

When it comes to policy, standards, procedures and guidelines, there's a ton to create, and who's to say that we don't miss certain components of that? What we can do is start out with a framework. A framework helps set up how things are going to be organized and what we're going to create.

What a Cybersecurity Framework Is

A cyber security framework comes with a bunch of standards and controls already in place, and so what we can do is use a framework to help develop our cyber security program. I like to think of the cyber security framework as being a blueprint for your full cyber security program, kind of similar to how we set up policies. That's going to establish what our cyber security program looks like. Same thing with the cyber security framework: it sets up that blueprint and it gives you already something to work with.

What will happen is you'll actually choose which cyber security framework you want to have, which blueprint you want to start out with, and then you're going to start filling in the details. It will have things like, you will perform patching on a something reoccurrence, and so then you'd have to fill it in with, we're going to do it on a monthly reoccurrence, we're going to patch on a monthly basis. So it will allow you to kind of fill in the details and build it specifically for your organization.

Examples of Frameworks

Some examples of frameworks could include the NIST Cybersecurity Framework. Even though it has the term cyber security framework, it's NIST CSF, or Cybersecurity Framework; it's a specific framework. We also have ISO 27000, we have the CIS controls, SOC 2, PCI DSS, COBIT, CMMC. These are just some of the examples of frameworks that are out there.

Now, some of these frameworks are a little more basic in nature, while others are more comprehensive, and depending on what your needs are, maybe you choose the NIST Cybersecurity Framework, also known as CSF. Or maybe you need something a little more advanced, so maybe it's FedRAMP and you have to comply with FedRAMP, or CMMC. There are some like this 800-53 that has a low baseline, a moderate baseline and high baseline depending on what your needs are.

Walking Through NIST 800-53

Since NIST 800-53 is one of the more complex, more comprehensive programs, let's take a look at just the highlights of the NIST 800-53. If I scroll down, this is a Wikipedia and it's talking about 800-53. If I scroll down, it talks about the families, the control families. There's 18 control families. These are like categories here, so we've got access control, we got audit and accountability, we've got incident response, we've got program management, risk assessment. So there's different elements to this. Actually the newer one has 20 control families.

What I can do is actually do a search for NIST 800-53, and it will come up with this site right here, which is NIST. It's directly from NIST, so I can click and open this and I can download the control catalog spreadsheet.

So now I've got the document open. Here we have on the left hand side the controls family, so we see AC-1, and I look over here, AC is access control. So there's access control, and I've got to scroll down quite a bit before I get to the next one. I'm still in the AC's here, so I've got to go all the way to line, well here we are, AC 20 23 25 148. Then we switch to AT, and if I look at, is this awareness training, so now we're into the awareness training. So those are the control families, and then here is the actual controls, this middle section right here.

What I can do is I'm going to jump down to one that we can relate to here. This is IIA, so IIA is identification and authentication. So here's identification and authentication, and here's the control for it: implement multifactor authentication for — and then it gives us a selection, so we can choose it for the local, the network, the remote and access to, and is it the privileged accounts, the non-privileged accounts. So what are we going to set up for multifactor authentication? We're going to choose the one that's appropriate for the size of company that we have, and the device meets, and then has some sort of requirement there that you would fill in. So it's not giving you the answer, but you would fill it in with the appropriate answer there.

So what it's giving you is, this is what I would create. I copy and paste this into our policies, and then we would fill in the proper blanks for this to create it to meet the needs of our organization. So that is NIST 800-53.

The NIST Cybersecurity Framework

The NIST Cybersecurity Framework is actually much more simplistic, so that's one that you use on smaller companies. Let's go to NIST Cybersecurity Framework and hit enter here, and we're going to go to this first one, and the number of categories that it has — it doesn't call it families, the number of categories that it has. Let's view the quick start guide, and let's see, maybe this is what we want to download.

So here is the categories for it. It has identify, protect, detect, respond and recover, and then there's this govern, and the govern is kind of the overall scoping idea of this. So those are the different categories that they have. If we scroll down, this does not give us examples, so maybe I can find one with an example. Here I found the full document for the NIST Cybersecurity Framework. I'm going to scroll all the way down to our controls, so we see our controls here, and let's take a look at one. Let's look at maybe one of the identifies. I can click identify, and in this identify the control is that inventories of hardware managed by the organization are maintained. So we're managing some sort of inventory here, and we have software, services, systems that we inventory. So we do some sort of inventory with this identify.

Comparing the Two

We can see that this is much more simplistic. The NIST 800-53, I can bring that up, we've got almost 1,200 lines to it, and each one of those has, look, in this one we have what looks like two different controls in it, or sub controls, whatever you want to call it, and this one also three there. So it actually is a lot more in depth, versus this one is much more simplistic. We can see the confidentiality, integrity and availability of data at rest are protected. So very much more simplistic.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →