Please enable JavaScript.
Coggle requires JavaScript to display documents.
Information Security Framework - Coggle Diagram
Information Security Framework
Examples
ISO 27k
CIS Critical Security Controls
NIST CSF
NIST 800-53
PCI DSS
ISF Good Practices for US
COBIT
NCSC CAF
ENISA NCAF
Terms
Framework
A structured description of a topic of interest, inculding a detailed statement of the problems to be solved and the goals to be achieved.
Security Control
Countermeasures to avoid, detect, counteract or minimize security risks.
Type of controls
Levels
Managerial
Technical
Physical
Timing
Compensative
Corrective
Detective
Deterent
Preventive
Activity
Identify
Protect
Detect
Respond
Recover
Features
Report to
Leadership
Auditors
Essentials
Repeatable
Reusable
Content
Policies
Processes
Practices
Types
Programme Framework
Examples
ISO 27k
NIST CSF
Use to
Assess overal state of security
Build a comprehensive Security programme
Measure activity adn conduct industry comparisons
Simplify communication with business leaders
Control Frameworks
Examples
CIS Controls
ISO 27k
NIST 800-53
Use to
Identify baseline controls
Assess state of technical capabilities
Prioritise implementation of controls
Develop initial roadmap
Risk Framework
Examples
NIST 800-39, -37, -30
ISO 27005
Use to
Define key process steps for assessing and managing risks
Identify, measure and quantify risk
Prioritise security activities
Why
Reason to use
Regulatory compliance
Public safety
Protecting sensitive data
Reputation
Benefits
Compliance
Improved maturity
Common language
Measurement and benchmarking
Systemic and holistic approach
Top challenges
Lack of funding
Trained staff
Automation tools
Lack of integration between tools