Framework Categories
Cybersecurity frameworks organized by their primary focus area. Each category addresses specific aspects of cybersecurity management and implementation.
Risk Management
4 frameworks
Frameworks focused on identifying, assessing, and managing cybersecurity risks across organizations.
NIST Cybersecurity Framework
The NIST Cybersecurity Framework provides a policy framework of computer security guidance for how private sector organizations can assess and improve their ability to prevent, detect, and respond to cyber attacks.
NIST Artificial Intelligence Risk Management Framework
The NIST AI Risk Management Framework provides a comprehensive approach for organizations to design, develop, deploy, and use AI systems in a responsible and trustworthy manner.
ISO/IEC 27005:2022 Information Security Risk Management
ISO/IEC 27005 provides guidelines for information security risk management supporting ISO/IEC 27001.
Factor Analysis of Information Risk
FAIR is the only international standard quantitative model for information security and operational risk.
Technical Controls
2 frameworks
Implementation-focused frameworks with specific security controls and technical safeguards.
CIS Critical Security Controls
The CIS Critical Security Controls are a prioritized set of actions that collectively form a defense-in-depth set of best practices that mitigate the most common attacks against systems and networks.
NIST Zero Trust Architecture
NIST SP 800-207 defines zero trust architecture for preventing data breaches and limiting internal lateral movement.
Governance & Compliance
2 frameworks
Regulatory and governance frameworks ensuring organizational compliance and oversight.
ISO/IEC 27001 Information Security Management
ISO/IEC 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization.
NIST Privacy Framework
The NIST Privacy Framework enables organizations to take a comprehensive, risk-based approach to privacy.
Maturity Models
2 frameworks
Assessment frameworks for measuring and improving cybersecurity maturity and capabilities.
Cyber Threat Intelligence Capability Maturity Model
The CTI-CMM is a community-driven framework designed to provide CTI programs with a roadmap to improve stakeholder support. It helps organizations assess and enhance their cyber threat intelligence capabilities through structured maturity levels and capability areas.
Detection Engineering Maturity Matrix
The Detection Engineering Maturity Matrix helps security operations teams measure capabilities and maturity of their detection function. It provides a high-level roadmap for organizations looking to build or expand detection engineering teams through people, process, technology, and detection content dimensions.