Compliance & regulation
A ready-made, shared structure of goals and controls that an organisation follows to build and check its security work.
Formal
A published, structured set of principles, processes and controls - such as ISO 27001, the NIST CSF or the CIS Controls - that an organisation adopts to decide what to protect, in which order, and how to measure progress.
In plain English
A well-tested cookbook - you do not invent the dish from scratch, you follow proven steps and adjust to taste.
In practice
The newly hired IT manager at a Danish housing association uses the CIS Controls as a checklist to see which basic protections are already in place and which to add first.
Why it matters
Without one, each organisation guesses at what good security looks like and misses whole areas; a shared framework also gives a common language with auditors, partners and authorities.