Security framework
Also known as: cybersecurity framework, control framework
A ready-made, shared structure of goals and controls that an organisation follows to build and check its security work.
Draft - this entry has not been reviewed yet.
Formal
A published, structured set of principles, processes and controls - such as ISO 27001, the NIST CSF or the CIS Controls - that an organisation adopts to decide what to protect, in which order, and how to measure progress.
In plain English
A well-tested cookbook - you do not invent the dish from scratch, you follow proven steps and adjust to taste.
In practice
The newly hired IT manager at a Danish housing association uses the CIS Controls as a checklist to see which basic protections are already in place and which to add first.
Why it matters
Without one, each organisation guesses at what good security looks like and misses whole areas; a shared framework also gives a common language with auditors, partners and authorities.
Technical deep dive
"Framework" covers documents of quite different kinds, and much confusion comes from comparing them as if they were alike. Programme or management-system frameworks describe how security is governed: ISO/IEC 27001 specifies requirements for an ISMS, and the NIST CSF 2.0 organises desired outcomes into six functions. Control catalogues specify what to implement: ISO/IEC 27002 with 93 controls, NIST SP 800-53 Rev. 5 with controls in 20 families, and the CIS Controls v8.1 with 18 controls and 153 safeguards sorted into three Implementation Groups, of which IG1 (56 safeguards) is presented as essential cyber hygiene. Risk frameworks describe how to assess and treat risk: ISO/IEC 27005, NIST SP 800-30 and the Risk Management Framework in SP 800-37, or FAIR for quantitative estimates. Governance frameworks such as COBIT 2019 position security inside enterprise IT governance.
A further distinction runs between voluntary frameworks and binding law. NIS2, DORA and the GDPR set legal outcomes and deadlines but rarely say how to achieve them; frameworks supply the how, and a certificate or assessment against a framework is evidence, not proof, of legal compliance. Threat-centred knowledge bases such as MITRE ATT&CK are not control frameworks either, although they are often used to check whether the chosen controls cover realistic attack techniques.
Organisations subject to several regimes usually end up with a crosswalk or common control framework: one internal set of controls, each mapped to the requirements it satisfies in 27001 Annex A, NIS2 Article 21(2), customer contracts and sector rules, so that one piece of evidence serves several audits. Public mappings help, for example NIST's OLIR programme and the CIS mappings to other frameworks, but mappings are many-to-many and approximate, and a control that "maps" to a requirement may cover only part of it.
Selection should follow the question being answered. For a certificate that customers recognise, ISO 27001 is the default in Europe; for board-level communication and gap analysis the CSF functions are popular; for a small organisation needing a prioritised technical to-do list, CIS IG1 is a realistic start; in Denmark, D-mærket offers a lighter label aimed at smaller companies. The common failure is framework collecting: adopting several in parallel without a common control set, which multiplies documentation without improving security.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Security control
- →Security framework
Relationships
- Part of
- Governance
- Requires
- Security control
- Don't confuse with
- Security policy
Sources & further reading
Standards & official texts
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 1 og 4
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…