Cybersecurity Framework
6 slides · 4 min read · Domain 1
Text on this slide
Cybersecurity Frameworks
(099 P4 C771
- R372
Just like in the case of privacy frameworks, there are various frameworks in the cybersecurity world that can help guide an organization on how cybersecurity is governed.
A security framework is a notional construct outlining the organization's approach to cybersecurity, including a list of specific security processes, policies, procedures, and solutions that the organization can choose from.
The framework is often used by the organization to describe its security efforts, for both internal management purposes and to demonstrate the security posture of the organization to external entities such as regulators and auditors. There are a variety of cybersecurity frameworks currently popular in the industry, each offering benefits and capabilities, usually designed for a certain industry, type of organization, or approach to security.
The following list of framework examples is by no means exhaustive or intended to be exclusive.
Cloud Security Alliance (CSA)
Cloud Security Alliance (CSA) is a volunteer organization with participant members from both public and private sectors, concentrating - as the name suggests - on security aspects of cloud computing. The CSA publishes standards and tools for industry and practitioners, at no charge. The CSA also hosts the Security, Trust, and Assurance Registry (STAR), which is a voluntary list of all cloud service providers who comply with the STAR program framework and agree to publish documentation on the STAR website attesting to compliance. Customers and potential customers can review and consider cloud vendors at no cost by accessing the STAR website.
The STAR framework is a composite of various standards, regulations, and statutory requirements from around the world, covering a variety of subjects related to IT and data security; entities that choose to subscribe to the STAR program are required to complete and publish a questionnaire (the Consensus Assessments Initiative Questionnaire (CAIQ), colloquially pronounced "cake") published by CSA. The STAR program has three tiers, 1-3, in ascending order of complexity. Tier 1 only requires the vendor self-assessment, using the CAIQ. Tier 2 is an assessment of the organization by an external auditor certified by CSA to perform CAIQ audits. Tier 3 is in draft form as of the time of publication of this Common Body of Knowledge (CBK); it will require continuous monitoring of the target organization by independent, certified entities.
Risk Management Framework (RMF)
The U.S. National Institute of Standards and Technology (NIST) publishes two methods that work in concert (similar to how ISO 27001 and 27002 function); the RMF and the applicable list of security and privacy controls that goes along with it (respectively, these documents are Special Publications (SPs) 800-37 and 800-53). While the NIST SP series is only required to be followed by federal agencies in the United States, it can easily be applied to any kind of organization as the methods and concepts are universal. Also, like all American government documents, it is in the public domain; private organizations | do not have to pay to adopt and use this framework. However, there is no private certification for the NIST framework.
Hitrust Common Security And Privacy Framework (CSF)
HITRUST is an American company, that in collaboration with healthcare, technology and information security organizations, established the HITRUST CSF (supported by both non-profit and for-profit entities). HITRUST is working to have one framework, one certification, and one assessment as a globally recognized standard for exchanging attestations of trust between organizations public or private. HITRUST CSF normalizes the many different sets of security and privacy requirements, definitions, and controls, starting from the ISO/IEC 27000 family, U.S. government requirements, standards and guidelines such as NIST, HIPAA, and others, along with industry frameworks from COBIT and ITIL.
The International Standards Organization (ISO) 27000 series is recognized globally, and it is probably the most pervasive and used source of security standards outside the United States (American organizations often use standards from other sources).
International Standards Organization (ISO) 27001
ISO 27001 is known as the information security management system (ISMS) and is a comprehensive, holistic view of security governance within an organization, mostly focused on policy.
The security professional should have working familiarity with frameworks on this list, as well as whatever framework is used by their organization (if any).
