The Standards That Define Trust
Security frameworks are a shared language for doing the right things and proving it. Here is a plain-language map of the global standards that matter — what each one is, who it is for, and why it exists.
NIST CSF 2.0 — The Six Functions
The most widely adopted framework for organizing a security program. Every other standard maps back to these outcomes.
Govern
Establish and monitor the cybersecurity risk-management strategy, expectations, and policy. (New in CSF 2.0.)
Identify
Understand assets, suppliers, and the risks to them — you cannot protect what you have not inventoried.
Protect
Put safeguards in place: access control, data security, awareness training, and maintenance.
Detect
Find anomalies and adverse events quickly through continuous monitoring.
Respond
Take action on a detected incident — contain, analyze, communicate, and mitigate.
Recover
Restore assets and operations, and capture lessons learned to improve resilience.
Frameworks, Standards & Regulations
The difference matters: frameworks guide, standards certify, and regulations are the law.
NIST CSF 2.0
NIST Cybersecurity Framework
A voluntary, outcome-based framework organizing security into six functions: Govern, Identify, Protect, Detect, Respond, Recover.
Any organization wanting a common language to describe and improve its security posture.
The de facto starting point for building a risk-based program that maps cleanly onto other standards.
ISO 27001
ISO/IEC 27001:2022
An internationally certifiable standard for an Information Security Management System (ISMS) — the processes for managing security risk.
Organizations needing a globally recognized certification, often for enterprise or international customers.
Certification is independent, audited proof that security is systematically managed, not ad hoc.
SOC 2
SOC 2 (Trust Services Criteria)
An attestation report on controls relevant to security, availability, processing integrity, confidentiality, and privacy.
SaaS and service providers that handle customer data and need to prove it to buyers.
A SOC 2 report is frequently a hard requirement to close B2B and enterprise deals.
PCI DSS 4.0
Payment Card Industry Data Security Standard
A mandatory standard of technical and operational requirements for anyone that stores, processes, or transmits cardholder data.
Merchants, processors, and any business touching payment card data.
Non-compliance can mean fines and loss of the ability to process card payments.
GDPR
General Data Protection Regulation
A law governing how personal data of individuals in the EU/EEA is collected, processed, and protected.
Any organization worldwide that handles the personal data of EU/EEA residents.
Penalties can reach the greater of €20M or 4% of global annual revenue.
HIPAA
Health Insurance Portability and Accountability Act
US law setting national standards to protect sensitive patient health information (PHI), including a Security Rule for electronic PHI.
Healthcare providers, plans, clearinghouses, and their business associates.
Protects patient privacy and carries significant civil and criminal penalties for breaches.
CIS Controls v8
CIS Critical Security Controls
A prioritized set of 18 safeguards that defend against the most common and impactful attacks.
Teams wanting a concrete, action-first checklist to improve defenses fast.
Highly practical and prioritized — an excellent bridge from strategy to hands-on hardening.
OWASP
Open Worldwide Application Security Project
Community standards for application security, including the OWASP Top 10, ASVS, and the Top 10 for LLM Applications.
Developers and security teams building and testing web, API, and AI applications.
The industry reference for what application weaknesses to prevent, test for, and verify.
MITRE ATT&CK
MITRE ATT&CK & D3FEND
A curated knowledge base of real-world adversary tactics and techniques (ATT&CK) and the defensive countermeasures that address them (D3FEND).
Detection engineers, threat hunters, and red/blue teams.
A shared vocabulary for describing attacks and measuring detection coverage.
NIST AI RMF
NIST AI Risk Management Framework
Guidance for managing risks unique to AI systems across the Govern, Map, Measure, and Manage functions.
Organizations building, deploying, or relying on AI and LLM-powered systems.
The emerging reference for trustworthy, secure, and accountable AI.
Which One Do I Need?
A starting point, not legal advice — most mature programs adopt several in layers.