# Security Frameworks & Standards Comprehensive collection of security frameworks, compliance standards, and threat analysis models used across the cybersecurity industry. ## NIST Framework Suite The National Institute of Standards and Technology (NIST) publishes comprehensive cybersecurity frameworks and guidelines. ### Core Frameworks - [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework) - Framework for improving critical infrastructure cybersecurity - [NIST Privacy Framework](https://www.nist.gov/privacy-framework) - Privacy risk management framework - [NIST 800-37 Risk Management Framework](https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final) - RMF for information systems and organizations ### Security Controls - [NIST 800-53 Security Controls](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final) - Security and privacy controls for information systems - [NIST 800-171](https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final) - Protecting Controlled Unclassified Information (CUI) ### Risk Management - [NIST 800-39 Managing Information Security Risk](https://csrc.nist.gov/publications/detail/sp/800-39/final) - Organization-level risk management ### Specialized Guidelines - [NIST 800-61 Incident Handling Guide](https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final) - Computer security incident handling - [NIST 800-63 Digital Identity Guidelines](https://pages.nist.gov/800-63-3/) - Digital identity framework - [NIST 800-207 Zero Trust Architecture](https://csrc.nist.gov/publications/detail/sp/800-207/final) - Zero trust security model - [NIST 800-218 Secure Software Development Framework](https://csrc.nist.gov/publications/detail/sp/800-218/final) - Secure SDLC practices --- ## ISO/IEC Standards International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) security standards. ### Information Security Management - [ISO/IEC 27001](https://www.iso.org/isoiec-27001-information-security.html) - Information security management systems (ISMS) requirements - [ISO/IEC 27002](https://www.iso.org/standard/73906.html) - Code of practice for information security controls ### Specialized ISO Standards - [ISO/IEC 27032](https://www.iso.org/standard/44375.html) - Guidelines for cybersecurity - [ISO/IEC 27033](https://www.iso.org/standard/63411.html) - Network security management - [ISO/IEC 27034](https://www.iso.org/standard/44379.html) - Application security guidelines - [ISO 22301](https://www.iso.org/iso-22301-business-continuity.html) - Business continuity management systems --- ## Industry Security Frameworks ### Threat Intelligence & Attack Frameworks **MITRE Corporation:** - [MITRE ATT&CK Framework](https://attack.mitre.org/) - Adversary tactics, techniques, and common knowledge - [MITRE Shield](https://shield.mitre.org/) - Active defense knowledge base - [MITRE Engage](https://engage.mitre.org/) - Framework for adversary engagement operations **Attack Models:** - [Lockheed Martin Cyber Kill Chain](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html) - Framework for identifying and preventing cyber intrusions - [Diamond Model of Intrusion Analysis](https://www.threatintel.academy/wp-content/uploads/2020/07/diamond-model.pdf) - Model for analyzing cyber intrusions - [Unified Kill Chain](https://www.unifiedkillchain.com/assets/The-Unified-Kill-Chain.pdf) - Unified framework combining multiple kill chain models ### Application Security - [OWASP Top 10](https://owasp.org/www-project-top-ten/) - Top 10 web application security risks - [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/) - Application Security Verification Standard - [OWASP SAMM](https://owaspsamm.org/) - Software Assurance Maturity Model - [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) - Mobile application security risks ### Security Controls & Best Practices - [CIS Controls](https://www.cisecurity.org/controls) - Critical security controls for effective cyber defense - [CIS Benchmarks](https://www.cisecurity.org/cis-benchmarks/) - Configuration best practices for various technologies ### Cloud Security - [Cloud Security Alliance CCSK](https://cloudsecurityalliance.org/education/ccsk/) - Certificate of Cloud Security Knowledge - [CSA Cloud Controls Matrix](https://cloudsecurityalliance.org/research/cloud-controls-matrix/) - Security controls framework for cloud computing - [AWS Well-Architected Framework](https://aws.amazon.com/architecture/well-architected/) - Security pillar for AWS --- ## Compliance & Regulatory Frameworks ### Financial Services **Payment Card Industry:** - [PCI-DSS](https://www.pcisecuritystandards.org/) - Payment Card Industry Data Security Standard - Requirements for securing credit card transactions - Applies to all entities that store, process, or transmit cardholder data **Banking & Finance:** - [SOX (Sarbanes-Oxley Act)](https://www.sarbanes-oxley-101.com/sarbanes-oxley-compliance.htm) - Financial reporting and IT controls - [GLBA (Gramm-Leach-Bliley Act)](https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act) - Financial privacy requirements ### Healthcare - [HIPAA Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/index.html) - Health Insurance Portability and Accountability Act - Protects electronic protected health information (ePHI) - Administrative, physical, and technical safeguards - [HITECH Act](https://www.hhs.gov/hipaa/for-professionals/special-topics/hitech-act-enforcement-interim-final-rule/index.html) - Health Information Technology for Economic and Clinical Health ### Privacy Regulations **International:** - [GDPR (General Data Protection Regulation)](https://gdpr.eu/) - European Union data protection and privacy - Applies to all organizations processing EU citizen data - Data protection by design and default **United States:** - [CCPA (California Consumer Privacy Act)](https://oag.ca.gov/privacy/ccpa) - California privacy law - [CPRA (California Privacy Rights Act)](https://cpra.ca.gov/) - Enhanced California privacy protections **Canada:** - [PIPEDA](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/) - Personal Information Protection and Electronic Documents Act ### Federal & Government **United States Federal:** - [FISMA (Federal Information Security Management Act)](https://www.cisa.gov/fisma) - Federal information security requirements - [FedRAMP (Federal Risk and Authorization Management Program)](https://www.fedramp.gov/) - Cloud security assessment for federal agencies - [NIST SP 800-53](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final) - Security controls for federal systems **Defense:** - [CMMC (Cybersecurity Maturity Model Certification)](https://www.acq.osd.mil/cmmc/) - DoD cybersecurity framework - Required for defense contractors - Tiered maturity model (Levels 1-3) ### Industry Standards - [SOC 2 Type II](https://www.vanta.com/products/soc-2) - Service Organization Control 2 - Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy - Common for SaaS and cloud service providers --- ## Incident Response Frameworks ### Response Methodologies **NIST Incident Response:** - Preparation - Detection and Analysis - Containment, Eradication, and Recovery - Post-Incident Activity **SANS Incident Response:** - Preparation - Identification - Containment - Eradication - Recovery - Lessons Learned --- ## Risk Management Frameworks ### Enterprise Risk - [ISO 31000](https://www.iso.org/iso-31000-risk-management.html) - Risk management guidelines - [COSO ERM Framework](https://www.coso.org/guidance-on-enterprise-risk-management) - Enterprise risk management - [FAIR (Factor Analysis of Information Risk)](https://www.fairinstitute.org/) - Quantitative risk analysis ### IT Risk - [OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation)](https://insights.sei.cmu.edu/library/octave-threat-based-risk-assessment/) - Risk-based strategic assessment - [NIST RMF](https://csrc.nist.gov/projects/risk-management/about-rmf) - Risk Management Framework for information systems --- ## Security Architecture Frameworks ### Enterprise Architecture - [SABSA (Sherwood Applied Business Security Architecture)](https://sabsa.org/) - Business-driven security architecture framework - [TOGAF (The Open Group Architecture Framework)](https://www.opengroup.org/togaf) - Enterprise architecture methodology - [Zachman Framework](https://www.zachman.com/about-the-zachman-framework) - Enterprise architecture framework ### Zero Trust - [NIST Zero Trust Architecture (SP 800-207)](https://csrc.nist.gov/publications/detail/sp/800-207/final) - [Microsoft Zero Trust Model](https://www.microsoft.com/en-us/security/business/zero-trust) - [Google BeyondCorp](https://cloud.google.com/beyondcorp) - Zero trust security framework --- ## Industry-Specific Frameworks ### Critical Infrastructure - [NERC CIP](https://www.nerc.com/pa/Stand/Pages/CIPstandards.aspx) - North American Electric Reliability Corporation Critical Infrastructure Protection - [TSA Security Directives](https://www.tsa.gov/for-industry/security-directives) - Transportation security requirements ### Manufacturing & IoT - [IEC 62443](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards) - Industrial automation and control systems security - [NIST Cybersecurity for IoT](https://www.nist.gov/programs-projects/nist-cybersecurity-iot-program) - IoT security guidance --- ## Threat & Vulnerability Frameworks ### Vulnerability Databases - [CVE (Common Vulnerabilities and Exposures)](https://cve.mitre.org/) - Vulnerability naming standard - [NVD (National Vulnerability Database)](https://nvd.nist.gov/) - US government vulnerability database - [CWE (Common Weakness Enumeration)](https://cwe.mitre.org/) - Software security weakness taxonomy ### Scoring Systems - [CVSS (Common Vulnerability Scoring System)](https://www.first.org/cvss/) - Vulnerability severity scoring - [EPSS (Exploit Prediction Scoring System)](https://www.first.org/epss/) - Likelihood of exploitation --- ## Data Breach & Incident Frameworks ### Incident Documentation - [VERIS (Vocabulary for Event Recording and Incident Sharing)](http://veriscommunity.net/) - Framework for describing security incidents - [STIX/TAXII](https://oasis-open.github.io/cti-documentation/) - Structured Threat Information Expression / Trusted Automated Exchange of Intelligence Information --- ## Maturity Models ### Security Maturity - [OWASP SAMM](https://owaspsamm.org/) - Software Assurance Maturity Model - [CMMC](https://www.acq.osd.mil/cmmc/) - Cybersecurity Maturity Model Certification - [C2M2 (Cybersecurity Capability Maturity Model)](https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2) - Energy sector cybersecurity maturity ### Governance Maturity - [COBIT](https://www.isaca.org/resources/cobit) - Control Objectives for Information and Related Technologies - IT governance and management framework - Published by ISACA --- ## Additional Resources ### Framework Implementation Guides - [NIST Cybersecurity Framework Implementation Guide](https://www.nist.gov/cyberframework/getting-started) - [CIS Controls Implementation Groups](https://www.cisecurity.org/controls/cis-controls-implementation-groups) - [ISO 27001 Implementation Guide](https://www.iso.org/standard/73906.html) ### Framework Mapping - [NIST-to-ISO Mapping](https://www.nist.gov/cyberframework/nist-cybersecurity-framework-and-iso-27001) - [CIS Controls to NIST CSF Mapping](https://www.cisecurity.org/controls/cis-controls-navigator) --- [Back to Resources](./README.md) | [Back to Main](../README.md)