260 lines
12 KiB
Markdown
260 lines
12 KiB
Markdown
# Security Frameworks & Standards
|
|
|
|
Comprehensive collection of security frameworks, compliance standards, and threat analysis models used across the cybersecurity industry.
|
|
|
|
## NIST Framework Suite
|
|
|
|
The National Institute of Standards and Technology (NIST) publishes comprehensive cybersecurity frameworks and guidelines.
|
|
|
|
### Core Frameworks
|
|
|
|
- [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework) - Framework for improving critical infrastructure cybersecurity
|
|
- [NIST Privacy Framework](https://www.nist.gov/privacy-framework) - Privacy risk management framework
|
|
- [NIST 800-37 Risk Management Framework](https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final) - RMF for information systems and organizations
|
|
|
|
### Security Controls
|
|
|
|
- [NIST 800-53 Security Controls](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final) - Security and privacy controls for information systems
|
|
- [NIST 800-171](https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final) - Protecting Controlled Unclassified Information (CUI)
|
|
|
|
### Risk Management
|
|
|
|
- [NIST 800-39 Managing Information Security Risk](https://csrc.nist.gov/publications/detail/sp/800-39/final) - Organization-level risk management
|
|
|
|
### Specialized Guidelines
|
|
|
|
- [NIST 800-61 Incident Handling Guide](https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final) - Computer security incident handling
|
|
- [NIST 800-63 Digital Identity Guidelines](https://pages.nist.gov/800-63-3/) - Digital identity framework
|
|
- [NIST 800-207 Zero Trust Architecture](https://csrc.nist.gov/publications/detail/sp/800-207/final) - Zero trust security model
|
|
- [NIST 800-218 Secure Software Development Framework](https://csrc.nist.gov/publications/detail/sp/800-218/final) - Secure SDLC practices
|
|
|
|
---
|
|
|
|
## ISO/IEC Standards
|
|
|
|
International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) security standards.
|
|
|
|
### Information Security Management
|
|
|
|
- [ISO/IEC 27001](https://www.iso.org/isoiec-27001-information-security.html) - Information security management systems (ISMS) requirements
|
|
- [ISO/IEC 27002](https://www.iso.org/standard/73906.html) - Code of practice for information security controls
|
|
|
|
### Specialized ISO Standards
|
|
|
|
- [ISO/IEC 27032](https://www.iso.org/standard/44375.html) - Guidelines for cybersecurity
|
|
- [ISO/IEC 27033](https://www.iso.org/standard/63411.html) - Network security management
|
|
- [ISO/IEC 27034](https://www.iso.org/standard/44379.html) - Application security guidelines
|
|
- [ISO 22301](https://www.iso.org/iso-22301-business-continuity.html) - Business continuity management systems
|
|
|
|
---
|
|
|
|
## Industry Security Frameworks
|
|
|
|
### Threat Intelligence & Attack Frameworks
|
|
|
|
**MITRE Corporation:**
|
|
- [MITRE ATT&CK Framework](https://attack.mitre.org/) - Adversary tactics, techniques, and common knowledge
|
|
- [MITRE Shield](https://shield.mitre.org/) - Active defense knowledge base
|
|
- [MITRE Engage](https://engage.mitre.org/) - Framework for adversary engagement operations
|
|
|
|
**Attack Models:**
|
|
- [Lockheed Martin Cyber Kill Chain](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html) - Framework for identifying and preventing cyber intrusions
|
|
- [Diamond Model of Intrusion Analysis](https://www.threatintel.academy/wp-content/uploads/2020/07/diamond-model.pdf) - Model for analyzing cyber intrusions
|
|
- [Unified Kill Chain](https://www.unifiedkillchain.com/assets/The-Unified-Kill-Chain.pdf) - Unified framework combining multiple kill chain models
|
|
|
|
### Application Security
|
|
|
|
- [OWASP Top 10](https://owasp.org/www-project-top-ten/) - Top 10 web application security risks
|
|
- [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/) - Application Security Verification Standard
|
|
- [OWASP SAMM](https://owaspsamm.org/) - Software Assurance Maturity Model
|
|
- [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) - Mobile application security risks
|
|
|
|
### Security Controls & Best Practices
|
|
|
|
- [CIS Controls](https://www.cisecurity.org/controls) - Critical security controls for effective cyber defense
|
|
- [CIS Benchmarks](https://www.cisecurity.org/cis-benchmarks/) - Configuration best practices for various technologies
|
|
|
|
### Cloud Security
|
|
|
|
- [Cloud Security Alliance CCSK](https://cloudsecurityalliance.org/education/ccsk/) - Certificate of Cloud Security Knowledge
|
|
- [CSA Cloud Controls Matrix](https://cloudsecurityalliance.org/research/cloud-controls-matrix/) - Security controls framework for cloud computing
|
|
- [AWS Well-Architected Framework](https://aws.amazon.com/architecture/well-architected/) - Security pillar for AWS
|
|
|
|
---
|
|
|
|
## Compliance & Regulatory Frameworks
|
|
|
|
### Financial Services
|
|
|
|
**Payment Card Industry:**
|
|
- [PCI-DSS](https://www.pcisecuritystandards.org/) - Payment Card Industry Data Security Standard
|
|
- Requirements for securing credit card transactions
|
|
- Applies to all entities that store, process, or transmit cardholder data
|
|
|
|
**Banking & Finance:**
|
|
- [SOX (Sarbanes-Oxley Act)](https://www.sarbanes-oxley-101.com/sarbanes-oxley-compliance.htm) - Financial reporting and IT controls
|
|
- [GLBA (Gramm-Leach-Bliley Act)](https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act) - Financial privacy requirements
|
|
|
|
### Healthcare
|
|
|
|
- [HIPAA Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/index.html) - Health Insurance Portability and Accountability Act
|
|
- Protects electronic protected health information (ePHI)
|
|
- Administrative, physical, and technical safeguards
|
|
- [HITECH Act](https://www.hhs.gov/hipaa/for-professionals/special-topics/hitech-act-enforcement-interim-final-rule/index.html) - Health Information Technology for Economic and Clinical Health
|
|
|
|
### Privacy Regulations
|
|
|
|
**International:**
|
|
- [GDPR (General Data Protection Regulation)](https://gdpr.eu/) - European Union data protection and privacy
|
|
- Applies to all organizations processing EU citizen data
|
|
- Data protection by design and default
|
|
|
|
**United States:**
|
|
- [CCPA (California Consumer Privacy Act)](https://oag.ca.gov/privacy/ccpa) - California privacy law
|
|
- [CPRA (California Privacy Rights Act)](https://cpra.ca.gov/) - Enhanced California privacy protections
|
|
|
|
**Canada:**
|
|
- [PIPEDA](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/) - Personal Information Protection and Electronic Documents Act
|
|
|
|
### Federal & Government
|
|
|
|
**United States Federal:**
|
|
- [FISMA (Federal Information Security Management Act)](https://www.cisa.gov/fisma) - Federal information security requirements
|
|
- [FedRAMP (Federal Risk and Authorization Management Program)](https://www.fedramp.gov/) - Cloud security assessment for federal agencies
|
|
- [NIST SP 800-53](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final) - Security controls for federal systems
|
|
|
|
**Defense:**
|
|
- [CMMC (Cybersecurity Maturity Model Certification)](https://www.acq.osd.mil/cmmc/) - DoD cybersecurity framework
|
|
- Required for defense contractors
|
|
- Tiered maturity model (Levels 1-3)
|
|
|
|
### Industry Standards
|
|
|
|
- [SOC 2 Type II](https://www.vanta.com/products/soc-2) - Service Organization Control 2
|
|
- Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy
|
|
- Common for SaaS and cloud service providers
|
|
|
|
---
|
|
|
|
## Incident Response Frameworks
|
|
|
|
### Response Methodologies
|
|
|
|
**NIST Incident Response:**
|
|
- Preparation
|
|
- Detection and Analysis
|
|
- Containment, Eradication, and Recovery
|
|
- Post-Incident Activity
|
|
|
|
**SANS Incident Response:**
|
|
- Preparation
|
|
- Identification
|
|
- Containment
|
|
- Eradication
|
|
- Recovery
|
|
- Lessons Learned
|
|
|
|
---
|
|
|
|
## Risk Management Frameworks
|
|
|
|
### Enterprise Risk
|
|
|
|
- [ISO 31000](https://www.iso.org/iso-31000-risk-management.html) - Risk management guidelines
|
|
- [COSO ERM Framework](https://www.coso.org/guidance-on-enterprise-risk-management) - Enterprise risk management
|
|
- [FAIR (Factor Analysis of Information Risk)](https://www.fairinstitute.org/) - Quantitative risk analysis
|
|
|
|
### IT Risk
|
|
|
|
- [OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation)](https://insights.sei.cmu.edu/library/octave-threat-based-risk-assessment/) - Risk-based strategic assessment
|
|
- [NIST RMF](https://csrc.nist.gov/projects/risk-management/about-rmf) - Risk Management Framework for information systems
|
|
|
|
---
|
|
|
|
## Security Architecture Frameworks
|
|
|
|
### Enterprise Architecture
|
|
|
|
- [SABSA (Sherwood Applied Business Security Architecture)](https://sabsa.org/) - Business-driven security architecture framework
|
|
- [TOGAF (The Open Group Architecture Framework)](https://www.opengroup.org/togaf) - Enterprise architecture methodology
|
|
- [Zachman Framework](https://www.zachman.com/about-the-zachman-framework) - Enterprise architecture framework
|
|
|
|
### Zero Trust
|
|
|
|
- [NIST Zero Trust Architecture (SP 800-207)](https://csrc.nist.gov/publications/detail/sp/800-207/final)
|
|
- [Microsoft Zero Trust Model](https://www.microsoft.com/en-us/security/business/zero-trust)
|
|
- [Google BeyondCorp](https://cloud.google.com/beyondcorp) - Zero trust security framework
|
|
|
|
---
|
|
|
|
## Industry-Specific Frameworks
|
|
|
|
### Critical Infrastructure
|
|
|
|
- [NERC CIP](https://www.nerc.com/pa/Stand/Pages/CIPstandards.aspx) - North American Electric Reliability Corporation Critical Infrastructure Protection
|
|
- [TSA Security Directives](https://www.tsa.gov/for-industry/security-directives) - Transportation security requirements
|
|
|
|
### Manufacturing & IoT
|
|
|
|
- [IEC 62443](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards) - Industrial automation and control systems security
|
|
- [NIST Cybersecurity for IoT](https://www.nist.gov/programs-projects/nist-cybersecurity-iot-program) - IoT security guidance
|
|
|
|
---
|
|
|
|
## Threat & Vulnerability Frameworks
|
|
|
|
### Vulnerability Databases
|
|
|
|
- [CVE (Common Vulnerabilities and Exposures)](https://cve.mitre.org/) - Vulnerability naming standard
|
|
- [NVD (National Vulnerability Database)](https://nvd.nist.gov/) - US government vulnerability database
|
|
- [CWE (Common Weakness Enumeration)](https://cwe.mitre.org/) - Software security weakness taxonomy
|
|
|
|
### Scoring Systems
|
|
|
|
- [CVSS (Common Vulnerability Scoring System)](https://www.first.org/cvss/) - Vulnerability severity scoring
|
|
- [EPSS (Exploit Prediction Scoring System)](https://www.first.org/epss/) - Likelihood of exploitation
|
|
|
|
---
|
|
|
|
## Data Breach & Incident Frameworks
|
|
|
|
### Incident Documentation
|
|
|
|
- [VERIS (Vocabulary for Event Recording and Incident Sharing)](http://veriscommunity.net/) - Framework for describing security incidents
|
|
- [STIX/TAXII](https://oasis-open.github.io/cti-documentation/) - Structured Threat Information Expression / Trusted Automated Exchange of Intelligence Information
|
|
|
|
---
|
|
|
|
## Maturity Models
|
|
|
|
### Security Maturity
|
|
|
|
- [OWASP SAMM](https://owaspsamm.org/) - Software Assurance Maturity Model
|
|
- [CMMC](https://www.acq.osd.mil/cmmc/) - Cybersecurity Maturity Model Certification
|
|
- [C2M2 (Cybersecurity Capability Maturity Model)](https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2) - Energy sector cybersecurity maturity
|
|
|
|
### Governance Maturity
|
|
|
|
- [COBIT](https://www.isaca.org/resources/cobit) - Control Objectives for Information and Related Technologies
|
|
- IT governance and management framework
|
|
- Published by ISACA
|
|
|
|
---
|
|
|
|
## Additional Resources
|
|
|
|
### Framework Implementation Guides
|
|
|
|
- [NIST Cybersecurity Framework Implementation Guide](https://www.nist.gov/cyberframework/getting-started)
|
|
- [CIS Controls Implementation Groups](https://www.cisecurity.org/controls/cis-controls-implementation-groups)
|
|
- [ISO 27001 Implementation Guide](https://www.iso.org/standard/73906.html)
|
|
|
|
### Framework Mapping
|
|
|
|
- [NIST-to-ISO Mapping](https://www.nist.gov/cyberframework/nist-cybersecurity-framework-and-iso-27001)
|
|
- [CIS Controls to NIST CSF Mapping](https://www.cisecurity.org/controls/cis-controls-navigator)
|
|
|
|
---
|
|
|
|
[Back to Resources](./README.md) | [Back to Main](../README.md)
|