Cybersecurity-Projects/RESOURCES/FRAMEWORKS.md

260 lines
12 KiB
Markdown

# Security Frameworks & Standards
Comprehensive collection of security frameworks, compliance standards, and threat analysis models used across the cybersecurity industry.
## NIST Framework Suite
The National Institute of Standards and Technology (NIST) publishes comprehensive cybersecurity frameworks and guidelines.
### Core Frameworks
- [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework) - Framework for improving critical infrastructure cybersecurity
- [NIST Privacy Framework](https://www.nist.gov/privacy-framework) - Privacy risk management framework
- [NIST 800-37 Risk Management Framework](https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final) - RMF for information systems and organizations
### Security Controls
- [NIST 800-53 Security Controls](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final) - Security and privacy controls for information systems
- [NIST 800-171](https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final) - Protecting Controlled Unclassified Information (CUI)
### Risk Management
- [NIST 800-39 Managing Information Security Risk](https://csrc.nist.gov/publications/detail/sp/800-39/final) - Organization-level risk management
### Specialized Guidelines
- [NIST 800-61 Incident Handling Guide](https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final) - Computer security incident handling
- [NIST 800-63 Digital Identity Guidelines](https://pages.nist.gov/800-63-3/) - Digital identity framework
- [NIST 800-207 Zero Trust Architecture](https://csrc.nist.gov/publications/detail/sp/800-207/final) - Zero trust security model
- [NIST 800-218 Secure Software Development Framework](https://csrc.nist.gov/publications/detail/sp/800-218/final) - Secure SDLC practices
---
## ISO/IEC Standards
International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) security standards.
### Information Security Management
- [ISO/IEC 27001](https://www.iso.org/isoiec-27001-information-security.html) - Information security management systems (ISMS) requirements
- [ISO/IEC 27002](https://www.iso.org/standard/73906.html) - Code of practice for information security controls
### Specialized ISO Standards
- [ISO/IEC 27032](https://www.iso.org/standard/44375.html) - Guidelines for cybersecurity
- [ISO/IEC 27033](https://www.iso.org/standard/63411.html) - Network security management
- [ISO/IEC 27034](https://www.iso.org/standard/44379.html) - Application security guidelines
- [ISO 22301](https://www.iso.org/iso-22301-business-continuity.html) - Business continuity management systems
---
## Industry Security Frameworks
### Threat Intelligence & Attack Frameworks
**MITRE Corporation:**
- [MITRE ATT&CK Framework](https://attack.mitre.org/) - Adversary tactics, techniques, and common knowledge
- [MITRE Shield](https://shield.mitre.org/) - Active defense knowledge base
- [MITRE Engage](https://engage.mitre.org/) - Framework for adversary engagement operations
**Attack Models:**
- [Lockheed Martin Cyber Kill Chain](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html) - Framework for identifying and preventing cyber intrusions
- [Diamond Model of Intrusion Analysis](https://www.threatintel.academy/wp-content/uploads/2020/07/diamond-model.pdf) - Model for analyzing cyber intrusions
- [Unified Kill Chain](https://www.unifiedkillchain.com/assets/The-Unified-Kill-Chain.pdf) - Unified framework combining multiple kill chain models
### Application Security
- [OWASP Top 10](https://owasp.org/www-project-top-ten/) - Top 10 web application security risks
- [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/) - Application Security Verification Standard
- [OWASP SAMM](https://owaspsamm.org/) - Software Assurance Maturity Model
- [OWASP Mobile Top 10](https://owasp.org/www-project-mobile-top-10/) - Mobile application security risks
### Security Controls & Best Practices
- [CIS Controls](https://www.cisecurity.org/controls) - Critical security controls for effective cyber defense
- [CIS Benchmarks](https://www.cisecurity.org/cis-benchmarks/) - Configuration best practices for various technologies
### Cloud Security
- [Cloud Security Alliance CCSK](https://cloudsecurityalliance.org/education/ccsk/) - Certificate of Cloud Security Knowledge
- [CSA Cloud Controls Matrix](https://cloudsecurityalliance.org/research/cloud-controls-matrix/) - Security controls framework for cloud computing
- [AWS Well-Architected Framework](https://aws.amazon.com/architecture/well-architected/) - Security pillar for AWS
---
## Compliance & Regulatory Frameworks
### Financial Services
**Payment Card Industry:**
- [PCI-DSS](https://www.pcisecuritystandards.org/) - Payment Card Industry Data Security Standard
- Requirements for securing credit card transactions
- Applies to all entities that store, process, or transmit cardholder data
**Banking & Finance:**
- [SOX (Sarbanes-Oxley Act)](https://www.sarbanes-oxley-101.com/sarbanes-oxley-compliance.htm) - Financial reporting and IT controls
- [GLBA (Gramm-Leach-Bliley Act)](https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act) - Financial privacy requirements
### Healthcare
- [HIPAA Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/index.html) - Health Insurance Portability and Accountability Act
- Protects electronic protected health information (ePHI)
- Administrative, physical, and technical safeguards
- [HITECH Act](https://www.hhs.gov/hipaa/for-professionals/special-topics/hitech-act-enforcement-interim-final-rule/index.html) - Health Information Technology for Economic and Clinical Health
### Privacy Regulations
**International:**
- [GDPR (General Data Protection Regulation)](https://gdpr.eu/) - European Union data protection and privacy
- Applies to all organizations processing EU citizen data
- Data protection by design and default
**United States:**
- [CCPA (California Consumer Privacy Act)](https://oag.ca.gov/privacy/ccpa) - California privacy law
- [CPRA (California Privacy Rights Act)](https://cpra.ca.gov/) - Enhanced California privacy protections
**Canada:**
- [PIPEDA](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/) - Personal Information Protection and Electronic Documents Act
### Federal & Government
**United States Federal:**
- [FISMA (Federal Information Security Management Act)](https://www.cisa.gov/fisma) - Federal information security requirements
- [FedRAMP (Federal Risk and Authorization Management Program)](https://www.fedramp.gov/) - Cloud security assessment for federal agencies
- [NIST SP 800-53](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final) - Security controls for federal systems
**Defense:**
- [CMMC (Cybersecurity Maturity Model Certification)](https://www.acq.osd.mil/cmmc/) - DoD cybersecurity framework
- Required for defense contractors
- Tiered maturity model (Levels 1-3)
### Industry Standards
- [SOC 2 Type II](https://www.vanta.com/products/soc-2) - Service Organization Control 2
- Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy
- Common for SaaS and cloud service providers
---
## Incident Response Frameworks
### Response Methodologies
**NIST Incident Response:**
- Preparation
- Detection and Analysis
- Containment, Eradication, and Recovery
- Post-Incident Activity
**SANS Incident Response:**
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons Learned
---
## Risk Management Frameworks
### Enterprise Risk
- [ISO 31000](https://www.iso.org/iso-31000-risk-management.html) - Risk management guidelines
- [COSO ERM Framework](https://www.coso.org/guidance-on-enterprise-risk-management) - Enterprise risk management
- [FAIR (Factor Analysis of Information Risk)](https://www.fairinstitute.org/) - Quantitative risk analysis
### IT Risk
- [OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation)](https://insights.sei.cmu.edu/library/octave-threat-based-risk-assessment/) - Risk-based strategic assessment
- [NIST RMF](https://csrc.nist.gov/projects/risk-management/about-rmf) - Risk Management Framework for information systems
---
## Security Architecture Frameworks
### Enterprise Architecture
- [SABSA (Sherwood Applied Business Security Architecture)](https://sabsa.org/) - Business-driven security architecture framework
- [TOGAF (The Open Group Architecture Framework)](https://www.opengroup.org/togaf) - Enterprise architecture methodology
- [Zachman Framework](https://www.zachman.com/about-the-zachman-framework) - Enterprise architecture framework
### Zero Trust
- [NIST Zero Trust Architecture (SP 800-207)](https://csrc.nist.gov/publications/detail/sp/800-207/final)
- [Microsoft Zero Trust Model](https://www.microsoft.com/en-us/security/business/zero-trust)
- [Google BeyondCorp](https://cloud.google.com/beyondcorp) - Zero trust security framework
---
## Industry-Specific Frameworks
### Critical Infrastructure
- [NERC CIP](https://www.nerc.com/pa/Stand/Pages/CIPstandards.aspx) - North American Electric Reliability Corporation Critical Infrastructure Protection
- [TSA Security Directives](https://www.tsa.gov/for-industry/security-directives) - Transportation security requirements
### Manufacturing & IoT
- [IEC 62443](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards) - Industrial automation and control systems security
- [NIST Cybersecurity for IoT](https://www.nist.gov/programs-projects/nist-cybersecurity-iot-program) - IoT security guidance
---
## Threat & Vulnerability Frameworks
### Vulnerability Databases
- [CVE (Common Vulnerabilities and Exposures)](https://cve.mitre.org/) - Vulnerability naming standard
- [NVD (National Vulnerability Database)](https://nvd.nist.gov/) - US government vulnerability database
- [CWE (Common Weakness Enumeration)](https://cwe.mitre.org/) - Software security weakness taxonomy
### Scoring Systems
- [CVSS (Common Vulnerability Scoring System)](https://www.first.org/cvss/) - Vulnerability severity scoring
- [EPSS (Exploit Prediction Scoring System)](https://www.first.org/epss/) - Likelihood of exploitation
---
## Data Breach & Incident Frameworks
### Incident Documentation
- [VERIS (Vocabulary for Event Recording and Incident Sharing)](http://veriscommunity.net/) - Framework for describing security incidents
- [STIX/TAXII](https://oasis-open.github.io/cti-documentation/) - Structured Threat Information Expression / Trusted Automated Exchange of Intelligence Information
---
## Maturity Models
### Security Maturity
- [OWASP SAMM](https://owaspsamm.org/) - Software Assurance Maturity Model
- [CMMC](https://www.acq.osd.mil/cmmc/) - Cybersecurity Maturity Model Certification
- [C2M2 (Cybersecurity Capability Maturity Model)](https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2) - Energy sector cybersecurity maturity
### Governance Maturity
- [COBIT](https://www.isaca.org/resources/cobit) - Control Objectives for Information and Related Technologies
- IT governance and management framework
- Published by ISACA
---
## Additional Resources
### Framework Implementation Guides
- [NIST Cybersecurity Framework Implementation Guide](https://www.nist.gov/cyberframework/getting-started)
- [CIS Controls Implementation Groups](https://www.cisecurity.org/controls/cis-controls-implementation-groups)
- [ISO 27001 Implementation Guide](https://www.iso.org/standard/73906.html)
### Framework Mapping
- [NIST-to-ISO Mapping](https://www.nist.gov/cyberframework/nist-cybersecurity-framework-and-iso-27001)
- [CIS Controls to NIST CSF Mapping](https://www.cisecurity.org/controls/cis-controls-navigator)
---
[Back to Resources](./README.md) | [Back to Main](../README.md)