Category: Security frameworks
A security framework is a structured set of controls and practices an organisation adopts to manage cyber risk, usually published by a national body or an industry scheme rather than by ISO. Some are voluntary guidance, some are regulatory obligations, and some are contractual requirements imposed by the parties you do business with.
They differ from ISO 27001 in an important way. ISO 27001 certifies a management system: you define the scope, assess the risk and justify the controls you select. Most other frameworks prescribe a control baseline and ask you to evidence each control individually. Neither approach is better, but they produce different work and different proof.
The NIST Cybersecurity Framework is voluntary guidance organised around six functions since version 2.0 added Govern alongside Identify, Protect, Detect, Respond and Recover. It cannot be certified, so organisations that need something a customer can verify typically use the CSF to structure the programme and ISO 27001 or SOC 2 to prove it.
PCI DSS is contractual rather than legal, imposed by the card brands on anyone who stores, processes or transmits cardholder data. Version 4.0 introduced the customised approach, which allows you to meet a requirement’s objective with a control of your own design, provided you document a targeted risk analysis and your assessor validates it.
The NCA Essential Cybersecurity Controls are mandatory for Saudi government organisations and operators of critical national infrastructure, assessed by self-assessment reported to the National Cybersecurity Authority rather than by certification.
The guides below cover the NIST Cybersecurity Framework and its profiles, PCI DSS v4.0 and the customised approach, and the NCA ECC for organisations operating in Saudi Arabia.