Uploaded by Chirayu Mahajan

25 Great but Little known Cybersecurity Frameworks 1692503179

advertisement
25 Great but Little-known Cybersecurity Frameworks
1.0, 17.08.2023
Current
Organization
Revision
Framework
Country
Price
1.
Information Security Manual (ISM)
2023
ACSC
Australia
Free
2.
Essential Eight
2023
ACSC
Australia
Free
3.
Baseline Cyber Security Controls for Small
and Medium Organizations
2021
DGC
Canada
Free
2020
NSA (Finland)
Finland
Free
(CAN/CIOSC 104:2021)
4.
Katakri 2020. Information security auditing
tool for authorities
5.
ETSI TR 103 305-1 (set)
v.4.1.2,
2022
ETSI
France
Free
6.
Controlling the digital risk.
The trust advantage
2019
ANSSI and
AMRAE
France
Free
7.
IT-Grundschutz (set)
1.0, 2017
BSI
Germany
Free
8.
Guideline "State of the art".
Technical and organisational measures
2023
TeleTrusT &
ENISA
Germany
Free
9.
Cybersecurity Management Guidelines for
Japanese Enterprise Executives
3.0, 2023
METI & IPA
Japan
Free
2021
ISO
International,
Switzerland
CHF124
($140)
11. Standard of Good Practice for Information
Security (SoGP)
2022
ISF
International,
For
USA
members
12. COBIT Focus Area: Information Security
2020
ISACA
International,
USA
$90
v.11.1,
2023
HITRUST
International,
USA
Free
14. Open Information Security Management
Maturity Model (O-ISM3)
2.0, 2017
Open Group
International
Free
15. New Zealand Information Security Manual
(NZISM)
3.6, 2022
New Zealand
Government
New Zealand
Free
16. Qatar 2022 Cybersecurity Framework
1.0, 2018
SCDL
Qatar
Free
2018
NCA
Saudi Arabia
Free
18. Cyber Security Framework (by SAMA)
1.0, 2-17
SAMA
Saudi Arabia
Free
19. Cyber Essentials: Requirements for IT
infrastructure
3.1, 2022
NCSC
UK
Free
20. Cyber Assessment Framework (CAF)
3.1, 2022
NCSC
UK
Free
21. Cybersecurity Capability Maturity Model
(C2M2)
2.1, 2022
CESER
USA
Free
2020?
CISA
USA
Free
23. Cybersecurity Maturity Model Certification
(CMMC)
2.0, 2021
Department of
Defense
USA
Free
24. Equifax Security Controls Framework
2.0, 2022
Equifax
USA
Free
25. Common Sense Guide to Mitigating Insider
Threats
v.7, 2022
CMU
USA
Free
Cyber Security (CYBER); Critical Security Controls for
Effective Cyber Defence; Part 1: The Critical Security Controls
10. ISO/IEC TS 27110:2021
Information technology, cybersecurity and privacy protection
— Cybersecurity framework development guidelines
13. HITRUST CSF
(Common Security Framework)
17. Essential Cybersecurity Controls (ECC) (set)
22. Cyber Essentials Toolkits (set)
by Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001
www.patreon.com/AndreyProzorov
25 Great but Little-known Cybersecurity Frameworks
1.0, 17.08.2023
Links:
1.
ISM: https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism
2.
Essential Eight: https://www.cyber.gov.au/resources-business-and-government/essential-cybersecurity/essential-eight/essential-eight-assessment-process-guide
3.
CAN/CIOSC 104: 2021: https://dgc-cgn.org/standards/find-a-standard/standards-incybersecurity/cybersecurity-smes
4.
Katakri: https://um.fi/information-security-auditing-tool-for-authorities-katakri
5.
ETSI: https://www.etsi.org/committee/cyber
6.
IT-Grundschutz: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standardsund-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html
7.
Controlling the digital risk: https://www.ssi.gouv.fr/guide/controlling-the-digital-risk-the-trustadvantage
8.
"State of the art" in IT security: https://www.teletrust.de/en/publikationen/broschueren/state-of-theart-in-it-security
9.
Japanese Guidelines: https://www.meti.go.jp/policy/netsecurity/mng_guide.html
10. ISO 27110: https://www.iso.org/standard/72435.html
11. ISF SoGP: https://www.securityforum.org/solutions-and-insights/standard-of-good-practice-forinformation-security
12. COBIT Focus Area: Information Security:
https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Ko9hEAC
13. HITRUST: https://hitrustalliance.net/product-tool/hitrust-csf
14. O-ISM3: https://publications.opengroup.org/c17b
15. NZISM: https://nzism.gcsb.govt.nz
16. Qatar 2022 Cybersecurity Framework:
https://www.qatar2022.qa/sites/default/files/Qatar2022Framework.pdf
17. Essential Cybersecurity Controls (ECC): https://nca.gov.sa/en/legislation
18. SAMA: https://www.sama.gov.sa/enUS/RulesInstructions/CyberSecurity/Cyber%20Security%20Framework.pdf
19. NCSC Cyber Essentials: https://www.ncsc.gov.uk/cyberessentials/overview
20. CAF: https://www.ncsc.gov.uk/collection/caf
21. C2M2: https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2
22. CISA Cyber Essentials
CISA Cyber Essentials Starter Kit: https://www.cisa.gov/resources-tools/resources/cisa-cyberessentials-starter-kit
Cyber Essentials Toolkits: https://www.cisa.gov/resources-tools/resources/cyber-essentials-toolkits
23. CMMC: https://dodcio.defense.gov/CMMC
24. Equifax: https://controlsframework.equifax.com/home
25. Insider Threats Guide: https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=886874
26. NCSC Cyber Security Framework (beta): https://www.ncsc.govt.nz/resources/ncsc-cyber-securityframework
27. Cyber Security Body of Knowledge (CyBOK): https://www.cybok.org
by Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001
www.patreon.com/AndreyProzorov
Download