25 Great but Little-known Cybersecurity Frameworks 1.0, 17.08.2023 Current Organization Revision Framework Country Price 1. Information Security Manual (ISM) 2023 ACSC Australia Free 2. Essential Eight 2023 ACSC Australia Free 3. Baseline Cyber Security Controls for Small and Medium Organizations 2021 DGC Canada Free 2020 NSA (Finland) Finland Free (CAN/CIOSC 104:2021) 4. Katakri 2020. Information security auditing tool for authorities 5. ETSI TR 103 305-1 (set) v.4.1.2, 2022 ETSI France Free 6. Controlling the digital risk. The trust advantage 2019 ANSSI and AMRAE France Free 7. IT-Grundschutz (set) 1.0, 2017 BSI Germany Free 8. Guideline "State of the art". Technical and organisational measures 2023 TeleTrusT & ENISA Germany Free 9. Cybersecurity Management Guidelines for Japanese Enterprise Executives 3.0, 2023 METI & IPA Japan Free 2021 ISO International, Switzerland CHF124 ($140) 11. Standard of Good Practice for Information Security (SoGP) 2022 ISF International, For USA members 12. COBIT Focus Area: Information Security 2020 ISACA International, USA $90 v.11.1, 2023 HITRUST International, USA Free 14. Open Information Security Management Maturity Model (O-ISM3) 2.0, 2017 Open Group International Free 15. New Zealand Information Security Manual (NZISM) 3.6, 2022 New Zealand Government New Zealand Free 16. Qatar 2022 Cybersecurity Framework 1.0, 2018 SCDL Qatar Free 2018 NCA Saudi Arabia Free 18. Cyber Security Framework (by SAMA) 1.0, 2-17 SAMA Saudi Arabia Free 19. Cyber Essentials: Requirements for IT infrastructure 3.1, 2022 NCSC UK Free 20. Cyber Assessment Framework (CAF) 3.1, 2022 NCSC UK Free 21. Cybersecurity Capability Maturity Model (C2M2) 2.1, 2022 CESER USA Free 2020? CISA USA Free 23. Cybersecurity Maturity Model Certification (CMMC) 2.0, 2021 Department of Defense USA Free 24. Equifax Security Controls Framework 2.0, 2022 Equifax USA Free 25. Common Sense Guide to Mitigating Insider Threats v.7, 2022 CMU USA Free Cyber Security (CYBER); Critical Security Controls for Effective Cyber Defence; Part 1: The Critical Security Controls 10. ISO/IEC TS 27110:2021 Information technology, cybersecurity and privacy protection — Cybersecurity framework development guidelines 13. HITRUST CSF (Common Security Framework) 17. Essential Cybersecurity Controls (ECC) (set) 22. Cyber Essentials Toolkits (set) by Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 www.patreon.com/AndreyProzorov 25 Great but Little-known Cybersecurity Frameworks 1.0, 17.08.2023 Links: 1. ISM: https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism 2. Essential Eight: https://www.cyber.gov.au/resources-business-and-government/essential-cybersecurity/essential-eight/essential-eight-assessment-process-guide 3. CAN/CIOSC 104: 2021: https://dgc-cgn.org/standards/find-a-standard/standards-incybersecurity/cybersecurity-smes 4. Katakri: https://um.fi/information-security-auditing-tool-for-authorities-katakri 5. ETSI: https://www.etsi.org/committee/cyber 6. IT-Grundschutz: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standardsund-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html 7. Controlling the digital risk: https://www.ssi.gouv.fr/guide/controlling-the-digital-risk-the-trustadvantage 8. "State of the art" in IT security: https://www.teletrust.de/en/publikationen/broschueren/state-of-theart-in-it-security 9. Japanese Guidelines: https://www.meti.go.jp/policy/netsecurity/mng_guide.html 10. ISO 27110: https://www.iso.org/standard/72435.html 11. ISF SoGP: https://www.securityforum.org/solutions-and-insights/standard-of-good-practice-forinformation-security 12. COBIT Focus Area: Information Security: https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Ko9hEAC 13. HITRUST: https://hitrustalliance.net/product-tool/hitrust-csf 14. O-ISM3: https://publications.opengroup.org/c17b 15. NZISM: https://nzism.gcsb.govt.nz 16. Qatar 2022 Cybersecurity Framework: https://www.qatar2022.qa/sites/default/files/Qatar2022Framework.pdf 17. Essential Cybersecurity Controls (ECC): https://nca.gov.sa/en/legislation 18. SAMA: https://www.sama.gov.sa/enUS/RulesInstructions/CyberSecurity/Cyber%20Security%20Framework.pdf 19. NCSC Cyber Essentials: https://www.ncsc.gov.uk/cyberessentials/overview 20. CAF: https://www.ncsc.gov.uk/collection/caf 21. C2M2: https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2 22. CISA Cyber Essentials CISA Cyber Essentials Starter Kit: https://www.cisa.gov/resources-tools/resources/cisa-cyberessentials-starter-kit Cyber Essentials Toolkits: https://www.cisa.gov/resources-tools/resources/cyber-essentials-toolkits 23. CMMC: https://dodcio.defense.gov/CMMC 24. Equifax: https://controlsframework.equifax.com/home 25. Insider Threats Guide: https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=886874 26. NCSC Cyber Security Framework (beta): https://www.ncsc.govt.nz/resources/ncsc-cyber-securityframework 27. Cyber Security Body of Knowledge (CyBOK): https://www.cybok.org by Andrey Prozorov, CISM, CIPP/E, CDPSE, LA 27001 www.patreon.com/AndreyProzorov