Skip to content
Home / Publication Type

Standard

Standards are formally developed documents that define agreed-upon requirements, controls, or best practices to ensure a consistent and measurable level of security across organizations. Unlike laws and regulations, standards are generally voluntary unless incorporated into contracts or referenced by legislation, but they often serve as benchmarks for certification, audit, and due diligence. For example, ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), while ISO/IEC 27002 provides detailed guidance on selecting and implementing security controls. Standards are typically consensus-based and internationally recognized, offering structured, auditable criteria that help organizations demonstrate maturity, comparability, and trustworthiness in their cybersecurity practices.

NIST IR 8596 Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile): NIST Community Profile

The NIST Cyber AI Profile offers a structured approach to integrating AI into cybersecurity operations. It provides guidance on leveraging AI for threat detection, risk assessment, and automated response while… Read More »NIST IR 8596 Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile): NIST Community Profile

NIST SP 800-18 Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

NIST SP 800-18 Revision 2, “Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems,” provides a structured framework for creating comprehensive security plans for federal information systems,… Read More »NIST SP 800-18 Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

NIST IR 8477 Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines

NIST Interagency Report (IR) 8477, titled “Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines,” outlines a structured approach for mapping and documenting the relationships between elements-such as controls, requirements,… Read More »NIST IR 8477 Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines

ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements

ISO 27001 is an internationally recognized standard that provides a comprehensive framework for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) within any organization. Its primary goal… Read More »ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements

NIST SP 800-161 Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

NIST SP 800-161 Rev. 1, titled “Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations,” offers comprehensive guidance for organizations to identify, assess, and mitigate cybersecurity risks across their… Read More »NIST SP 800-161 Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations