Skip to content
    Home / Publication Type / Standard

    Standard

    Standards are formally developed documents that define agreed-upon requirements, controls, or best practices to ensure a consistent and measurable level of security across organizations. Unlike laws and regulations, standards are generally voluntary unless incorporated into contracts or referenced by legislation, but they often serve as benchmarks for certification, audit, and due diligence. For example, ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), while ISO/IEC 27002 provides detailed guidance on selecting and implementing security controls. Standards are typically consensus-based and internationally recognized, offering structured, auditable criteria that help organizations demonstrate maturity, comparability, and trustworthiness in their cybersecurity practices.

    ISO/IEC 27004:2016 Information technology — Security techniques — Information security management — Monitoring, measurement, analysis and evaluation

    ISO/IEC 27004 is an international standard that provides guidelines for monitoring, measuring, analyzing, and evaluating the performance and effectiveness of an Information Security Management System (ISMS) based on ISO/IEC 27001.… Read More »ISO/IEC 27004:2016 Information technology — Security techniques — Information security management — Monitoring, measurement, analysis and evaluation

    NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View

    NIST SP 800-39 serves as the overarching flagship for information security risk management, providing the high-level governance necessary to align cybersecurity efforts with an organization’s core mission and business objectives.… Read More »NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View