Skip to content
    Home / Publication Type / Standard

    Standard

    Standards are formally developed documents that define agreed-upon requirements, controls, or best practices to ensure a consistent and measurable level of security across organizations. Unlike laws and regulations, standards are generally voluntary unless incorporated into contracts or referenced by legislation, but they often serve as benchmarks for certification, audit, and due diligence. For example, ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), while ISO/IEC 27002 provides detailed guidance on selecting and implementing security controls. Standards are typically consensus-based and internationally recognized, offering structured, auditable criteria that help organizations demonstrate maturity, comparability, and trustworthiness in their cybersecurity practices.

    CIS Secure by Design: A Guide to Assessing Software Security Practices

    This document is a comprehensive guide developed by the Center for Internet Security (CIS) in collaboration with SAFECode and a community of experts. It provides a practical, evaluable framework to… Read More »CIS Secure by Design: A Guide to Assessing Software Security Practices

    SEC Post-Quantum Financial Infrastructure Framework (PQFIF)

    The SEC’s Post-Quantum Financial Infrastructure Framework (PQFIF) is a comprehensive strategic plan designed to secure the U.S. financial system against the emerging threats posed by quantum computing advancements. Its primary… Read More »SEC Post-Quantum Financial Infrastructure Framework (PQFIF)

    NIST IR 8349 Methodology for Characterizing Network Behavior of Internet of Things Devices

    NIST Internal Report (IR) 8349, titled “Methodology for Characterizing Network Behavior of Internet of Things Devices,” outlines a comprehensive approach to capturing, documenting, and analyzing the network communication behaviors of… Read More »NIST IR 8349 Methodology for Characterizing Network Behavior of Internet of Things Devices

    CIS Controls Internet of Things Companion Guide

    The CIS Controls Internet of Things (IoT) Companion Guide provides detailed guidance on how to apply the cybersecurity best practices of the CIS Controls, particularly Version 8.1, to IoT environments.… Read More »CIS Controls Internet of Things Companion Guide

    CISA Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators

    The CISA guidance titled “Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators” provides operational technology (OT) owners and operators across critical infrastructure sectors with practical, step-by-step recommendations… Read More »CISA Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators