Skip to content
    Home / Publication Type / Standard

    Standard

    Standards are formally developed documents that define agreed-upon requirements, controls, or best practices to ensure a consistent and measurable level of security across organizations. Unlike laws and regulations, standards are generally voluntary unless incorporated into contracts or referenced by legislation, but they often serve as benchmarks for certification, audit, and due diligence. For example, ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), while ISO/IEC 27002 provides detailed guidance on selecting and implementing security controls. Standards are typically consensus-based and internationally recognized, offering structured, auditable criteria that help organizations demonstrate maturity, comparability, and trustworthiness in their cybersecurity practices.

    NIST SP 800-61 Rev. 3 Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile

    NIST SP 800-61 Revision 3, titled Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, provides updated guidance to help organizations integrate incident response into their… Read More »NIST SP 800-61 Rev. 3 Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile

    NIST IR 8286C Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight

    NIST IR 8286C Rev. 1, Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight, completes the risk management cycle by detailing how prioritized risks are formally communicated and acted… Read More »NIST IR 8286C Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight

    NIST IR 8286D Using Business Impact Analysis to Inform Risk Prioritization and Response

    NIST IR 8286D, Using Business Impact Analysis to Inform Risk Prioritization and Response, bridges the gap between traditional Business Impact Analysis (BIA) and modern cybersecurity risk management. It provides a… Read More »NIST IR 8286D Using Business Impact Analysis to Inform Risk Prioritization and Response

    NIST IR 8374 Rev. 1 Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile

    The “Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile” is a NIST publication that provides organizations with a practical guide to managing ransomware risks using the updated NIST Cybersecurity… Read More »NIST IR 8374 Rev. 1 Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile