Skip to content
    Home / Publication Type / Standard

    Standard

    Standards are formally developed documents that define agreed-upon requirements, controls, or best practices to ensure a consistent and measurable level of security across organizations. Unlike laws and regulations, standards are generally voluntary unless incorporated into contracts or referenced by legislation, but they often serve as benchmarks for certification, audit, and due diligence. For example, ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), while ISO/IEC 27002 provides detailed guidance on selecting and implementing security controls. Standards are typically consensus-based and internationally recognized, offering structured, auditable criteria that help organizations demonstrate maturity, comparability, and trustworthiness in their cybersecurity practices.

    NIST SP 800-55 Vol. 2 Measurement Guide for Information Security: Volume 2 — Developing an Information Security Measurement Program

    The NIST Special Publication 800-55, Volume 2, titled “Measurement Guide for Information Security,” provides a flexible methodology and workflow for developing an information security measurement program. It is designed to… Read More »NIST SP 800-55 Vol. 2 Measurement Guide for Information Security: Volume 2 — Developing an Information Security Measurement Program

    NIST SP 800-55 Vol. 1 Measurement Guide for Information Security: Volume 1 — Identifying and Selecting Measures

    NIST Special Publication 800-55 Volume 1, titled “Measurement Guide for Information Security,” provides a flexible and comprehensive approach for developing, selecting, and prioritizing information security measures at the organizational, mission/business,… Read More »NIST SP 800-55 Vol. 1 Measurement Guide for Information Security: Volume 1 — Identifying and Selecting Measures

    NIST SP 800-172 Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

    NIST SP 800-172 is a supplementary publication to NIST SP 800-171 that provides 35 enhanced security requirements designed to protect controlled unclassified information (CUI) on non-federal systems, especially when related… Read More »NIST SP 800-172 Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

    NIST SP 800-171 Rev. 3 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

    NIST SP 800-171 is a set of cybersecurity standards developed by the National Institute of Standards and Technology (NIST) to protect Controlled Unclassified Information (CUI) in nonfederal systems and organizations.… Read More »NIST SP 800-171 Rev. 3 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

    NIST IR 8477 Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines

    NIST Interagency Report (IR) 8477, titled “Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines,” outlines a structured approach for mapping and documenting the relationships between elements-such as controls, requirements,… Read More »NIST IR 8477 Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines