Skip to content
Home / Cyber Security Governance Guidelines

Which industry standards should guide your cyber strategy?

Here is the selection of readings we have chosen, to help you structure your cybersecurity strategy based on industry reference standards. This covers the key current topics in cybersecurity. We update this article regularly.

Cyber program

  • NIST CSF 2.0: Offers globally recognized control objectives, supported by predefined community profiles.
  • ISO 27002: An ideal control library for implementing the CSF, providing a more concise alternative to SP 800-53.

Ransomware protection

  • CISA Ransomware Guide: A practical, essential guide for both defending against and responding to ransomware attacks.

AI (Artificial Intelligence)

  • CEN-CLC-JTC21: Although still in draft by late 2025, this document is highly relevant and aligns with EU AI Act, Article 15 compliance.

PQC (Post Quantum Cryptography)

  • SEC PQFIF: A concise, straightforward reference for preparing PQC implementations.

Sec by Design for infra: ZT (Zero Trust)

  • NIST SP 800-207: Highlights the three core axes of Zero Trust Architecture.
  • CISA ZT Maturity: A must-have reference; conceptual but effectively maps ZTA and SDP principles.

Sec by Design for apps: SoFa and Coding