Explore other approaches
I focus on the Risk Management Framework (RMF) because I work with Department of Defense (DoD) Special Access Program (SAP) networks. Other frameworks, standards, and assurance programs are worth knowing about, too.
- National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)
Managing cybersecurity risk across an organization.
- ISO/IEC 27001
Information security management. Published by the International Organization for Standardization and the International Electrotechnical Commission.
- Center for Internet Security (CIS) Controls
Prioritized, practical security safeguards.
- Control Objectives for Information and Related Technologies (COBIT)
Governance and management of enterprise technology.
- System and Organization Controls (SOC) 2
Assurance about controls at service providers.
- Payment Card Industry Data Security Standard (PCI DSS)
Protecting payment account data.
- HITRUST Framework
Bringing multiple security and privacy requirements together.
- Cybersecurity Maturity Model Certification (CMMC)
Cybersecurity assurance for defense contractors.
- Federal Risk and Authorization Management Program (FedRAMP)
Security assessment and authorization for federal cloud services.