Security / frameworks explained Dark mode NIST CSF vs ISO 27001: What Is the Difference? NIST CSF 2.0 and ISO 27001 are two of the more widely referenced security frameworks, and teams often treat them as rivals. They are not. They solve overlapping problems in different ways, and many organizations use both. NIST CSF vs […]
Security / frameworks explained Dark mode What Is MITRE ATT&CK? Tactics, Techniques, and the Matrix MITRE ATT&CK is a curated knowledge base of how real adversaries behave. It catalogs the tactics and techniques attackers use across the phases of an intrusion, based on observations of actual attacks rather than theory. MITRE ATT&CK14 TacticsEnterprise / Mobile […]
Security / frameworks explained Dark mode What Are the CIS Controls? The CIS Critical Security Controls v8.1 The CIS Critical Security Controls are a prioritized set of actions that defend against the cyberattacks that actually happen. They began as a grassroots effort to study real-world attacks and turn that knowledge into constructive action for defenders, […]
Security / frameworks explained Dark mode What is ISO 27001? A Plain Guide to the ISMS Standard ISO/IEC 27001 is the international standard that specifies the requirements for an Information Security Management System, or ISMS. It is a widely recognized way for an organization to prove, to itself and to others, that it manages information […]
Security / frameworks explained Dark mode What Is the NIST Cybersecurity Framework (CSF) 2.0? The NIST Cybersecurity Framework (CSF) 2.0 is a free, voluntary framework that helps any organization understand, assess, prioritize, and communicate its cybersecurity risk. Published by the National Institute of Standards and Technology on February 26, 2024 (NIST CSWP 29), it gives […]