Terminology Index
Glossary
1801 terms
Showing 1473-1504 of 1801 terms
Security Framework Types
The different categories of security frameworks (control catalogs, risk frameworks, regulatory regimes, certifications) that serve different purposes and combine into how an organization manages compliance.
Security frameworks are not all the same: some are control catalogs (NIST 800-53, CIS Controls) listing what to do; some are risk frameworks (NIST RMF, ISO 31000) describing how to manage risk; some are regulatory regimes (GDPR, HIPAA) imposing obligations; some are certification schemes (ISO 27001, SOC 2, HITRUST) providing third-party assurance. Recognizing the type clarifies what each one delivers and how multiple frameworks combine, foundational to GRC and framework-mapping work.
Introduced in: Security Frameworks and Control Mapping
Examples
- Distinguishing a control catalog like 800-53 from a risk framework like RMF.
- Treating GDPR as a regulatory regime rather than a control catalog.
- Choosing a certification scheme to gain third-party assurance.
No related terms linked yet.
