Terminology Index
Glossary
2953 terms
Framework Purpose
Understanding what a given security framework is actually for, risk management, certification, regulatory compliance, or prescriptive guidance, so it is applied to the right ends rather than misused for a purpose it was not designed to serve.
Each framework was created with a purpose: the NIST CSF to structure and communicate risk management, ISO 27001 to certify an information security management system, SP 800-53 to catalog detailed controls, CIS Controls to give prioritized prescriptive actions. Knowing a framework's purpose lets an organization pick the right tool for its goal and avoid anti-patterns like forcing a reference framework to act as a certification. Purpose is the basis for selection and mapping.
Introduced in: Security Frameworks and Control Mapping
Examples
- Using the NIST CSF for risk structure rather than as a certification.
- Choosing ISO 27001 when the goal is a certifiable management system.
- Reaching for CIS Controls when prescriptive action is needed.
Related
