Terminology Index
Glossary
2953 terms
Prescriptive vs Outcome-Based
The distinction between frameworks that prescribe specific controls and those that require outcomes (leaving implementation up to the organization), shaping how flexibly the framework can be applied across different environments.
Some frameworks (like PCI DSS or HIPAA Security Rule's specific safeguards) are prescriptive, dictating particular controls, while others (like NIST CSF or HIPAA's required outcomes) are outcome-based, requiring an objective be achieved without dictating how. Prescriptive frameworks bring consistency but can be a poor fit for novel environments; outcome-based ones offer flexibility but require interpretation. Recognizing the difference shapes framework selection and how to comply effectively with each.
Introduced in: Security Frameworks and Control Mapping
Examples
- PCI DSS prescribing specific controls for cardholder data.
- NIST CSF stating outcomes leaving implementation flexible.
- Choosing how to comply based on a framework's prescriptive vs outcome style.
