Skip to content

Latest commit

 

History

History
75 lines (51 loc) · 3.46 KB

File metadata and controls

75 lines (51 loc) · 3.46 KB

Control Frameworks & Standards

Control frameworks and security standards provide structured approaches to implementing and assessing cybersecurity controls.

NIST Frameworks

NIST Cybersecurity Framework (CSF)

NIST Risk Management Framework (RMF)

NIST Publications on Risk & Governance

ISO/IEC Standards

CIS Controls

COBIT

CRF (Cyber Risk Framework)

Control Mappings & Alignment

Compare and align controls across different frameworks:

Other Standards Bodies

SLSA Framework (Supply Chain Levels for Software Artifacts)

  • SLSA Framework: Google's framework for software supply chain security
    • Levels 1-4 of software artifact security
    • Provenance and integrity guarantees
    • Focus on protecting against tampering and unauthorized changes

NIST Secure Software Development Framework (SSDF)

  • NIST SSDF: Security practices for software development
    • Practice Groups (PO, PS, PO, PR) covering practices and controls
    • Emphasis on secure development, secure supply chain, and incident management
    • Applicable to commercial and government software

CIS Software Supply Chain Security Benchmark

  • CIS Benchmarks - Supply Chain Security: Best practices for securing software supply chain
    • Code repository security
    • Build process security
    • Artifact and dependency management
    • Vulnerability management in dependencies