The one that fits the regulatory and contractual context. If you are a US federal agency, NIST 800-53. If you operate globally, ISO 27001. If you are a SaaS company selling to enterprise customers, SOC 2 and possibly ISO 27001. If you have no specific mandate, NIST CSF is the right starting point. The framework is a vocabulary; the discipline is what matters.
Security Governance Frameworks
A framework is a vocabulary, not a checklist. A control is a translation, not a guarantee. The operating model is what keeps the controls current. The posture assessment is the measurement that drives the work.
On this page
§ 01 ·
What security governance is
Security governance is the discipline of running a security practice as a practice, not as a project. The discipline covers the framework (the vocabulary the practice uses), the controls (the translation of the framework into specific actions), the operating model (the people, the processes, the tooling that keep the controls current), and the posture assessment (the measurement that drives the work).
The most important property of a security governance practice is that it is integrated with delivery. A security practice that runs in a separate team, on a separate schedule, with a separate backlog, is a security practice that is current to last quarter and out of date with this sprint. The framework is the vocabulary the delivery team uses; the controls are the paved roads the delivery team uses; the operating model is the discipline that keeps the paved roads current.
§ 02 ·
The frameworks
The frameworks that have held up across the organisations we work with:
NIST CSF (Cybersecurity Framework). The most useful of the US frameworks because it is organised by function (Identify, Protect, Detect, Respond, Recover) and because it is technology-neutral. The CSF is the right choice for organisations that need a framework but do not have a regulatory mandate for a specific framework.
NIST 800-53. The most rigorous of the US frameworks. The right choice for US federal agencies and for organisations that have government contracts. The control catalog is exhaustive; the discipline is the profile that selects the controls that apply.
ISO 27001 / 27002. The international standard. The right choice for organisations that operate globally. The certification is the formal attestation that the ISMS is in place; the certification is not the security practice.
CIS Controls (v8). The prioritised, actionable controls. The right choice for organisations that need a starting point. The Implementation Groups (IG1, IG2, IG3) are a useful maturity model.
SOC 2. The audit, not the framework. SOC 2 is the attestation that the controls are in place; the Trust Services Criteria (TSC) are the framework. SOC 2 is the right answer when a customer requires it; it is not a substitute for a security governance practice.
The framework is a vocabulary, not a checklist. The right answer is to pick the framework that fits the regulatory and contractual context, to use the framework as a vocabulary for the conversation, and to translate the framework into controls that fit the organisation.
§ 03 ·
State of the practice
§ 04 ·
Questions we get asked
The whole organisation, but starting with the crown-jewel assets. The scope is the boundary of the security practice; the scope has to be the whole organisation because the threats do not respect the boundary. The starting point is the crown-jewel assets because the highest-value work is on the highest-value assets. The scope grows from there.
On three properties, in order: (1) does the framework apply, is the vocabulary in use across the organisation; (2) are the controls in place, is the translation done, with evidence; (3) is the operating model working. are the controls current, is the audit loop closing. The order matters: a posture that scores high on (2) and low on (3) is a posture that is decaying.
§ 05 ·
Patterns we design our practice to avoid
A framework that is used as a checklist is a framework that is not in use. The framework is a vocabulary. The conversation is the vocabulary in use. A checklist of controls without a conversation is a control inventory without a security practice.
A control inventory that lives in a spreadsheet is a control inventory that is out of date. The controls have to live in the same place as the systems they apply to. The audit loop has to close against the actual systems, not against the spreadsheet.
An audit is a measurement. A security practice is the work. An organisation that has an annual SOC 2 audit and no security practice in between is an organisation that has a report and a posture, not a practice.
A security policy that nobody has read in two years is documentation, not governance. The policy has to be living: reviewed when the threats change, consulted when the controls are selected, updated when the controls are insufficient. A policy without an operating model is a policy that does not exist.
§ 06 ·
Evidence & references
Public frameworks and writing that inform our practice.
The most useful of the US frameworks for organisations that need a vocabulary but do not have a regulatory mandate. The five functions (Identify, Protect, Detect, Respond, Recover) and the six functions in 2.0 (with Govern added) are the canonical decomposition.
The most rigorous of the US control catalogs. The right choice for US federal agencies and for organisations with government contracts. The control catalog is exhaustive; the discipline is the profile.
The international standard. The right choice for organisations that operate globally. The certification is the formal attestation; the certification is not the practice.
The prioritised, actionable controls. The Implementation Groups (IG1, IG2, IG3) are a useful maturity model. The right starting point for organisations that need a starting point.
The audit framework. SOC 2 is the attestation, not the practice. The Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) are the framework.
Building a security governance practice?
If you are weighing a security governance initiative, evaluating a framework, or trying to make an existing practice more than a documentation exercise, we are useful at the boundary between the framework and the implementation. A short conversation is the right next step.
Learn more