Skip to content
FioSec Consulting

Frameworks & standards

Cybersecurity frameworks, explained

NIST, CIS, ISO 27001, SOC 2, PCI DSS, CIRO. The alphabet soup of security and compliance can be overwhelming, so this is a plain-language guide to what each one actually is, who it's for, and how they fit together. Each guide ends with a free readiness checklist you can score privately, right in your browser.

What is a security framework?

A cybersecurity framework is a structured set of outcomes, controls, or requirements that helps an organization decide what to protect, how to protect it, and how to prove it. Some are voluntary guides you adopt to organize your program; some are certifiable standards an auditor checks you against; and some are laws or regulator expectations you have to meet.

You rarely need all of them, and they are not in competition. Most organizations build on one foundational framework and layer specific compliance or regulatory requirements on top as customers and contracts demand. The guides below explain each one in detail and, where it helps, how they map onto FioSec's seven layers of defence.

Which framework fits your organization?

Answer six quick questions and we'll point you to the framework to build on, the obligations you have to meet, and the proof your customers may ask for.

Find your framework

Still weighing your options?

That's one of the most common questions we hear. Try the selector for an instant read, or talk it through with our team.