Frameworks & standards
Cybersecurity frameworks, explained
NIST, CIS, ISO 27001, SOC 2, PCI DSS, CIRO. The alphabet soup of security and compliance can be overwhelming, so this is a plain-language guide to what each one actually is, who it's for, and how they fit together. Each guide ends with a free readiness checklist you can score privately, right in your browser.
What is a security framework?
A cybersecurity framework is a structured set of outcomes, controls, or requirements that helps an organization decide what to protect, how to protect it, and how to prove it. Some are voluntary guides you adopt to organize your program; some are certifiable standards an auditor checks you against; and some are laws or regulator expectations you have to meet.
You rarely need all of them, and they are not in competition. Most organizations build on one foundational framework and layer specific compliance or regulatory requirements on top as customers and contracts demand. The guides below explain each one in detail and, where it helps, how they map onto FioSec's seven layers of defence.
Which framework fits your organization?
Answer six quick questions and we'll point you to the framework to build on, the obligations you have to meet, and the proof your customers may ask for.
Foundational
General-purpose frameworks that organize a whole security program. Start here; most organizations build on one of these.
NIST Cybersecurity Framework
A voluntary, outcome-based framework for organizing and improving a cybersecurity program around six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
Read the guide CIS Controls v8CIS Critical Security Controls
18 prioritized, prescriptive safeguards grouped into three Implementation Groups, and the most actionable starting point for most organizations.
Read the guide ISO/IEC 27001ISO/IEC 27001 Information Security Management
The international, certifiable standard for an Information Security Management System (ISMS): process- and governance-led, and recognized worldwide.
Read the guideCompliance & contractual
Standards you adopt because a customer, contract, or card network requires evidence that specific controls are in place.
SOC 2 (Trust Services Criteria)
An independent auditor’s report on the controls a service provider operates against five Trust Services Criteria, frequently requested by your customers.
Read the guide PCI DSSPayment Card Industry Data Security Standard
The mandatory control standard for any organization that stores, processes, or transmits payment-card data.
Read the guideCanadian & regulatory
Laws and regulator expectations that apply to organizations operating in Canada and Ontario.
CIRO Cybersecurity Expectations
The cybersecurity expectations the Canadian Investment Regulatory Organization sets for the investment dealers and mutual fund firms it regulates.
Read the guide PIPEDAPersonal Information Protection and Electronic Documents Act
Canada’s federal private-sector privacy law: the safeguarding and breach-reporting duties that apply when you handle personal information.
Read the guide PHIPAPersonal Health Information Protection Act (Ontario)
Ontario’s health-privacy law, governing how health-information custodians protect personal health information.
Read the guide CCCS BaselineCanadian Centre for Cyber Security Baseline Controls
Plain-language baseline cyber security controls for small and medium organizations, from Canada’s national cyber security authority.
Read the guideGovernment & supply chain
Control sets required to do business with government and within its supply chains.
Still weighing your options?
That's one of the most common questions we hear. Try the selector for an instant read, or talk it through with our team.