Standards
Cybersecurity standards can be described as a documented accumulation of best practices created by industry experts to protect organizations from cyber threats. Cybersecurity standards and frameworks are usually applicable to all organizations regardless of their size, industry, or sector, though some are a better fit than others. Now, what is the difference between a standard and a framework? A framework is always a standard, but a standard is not always a framework.
That should clear everything right up! The following unpacks the preceding statement. A framework is typically built from one or many standards. An example of a framework is the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), which is built using several other frameworks, such as the International Organization for Standardization (ISO) 27001, Control Objectives for Information and Related Technologies (COBIT), the Center for Internet Security Critical Security Controls ...