What is a framework?
There are many ways to get a cybersecurity program off the ground, but where should you start? This can be intimidating to many IT professionals as cybersecurity has its own language. Frameworks are developed to assist organizations with this endeavor. A framework is used to align a program against best practices. It can also be a set of requirements that one must implement to perform a particular function.
Frameworks do not necessarily tell you how to implement a particular control, only that you should have it in place. For instance, a framework may state that you should implement multi-factor authentication (MFA); however, it may not state how or where to implement it. The framework may state that you ensure proper auditing and logging is configured, but not state how to do it or how long you should keep the logs.
A framework is a document used to help the organization implement best practices. You, or the head of security, may decide that you do not intend...