Essential Security Frameworks
Corporate boards and other organizational boards might advise the use of existing security frameworks because they are tested, approved, and trusted by auditors and regulators. Various industries have frameworks they are familiar with. For example, US Federal Government institutions use and follow National Institute of Standards and Technology (NIST) standards to reduce risk, including the Special Publication (SP) 800-37: Guide for Applying the Risk Management Framework to Federal Information Systems and SP 800-53: Security and Privacy Controls for Federal Information Systems and Organizations.
Many for-profit organizations use and follow International Organization for Standardization (ISO) standards such as 27001: Information Technology – Security Techniques – Information Security Management Systems – Requirements and 27002: Code of Practice for Information Security Controls.
US hospitals and medical institutions follow the...