Control Framework
What is Control Framework?
A structured set of controls organized into domains and objectives that provides a systematic approach to managing specific types of risk.
Terms that appear alongside control framework
Each of these is named in at least one of the same controls as control framework. The number is how many controls name both.
- security framework 2 shared controls
- nist 2 shared controls
- audit 2 shared controls
- authentication 2 shared controls
- access control 2 shared controls
- information security 2 shared controls
- cybersecurity 2 shared controls
- internal control 2 shared controls
Frameworks that govern control framework
What the standards actually require on control framework
Requirements naming control framework across 6 standards, quoted from the control text.
Operate an information security programme that covers all the domains of the control framework rather than a chosen subset.
CCM-GRC-05 · Information Security Program →Article 33 requires notification of changes to the management body to the competent authority. Article 34 sets the substantive governance arrangements for ART issuers (Article 34 specifies the requirements for the management body, separation of functions, inte...
MiCA-Art.33_34_35 · Notification of management changes, governance and own funds (Articles 33-35) →HL7 FHIR Security Framework scope + structure. HL7 FAST HEALTHCARE INTEROPERABILITY RESOURCES (FHIR) is the global standard for healthcare data exchange APIs published by HEALTH LEVEL 7 INTERNATIONAL (HL7). VERSIONS: (a) FHIR DSTU1 (2014); (b) DSTU2 (2015);
HL7-FHIR-Scope-Versions-HL7-Specification · HL7 FHIR Security Framework Scope, FHIR Versions (R4/R4B/R5/R6), HL7 Specification + Security/Privacy Module →ITU-T Recommendation X.805 (10/2003) Security architecture for systems providing end-to-end communications is a foundational network security architecture standard published by the International Telecommunication Union Telecommunication Standardization Sector...
X805-Scope-Architecture-3Layers-3Planes-8Dimensions-5Threats-72Cells-X.800-Series-Heritage · ITU-T X.805 Scope + Security Architecture Overview + 3 Security Layers x 3 Security Planes (9 Modules) x 8 Security Dimensions = 72 Security Perspectives + 5 Threat Categories + X.800-Series Heritage + End-to-End Network Communications →Establish the scope of MITRE D3FEND (Detection, Denial and Disruption Framework Empowering Network Defense) - defensive cybersecurity countermeasure knowledge graph developed by MITRE Corporation under funding from National Security Agency (NSA) Information As...
MITRE-D3FEND-Scope-MITRE-NSA-2021-CC-BY-4-0-Countermeasure-Knowledge-Graph-Companion-ATTACK-Ontology · MITRE D3FEND Scope + MITRE + NSA 2021 + CC BY 4.0 + Countermeasure Knowledge Graph + Companion to ATT&CK + Ontology →Adequate internal control system including administrative and accounting procedures, internal control framework, and appropriate reporting arrangements (Article 46).
SII-P2-05 · Internal Control System →Questions people ask about control framework
What is Control Framework?
Why is Control Framework important for compliance?
Which compliance frameworks address Control Framework?
Where can I learn more about Control Framework?
See how Control Framework applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.