Skip to content

Cybersecurity Framework

What is Cybersecurity Framework?

A structured set of guidelines and best practices for managing cybersecurity risk, helping organizations assess and improve their security posture.

Information Security

Each of these is named in at least one of the same controls as cybersecurity framework. The number is how many controls name both.

What the standards actually require on cybersecurity framework

Requirements naming cybersecurity framework across 6 standards, quoted from the control text.

Article 29 establishes the COMMON ELECTRICITY CYBERSECURITY FRAMEWORK - a sector-specific set of cybersecurity controls building on horizontal frameworks (NIS2 Article 21(2) + ISO/IEC 27001 + IEC 62443) but adapted to the electricity sector + cross-border flow...

NCCS-Art.29_30_31 · Common electricity cybersecurity framework and minimum cybersecurity controls (NCCS Articles 29-31) - for high-impact entities

International cybersecurity coordination for aviation covers: (a) EASA Part-IS (EU Commission Implementing Regulation 2023/203) - the EU equivalent of FAA aviation cybersecurity framework, mandatory for EU-registered aircraft + operators + service providers +...

FAA-CSA-International · Coordination with EASA Part-IS, ICAO AVSEC and International Cybersecurity Frameworks

Operate HIPAA Security Rule compliance using NIST SP 800-66 Rev 2 as the bridge to broader NIST cybersecurity guidance per Chapter 5 of SP 800-66 Rev 2.

NISTSP66-8 · Integration with NIST RMF, Cybersecurity Framework, and OCR Enforcement Posture

Incidents are contained. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

NIST-CSF-RS.MI-01 · Incidents are contained
HKMA SPM3 controls

HKMA Supervisory Policy Manual (SPM) umbrella structure. SPM is the foundational HKMA supervisory framework + collection of ~60+ supervisory policy modules organised by subject area;

HKMA-SPM-Umbrella-60Modules-Structure · HKMA SPM Umbrella Structure, ~60 Modules Organised by Topic, Module Numbering and Versioning

Questions people ask about cybersecurity framework

What is Cybersecurity Framework?
A structured set of guidelines and best practices for managing cybersecurity risk, helping organizations assess and improve their security posture.
Why is Cybersecurity Framework important for compliance?
Cybersecurity Framework is a key concept in Information Security. Understanding cybersecurity framework helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Cybersecurity Framework?
Cybersecurity Framework appears in the requirement text of EU Network Code on Cybersecurity for the Electricity Sector, FAA Cybersecurity Framework for Aviation, NIST SP 800-66, NIST Cybersecurity Framework 2.0, HKMA SPM. Across these standards we have identified 44 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Cybersecurity Framework?
Explore our compliance framework pages to see how cybersecurity framework applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Cybersecurity Framework applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.