Skip to content

Security Posture

What is Security Posture?

The overall cybersecurity strength and readiness of an organization, encompassing its security controls, policies, awareness, and ability to detect and respond to threats.

Information Security

Each of these is named in at least one of the same controls as security posture. The number is how many controls name both.

What the standards actually require on security posture

Requirements naming security posture across 6 standards, quoted from the control text.

Define and implement a security posture management strategy establishing policy, procedure and standards for security configuration management and vulnerability management.

ASBv3-GS-5 · Define and implement security posture management strategy

Maintain the security posture of third-party endpoints that reach organisational assets, using technical measures, contractual terms or both.

CCM-UEM-14 · Third-Party Endpoint Security Posture
NIST SP 800-2073 controls

Aggregates asset logs, network traffic, and resource access actions to provide near real-time feedback on the security posture of enterprise systems.

SP800-207-SUP-LOGS · Network and System Activity Logs
ISMAP (Japan)2 controls

ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...

ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC

Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-C...

LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15 · Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15

Implement Acquisition Development Maintenance + Supplier Relationships + Vulnerability Management per MTCS SS 584. Acquisition Development and Maintenance (ISO 27001 Annex A.14) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Co...

MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container · MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA

Questions people ask about security posture

What is Security Posture?
The overall cybersecurity strength and readiness of an organization, encompassing its security controls, policies, awareness, and ability to detect and respond to threats.
Why is Security Posture important for compliance?
Security Posture is a key concept in Information Security. Understanding security posture helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Posture?
Security Posture appears in the requirement text of Azure Security Benchmark, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, NIST SP 800-207, ISMAP (Japan), Lloyd's Minimum Standards - Cyber Security. Across these standards we have identified 11 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Posture?
Explore our compliance framework pages to see how security posture applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Posture applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.