Security Control Frameworks

In marked contrast with many of the frameworks just reviewed, security control frameworks (SCFs) provide the framework publishers' minimum acceptable practices for implementation and operation of security controls within their span of activities.

2 slides · 1 min read · Domain 1

Slide 1

Banking and payment card systems builders, for example, need to be using SWIFT's Customer Security Controls Framework, or the PCI DSS, as they plan, install, and securely operate their information systems.

Cloud Security Alliance offers an Internet of Things SCF. HITRUST, NIST, COBIT, and Center for Internet Security (CIS) controls all have frameworks that can be used both as detailed shopping guides, as well as implementation checklists. GDPR, HIPAA, and other laws and regulations also set requirements that flow down into SCFs.

Adoption and implementation of SCFs is somewhat uneven, not only across different industries but also within them. Industrial controls, in particular, critical to many industries, do not have SCFs that provide effective guidance.

For a security professional, operationalizing use of a security control framework can take two different directions. If compliance requirements already exist for the organization regarding an SCF, then they've got a solid set of checklists and guidance information to use. If there is no such compliance need that explicitly directs, they should pick an SCF that seems to fit with their organization's business, markets, or activities, and use it as a source of best practice advice and ideas, particularly for areas where the organization's security may need improvement. Gap analysis can provide a semi-structured approach to using an SCF as an evaluation and assessment tool. This would produce a set of findings that indicate where the organization's information security controls do not deliver as robustly as what the SCF requires or recommends.

Test this domain