NIST Cybersecurity Framework 2.0 The NIST Cybersecurity Framework 2.0, released in February 2024, provides outcomes-based guidance for managing cybersecurity risk.

CIS Critical Security Controls v8.1 The CIS Critical Security Controls v8.1 organizes practical defensive measures into 18 Controls and a more detailed set of Safeguards.

FISMA and the NIST Risk Management Framework The Federal Information Security Modernization Act, or FISMA, requires U.S. federal agencies to maintain agency-wide information security programs.

NIST SP 800-53 provides the control catalog, while the NIST Risk Management Framework sets out a seven-step process: Prepare Categorize Select Implement Assess Authorize Monitor.

The real goal is defensible, continuous risk management Frameworks, certifications, and reports provide valuable structure and evidence.