Which framework?
Which security compliance framework is best for your business? There are multiple options of security frameworks to base your good security practices on.
But which one is best suited for your organisation?
This blog gives very high level guidance so you can start the process of selecting the most effective and efficient framework for your organisation.
The following questions should give you insight into a framework that best suits your security needs.
“Framework” In this blog is being used interchangeably with other words such as standards and benchmarks.
This blog talks to the most recognisable frameworks and gives general guidance to help you ask the right questions of your consultant or auditing firm. They can assess your organisation in detail to ensure you implement the correct framework.
Do any of the following questions relate to your security needs? Drill down and see what framework Governix recommends you look into.
-
Comply with the PSR and NZISM governed by the NCSC Cyber Security Framework and the Standards.
-
Implement ISO27k (or the ISO/IEC 27000 series) the family of international standards for information security. Internal auditors can provide compliance testing and recommendations. External auditors who are accredited can provide a certificate of compliance. This is perfect for sales and marketing of your product or services.
-
PCI-DSS, usually paired with another policy standard for structure and governance. Enforced by major credit card brands, usually through your bank. There are different compliance scales and different types of assessment.
-
This may become more prolific in. NZ with initiatives like Critical Infrastructure Regulation. Best fit frameworks are NIST or NCSC Cyber Security Framework.
-
As a starting point the minimum cyber security standards under the NCSC Cyber Security Framework or Australia’s The ASD Essential 8 are best to implement. Then it depends on the level of requirements in your insurance policy if further standards need to be implemented.
-
Ensure you understand any obligations of the Privacy laws and breach notification regulations. Plus any IT and Security requirements of industry regulation. Common examples include; GDPR, The Cyber Resilience Act in Europe. SOC Type II in the USA.
-
Industries well known to have regulation include Banking, financial services, Telecommunications, Energy and utilities sector. Publicly listed companies and many others. Understand the requirements. At Governix we have experience is many industries with compliance, get in touch today.
-
NZISM technical controls are important to adhere to. Typically government agencies will require you to provide evidence of security measures, it could be completing a questionnaire or more formal evidence.
Security Compliance Frameworks at a glance
*Costs can be hidden if a manager or staff member is maintaining policies and processes, working above the normal salary week hours.
Framework links:
NCSC minimum standards ASD Essential 8
NIST-CSF and SP 800-53 PSR and the NZISM
ISO/IEC 27000 series - Standards must be purchased, ~NZ$320 each
Costs can be higher if service providers are used in lieu of internal staff members:
$ - Internal staff, 1FTE or shared across staff, some tooling
$$ - Internal staff, 1-2+ FTE, security specialist, monitoring and protection tools
$$$ - Annual audits <$25k and internal staff, 2+ FTE, security specialists, technical specialists, executive, suite of security tooling.
Common Overseas frameworks
SOC Type II: Commonly used for verifying the effectiveness of security controls for service providers.
GDPR (General Data Protection Regulation): A key privacy regulation for organisations processing the data of EU citizens.
The Cyber Resilience Act: A specific piece of legislation in Europe addressing security and product regulation.
The Privacy Act’s of each jurisdiction; Australia’s is Privacy Act 1988, which contains 13 Australian Privacy Principles.
Privacy Impact Assessments are the initial task to undertake to confirm compliance. Talk to our partner PrivSec for more information.
The National Cyber Security Centre (NCSC) in the UK, provides resources like the Cyber Essentials scheme.
Get in touch today to talk about a plan to implement any of the frameworks discussed in this blog.