Which framework?

Which security compliance framework is best for your business? There are multiple options of security frameworks to base your good security practices on.

But which one is best suited for your organisation?

This blog gives very high level guidance so you can start the process of selecting the most effective and efficient framework for your organisation.

The following questions should give you insight into a framework that best suits your security needs.

“Framework” In this blog is being used interchangeably with other words such as standards and benchmarks.

This blog talks to the most recognisable frameworks and gives general guidance to help you ask the right questions of your consultant or auditing firm. They can assess your organisation in detail to ensure you implement the correct framework.

Do any of the following questions relate to your security needs? Drill down and see what framework Governix recommends you look into.


Security Compliance Frameworks at a glance


*Costs can be hidden if a manager or staff member is maintaining policies and processes, working above the normal salary week hours.

Framework links:

NCSC minimum standards ASD Essential 8

NIST-CSF and SP 800-53‍ ‍PSR and the NZISM

ISO/IEC 27000 series - Standards must be purchased, ~NZ$320 each

PCI-DSS‍ ‍CIS Benchmarks

Costs can be higher if service providers are used in lieu of internal staff members:

$ - Internal staff, 1FTE or shared across staff, some tooling

$$ - Internal staff, 1-2+ FTE, security specialist, monitoring and protection tools

$$$ - Annual audits <$25k and internal staff, 2+ FTE, security specialists, technical specialists, executive, suite of security tooling.


Common Overseas frameworks


SOC Type II: Commonly used for verifying the effectiveness of security controls for service providers. 

GDPR (General Data Protection Regulation): A key privacy regulation for organisations processing the data of EU citizens.

The Cyber Resilience Act: A specific piece of legislation in Europe addressing security and product regulation.

The Privacy Act’s of each jurisdiction; Australia’s is Privacy Act 1988, which contains 13 Australian Privacy Principles.

Privacy Impact Assessments are the initial task to undertake to confirm compliance. Talk to our partner PrivSec for more information.

The National Cyber Security Centre (NCSC) in the UK, provides resources like the Cyber Essentials scheme.

Get in touch today to talk about a plan to implement any of the frameworks discussed in this blog.

Next
Next

Security Due Diligence