← Architect · Master
Lesson 3 of 412 min

Compliance frameworks decoded

NIST (National Institute of Standards and Technology) CSF (Cybersecurity Framework), CIS (Center for Internet Security) Controls, ISO (International Organization for Standardization) 27001, SOC (Security Operations Center) 2, HIPAA (Health Insurance Portability and Accountability Act), PCI (Payment Card Industry)-DSS — what they actually demand.

Close-up of computer hardware components on a workbench
Photo by Anete Lusina on Pexels

NIST CSF (Identify/Protect/Detect/Respond/Recover) is the mental model. CIS Controls are the prioritized 'do these first' list.

SOC 2 audits operating effectiveness of controls over time. ISO 27001 certifies an Information Security Management System.

Map your existing controls to the framework; don't rebuild from scratch.

Key takeaways

Next: Observability — metrics, logs, traces →