How to choose the right cybersecurity framework

Does your organization need NIST, CSC, ISO, or FAIR frameworks? Here’s how to start making sense of security frameworks.
Cybersecurity professionals often face the curse of knowledge—understanding so much about cybersecurity that it is difficult to communicate about it in simple terms to those outside the field. But cybersecurity frameworks can make it easier for everyone in the business to understand, comprehend, and communicate about security, Frank Kim, founder of security consulting firm ThinkSec and curriculum director at the SANS Institute, said in a Wednesday session at RSA 2019.
The problem with common security frameworks is they often involve long PDFs that can lead to more confusion, Kim said. To make cybersecurity frameworks easier to understand, he separated them into three categories: Control frameworks, program frameworks, and risk frameworks.
Kim used the analogy of a person becoming a chef to describe each of these frameworks. Before a chef starts to cook, they must build a list of ingredients for their food—the control framework. Then, they need to determine the recipe to assemble those ingredients into a meal—the program framework. Finally, they need to figure out where they are going to serve that meal, in terms of what their customers want in a restaurant experience—the risk framework.
Here are the three types of security frameworks, explained:
Often times, when a security professional enters a new environment to build and manage a team, they are dealing with an organization that is relatively immature from an IT and security perspective, Kim said. In those cases, they want to determine the basic set of controls to implement.
Cybersecurity professionals use control frameworks to do the following, according to Kim:
NIST SP 800-53 is a comprehensive control catalog of security and privacy controls, in which control can be implemented based on priority or secure control baselines (low impact, moderate impact, or high impact).


