Frameworks and Assessment Tools
Frameworks and Assessment Tools
Below is a list of more cyber security frameworks and tools assessment information that can help you
establish a better security standard for your organization. These both go hand in hand and can be
applied in either order depending on where you are in your cyber security journey. Assessing your
network using some various tools will allow you to choose one or more frameworks that can assist
you and strengthen your cyber security posture. Also, after implementing these frameworks you can
then again use the tools to test and evaluate implementation and possible changes and growth that
needs to be addressed.
a. Security Frameworks and Implementation Guidance- These are some of the current
frameworks and guidance for implementing frameworks. Developing frameworks will
allow organizations to follow an organized path toward hardening their systems and
increasing overall security and recovery.
i. CIS- https://www.cisecurity.org/controls/
ii. FCC Security Planner- https://www.fcc.gov/cyberplanner
iii. ISO 27001- https://www.iso.org/isoiec-27001-information-security.html
iv. NIST-800-53-https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-
53r4.pdf
v. NIST CI Resources- https://www.nist.gov/cyberframework/critical-
infrastructure-resources
vi. COBIT-5 https://www.isaca.org/
vii. DOE Framework Implementation guide -
http://energy.gov/oe/downloads/energy-sector-cybersecurity-framework-
implementation-guidance
2. Self-Assessment tools - Below is a list of tools that are available to organizations that provide
testing and assessments of your current security posture.
c. On-Site Assessment Tools that will help mature and established cybersecurity program.
(Low-Level/Mature)