FRAMEWORKS
NOT A CERTIFICATION
These frameworks guide how we assess, prioritize, operate, and report. They are not represented as a certification or a guarantee of compliance.
NIST CSF 2.0
GOVERN
IDENTIFY
PROTECT
DETECT
RESPOND
RECOVER
Establish accountability, policy, risk ownership, supplier expectations, and leadership oversight.
Maintain accurate knowledge of systems, data, users, vendors, critical processes, and external exposure.
Apply practical safeguards for identity, endpoints, email, network access, data, backup, and workforce behavior.
Collect useful security signals and ensure high-severity events are reviewed and acted on.
Maintain defined escalation paths, evidence-preservation practices, communications, and incident procedures.
Validate recoverability, continuity priorities, recovery objectives, and lessons learned.
CIS CONTROLS v8
The practical control floor.
CIS Controls v8 turns the framework into repeatable, technical work. It is a practical baseline for reducing common attack paths and proving that safeguards are operating.
IG1 — ESSENTIAL
IG2 — RISK-BASED
IG3 — ADVANCED
INVENTORY
Know which devices, software, accounts, services, and internet-facing assets exist.
HARDENING
Standardize secure configurations for Microsoft 365, Active Directory, endpoints, firewalls, remote access, and business applications.
VALIDATION
Use vulnerability management, alert review, access review, patch evidence, and backup restore testing to verify control operation.
REPORTING
Track coverage, control exceptions, remediation status, unresolved risk, and recovery-test outcomes.
THE PRACTICAL RESULT
The result is not a binder of policies. It is a documented, measurable operating model that connects technical safeguards to leadership decisions, insurer questions, contractual expectations, and day-to-day business resilience.