TautSec logo

Frameworks

Download framework guides for SMB teams

The right framework depends on your operating model, risk profile, and reporting needs. Use this page to compare options and download practical quick guides.

Did You Know?

Directors of companies have obligations to protect personal information by detecting breaches, identifying data loss, responding and restoring in the event of a cyber incident, and reporting breaches to governing bodies within legislated timeframes.

What Are The Main Frameworks?

The NIST cyber security controls are extensive. ISO sets auditable security standards. Essential Eight are the highest priorities from regulators in Australia. CIS is a benchmark defined by a global IT community.

Framework overlap diagram

NIST CSF

National Institute of Standards and Technology Cyber Security Framework

ISO 27001

International Organization for Standardization

ACSC Essential Eight

Australian Cyber Security Centre baseline controls

CIS Controls

Center for Internet Security benchmark

NIST CSF

Comprehensive risk-aligned structure for identifying, protecting, detecting, responding, and recovering.

ISO 27001

Governance and management-system approach for information security controls and assurance.

ACSC Essential Eight

High-impact mitigation baseline designed to reduce common cyber attack pathways.

Framework comparison

Category
NISTNIST
ACSCACSC
ISOISO
WhoWho
Large Corporations / US DoD / Australian GovernanceSmall to Medium EnterpriseIPO, Large Corporations, Defence, Government
WhatWhat
Risk Management FrameworkMinimum Controls for Maximum ImpactStandardised Controls with Audits
BenefitBenefit
Flexible, customisable, robustEasy to implement, 85% mitigationSimplifies mergers and partnerships
OutcomesOutcomes
Optimum cyber security postureMinimum cyber security postureEffective cyber security posture
ProsPros
Largest set of controlsSimplest set of controlsStandardised certification
ConsCons
Subject to correct interpretationGaps in controlsComplex and costly

Need help choosing a framework pathway?

Start with a free scan to get a practical exposure summary and prioritised actions mapped to your next-step goals.