Cybersecurity Standards and Frameworks
Santiago Paz · 2023
Cyber-attacks are the seventh most important risk facing the world, according to the Global Economic Forum (below mental health deterioration and above debt crises). They are also costly: the cost of cybercrime globally exceeded $6T (6,000,000,000,000,000,000) in 2021. Organizations must take actions to protect their assets and business. The use of Frameworks and Standards of Cybersecurity is a way to have a structured approach to implement protective actions and implement metrics to measure its effectiveness. This chapter deals with Cybersecurity Risk and review the most important frameworks and standards to manage it. In particular NIST Cybersecurity Framework, ISO/IEC 27000 family, CIS Critical Controls, and OWASP TOP 10, among others, it also describes the main cybersecurity organizational building blocks and main roles.