Blog By: Kenneth Juhan
Date: August 12, 2026
Kenny Juhan will explain Security and reporting frameworks in the following blog.
Security Frameworks and Reporting: NIST CSF, CIS, CSA, and SOC 2
Security frameworks help organizations avoid building cybersecurity programs from scratch.
For SecurityX, candidates should understand the general purpose of benchmarks, foundational best practices, SOC 2, NIST CSF, CIS, and the Cloud Security Alliance.
The key is knowing when each is useful.
Benchmarks
Security benchmarks provide recommended configuration settings for systems and technologies.
Instead of every administrator deciding independently what a secure configuration looks like, organizations can compare systems against an established benchmark.
Think:
Benchmark = What should a secure configuration look like?
Benchmarks can improve consistency and make configuration auditing easier.
Foundational Best Practices
Not every organization has a mature security program.
Foundational best practices provide a starting point for establishing essential protections such as asset management, secure configurations, vulnerability management, access control, logging, and recovery.
SecurityX candidates should recognize that controls should match organizational maturity and risk.
SOC 2
SOC 2 reports provide information about controls at service organizations.
Customers may request a SOC 2 report when evaluating whether a service provider has appropriate controls.
This is especially useful during third-party risk assessments.
Think:
SOC 2 = Assurance about a service organization’s controls
NIST Cybersecurity Framework
The NIST Cybersecurity Framework (CSF) provides a structured approach for managing cybersecurity risk.
Its current structure organizes cybersecurity outcomes through major functions, including:
Govern → Identify → Protect → Detect → Respond → Recover
The framework can help organizations understand current capabilities, establish desired outcomes, and communicate cybersecurity risk.
Center for Internet Security
The Center for Internet Security (CIS) is well known for the CIS Controls and CIS Benchmarks.
CIS Benchmarks provide configuration recommendations for many operating systems, applications, cloud services, and other technologies.
For SecurityX:
CIS = Practical controls and secure configuration benchmarks
Cloud Security Alliance
The Cloud Security Alliance (CSA) focuses on cloud security.
CSA resources can help organizations evaluate cloud controls, cloud providers, and cloud-specific security risks.
If a SecurityX scenario specifically focuses on cloud governance or cloud security controls, CSA should stand out as a relevant organization.
Why This Matters for SecurityX
The easiest way to separate these concepts is by purpose:
Benchmark = Secure configuration target
SOC 2 = Service organization control assurance
NIST CSF = Cybersecurity risk-management framework
CIS = Practical security controls and benchmarks
CSA = Cloud-focused security guidance
SecurityX may give you several legitimate frameworks and ask which one BEST fits the scenario.
The trick is identifying what the organization needs.
Does it need a secure configuration?
A third-party assurance report?
A broad cybersecurity framework?
Cloud-specific guidance?
Once you determine the goal, selecting the appropriate framework becomes much easier.
Security professionals do not need to reinvent every security control. Frameworks and benchmarks provide tested structures that organizations can adapt to their own risk, technology, and business requirements.
Leave a comment