Vai al contenuto
← Compliance, ethics and future trends

Lezione 1 di 4 · 8 min

Security frameworks: NIST CSF 2.0, ISO/IEC 27001 and MITRE ATT&CK

Three frameworks you will hear about constantly, what each one is for, and how they fit together without overlapping.

Per ora questa pagina è in inglese.

Security work can feel like an endless list of things to do. Frameworks turn that list into a structure: they tell an organization what good looks like, how to organize its efforts, and how to talk about attacks in a shared language. Three are worth knowing by name, because they answer three different questions: what should we manage (NIST CSF), how do we run it as a system (ISO/IEC 27001), and how do attackers actually behave (MITRE ATT&CK).

NIST Cybersecurity Framework 2.0: the map of outcomes

The Cybersecurity Framework from the US National Institute of Standards and Technology is voluntary and free, and it is used well beyond the United States. Version 2.0, published in February 2024, organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern is new in 2.0 and puts cybersecurity strategy, roles and supply-chain risk at the center, a recognition that security failures are often management failures. Each function breaks down into categories and outcomes, for example knowing your assets, managing identities, or restoring from backup, without prescribing specific products.

The strength of the CSF is that it scales. A large bank and a five-person charity can use the same six functions to ask the same questions at very different levels of detail. NIST also publishes quick-start guides for small businesses.

CSF 2.0 also offers two tools to make this concrete. Profiles describe an organization’s current security posture and its target posture, so the gap between them becomes a to-do list. Tiers, from Partial through Risk Informed and Repeatable to Adaptive, describe how rigorous and well integrated its risk management practices are. Neither is a score to show off: they are ways to decide what to improve next. A small organization can sketch a useful profile on a single page, one line per function, and revisit it once a year.

Govern at the center, surrounded by Identify, Protect, Detect, Respond and Recover, the six functions of NIST CSF 2.0.
CSF 2.0 places the new Govern function at the center of the five original functions.

ISO/IEC 27001: running security as a management system

ISO/IEC 27001 is an international standard for an information security management system (ISMS): a documented, repeatable way to assess risks, choose controls, and review whether they work. Its current edition dates from 2022, and its Annex A lists 93 controls grouped into four themes: organizational, people, physical and technological. What sets it apart is that organizations can be audited against it by an accredited body and receive a certificate, which is why it often appears in contracts and supplier questionnaires.

A certificate proves that a management system exists and was audited, not that every system in the organization is secure. It is a signal of discipline, not a guarantee.

MITRE ATT&CK: the language of attacker behavior

MITRE ATT&CK is a free knowledge base of adversary tactics and techniques based on real-world observations. Tactics are the attacker’s goals, such as initial access, persistence, credential access or exfiltration; techniques are the ways they reach those goals, each with an identifier (for example, phishing is T1566). Defenders use it to check which techniques their tools can actually detect, threat-intelligence teams use it to describe campaigns precisely, and red teams use it to plan realistic exercises. There are matrices for enterprise systems, including macOS, as well as for mobile and industrial systems.

How the three fit together

FrameworkQuestion it answersTypical use
NIST CSF 2.0What outcomes should our security program achieve?Strategy, gap assessment, board reporting
ISO/IEC 27001How do we run security as an auditable system?Governance, contracts, external audits
MITRE ATT&CKHow do real attackers operate, and can we see them?Detection engineering, threat hunting, exercises

For an individual or a small team, the practical takeaway is to borrow the structure, not the paperwork. Know what you have (Identify), protect accounts and devices (Protect), make sure you would notice something wrong (Detect), know who to call (Respond), and have backups you have actually tested (Recover).

Da ricordare

  • NIST CSF 2.0 organizes security into six functions: Govern, Identify, Protect, Detect, Respond, Recover.
  • ISO/IEC 27001 defines an auditable information security management system with 93 Annex A controls.
  • MITRE ATT&CK catalogs real attacker tactics and techniques, each with an identifier.
  • A certificate proves a management system exists, not that everything is secure.

Mettiti alla prova

  1. 1. Which function was added in NIST CSF 2.0?

    • Detect
    • Govern — Esatto.
    • Recover
    • Encrypt

    CSF 2.0 (2024) added Govern to the original five functions, putting strategy, roles and supply-chain risk at the center.

  2. 2. What is MITRE ATT&CK mainly used for?

    • Certifying companies
    • Describing and detecting real attacker behavior with shared technique identifiers — Esatto.
    • Encrypting network traffic
    • Replacing antivirus software

    ATT&CK is a knowledge base of observed tactics and techniques used for detection, threat intelligence and exercises.

  3. 3. A supplier says it is ISO/IEC 27001 certified. What does that prove?

    • It has never been breached
    • Its information security management system was audited against the standard — Esatto.
    • All its software is bug-free
    • It follows US law

    Certification attests to an audited management system; it is evidence of discipline, not a guarantee against incidents.

Mettilo in pratica con FireAI

Metti in pratica questa lezione sul tuo Mac.

Fonti

Mettilo in pratica sul tuo Mac

Prova tutte le funzioni gratis per 17 giorni, senza carta.

Scarica per Mac Guide