Practical perspectives from the GSC team. New articles are published here. Below are curated references to the authoritative frameworks and programs our work aligns to. For tailored guidance, request a consultation.
Curated frameworks & references
Authoritative external references our work aligns to. Links open the issuing organizations’ sites. GSC is not affiliated with or endorsed by these organizations.
NIST Cybersecurity Framework 2.0
A voluntary framework of standards, guidelines, and best practices to manage cybersecurity risk.
Visit resourceNIST SP 800-53
Security and privacy controls for information systems and organizations.
Visit resourceRisk Management Framework (RMF)
NIST SP 800-37 process for managing security and privacy risk across the system lifecycle.
Visit resourceCISA Zero Trust Maturity Model
CISA guidance for advancing Zero Trust across identity, devices, networks, applications, and data.
Visit resourceFedRAMP
The U.S. government program providing a standardized approach to authorizing cloud services.
Visit resourceNIST SP 800-171
Protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.
Visit resource