home  /  standard of care  /  frameworks & benchmarking
the standard · cybersecurity incidents

Frameworks and benchmarking.

A framework is evidence of what the profession accepts. It is not a verdict, and both sides overclaim it.

begin here

What happened, and when did you learn of it?

Start a conversation with the Incident Concierge, already scoped to frameworks & benchmarking. Pick a starting point, or describe the incident directly.

Incident Conciergeframeworks & benchmarking · orientation, not a security opinion
Tell me which framework the organization adopted, if any, and what sector it is in — that decides which benchmark is credible. I'll help you see how the comparison is normally run.

In a breach dispute, published frameworks do a job no individual expert can do alone: they establish what the profession collectively regards as accepted practice, which is otherwise a matter of duelling opinion. That makes them genuinely valuable evidence. It also makes them systematically overclaimed. A defendant argues that alignment with a framework demonstrates reasonableness; a plaintiff argues that any gap against it demonstrates the opposite. Both readings misunderstand what these documents are. They are risk-management structures that explicitly require an organization to decide which controls fit its circumstances — so the evidentiary weight sits not in the mapping but in the reasoning behind the mapping, and in whether that reasoning was recorded before the incident or reconstructed after it.

mechanisms

What each framework is, and is for.

They are not interchangeable, and using the wrong one as a benchmark is an easy way to lose credibility.

NIST Cybersecurity Framework

Risk-outcome structure, widely referenced by regulators and courts. Descriptive, not prescriptive.

ISO/IEC 27001

A certifiable management-system standard. Certification is meaningful evidence of process, not of control efficacy.

CIS Controls

Prioritized, concrete and tiered by organization size. Often the most useful benchmark for smaller entities.

Sector regimes

HIPAA Security Rule, PCI DSS, GLBA Safeguards, NYDFS. Where one applies, it usually sets the floor.

Peer practice

What comparable organizations actually did. Harder to establish and often the most persuasive benchmark.

The mapping gap

A control marked "implemented" in a spreadsheet and a control actually working are different findings.

methodology

What the evidence shows — and what we examine.

How benchmarking is done credibly.

Pick the right benchmarkA framework the organization actually adopted, or one demonstrably standard for its sector.
Test implementation, not attestationWhether the control operated, evidenced by logs and configuration rather than a maturity score.
Trace the exceptionsWhich controls were consciously not implemented, and what reasoning was recorded at the time.
Match the version to the dateFrameworks are revised. The applicable benchmark is the one current when the decisions were made.
what's at stake

What benchmarking decides.

Whether "accepted practice" is established as a fact, or remains one expert’s opinion.

whether accepted practice is established credibility of the expert opinion what documentation matters most regulatory alignment which expertise the matter needs how quickly a position can be assessed

Attestation is not implementation.

A control marked "implemented" in a compliance spreadsheet, and a control whose operation is evidenced by configuration and logs, are different findings. The gap between them is where a great many breach cases are actually decided.

common questions

Frameworks — practical questions.

We were ISO 27001 certified. Is that a defense?

It is strong evidence and it is not a defense in itself. Certification shows an information security management system existed, was documented and passed audit — meaningful, because many breached organizations cannot show that. But ISO certifies the management process rather than certifying that every control operated effectively on the day, and its scope statement matters enormously: a certification covering one business unit says little about the environment that was actually compromised. The first question a competent opponent asks is what the scope covered.

Which framework should we be benchmarked against?

Ordinarily the one the organization adopted, and failing that the one demonstrably standard for its sector and size. Where a sector regime applies — the HIPAA Security Rule, PCI DSS, the GLBA Safeguards Rule, NYDFS Part 500 — that generally sets the floor and arguing for a lighter benchmark is not usually productive. For an organization with no formal program, the CIS Controls are often the fairest reference because they are tiered explicitly by organization size rather than assuming enterprise resources.

How are gaps against a framework used?

As the spine of the plaintiff's case, usually, and they are most effective when the gap is both basic and known. A missing control the organization never considered is one thing; a missing control its own assessment flagged, costed and deferred is considerably worse, because it converts a negligence argument into a documented decision. The defense response is normally proportionality — that the control was not warranted by the risk — which is a real argument but only if the reasoning was recorded at the time rather than assembled for the litigation.

Does a framework tell us what we should have spent?

No, and that is a genuine limitation worth stating plainly rather than papering over. Frameworks describe controls, not budgets, and none of them answers how much security an organization of a given size and risk profile ought to have bought. That question resolves into the proportionality analysis and, ultimately, into expert judgment about sector practice. It is also where standard-of-care opinions differ most sharply between competent experts, which is worth knowing before assuming the analysis will be tidy.

related

Related specialization areas & resources.

Benchmark against the right thing.

Describe the program and the sector. The Institute will help you choose the benchmark.

incident conciergeorientation · not a security opinion
Tell me which framework the organization adopted, if any, and what sector it is in — that decides which benchmark is credible. I'll help you see how the comparison is normally run.