control framework

term

governance & risk

A published set of controls used as a common reference - so an organisation can describe what it does in terms others recognise.

Its value is shared vocabulary rather than novelty: nothing in a framework is unknown to a competent practitioner, and the point is that a customer, an insurer and a regulator can all read the same map. The failure is adopting one as a to-do list, which produces uniform coverage rather than defence where it is needed. Frameworks describe what to consider, and the organisation still has to decide what its own risk demands.

Also known as: nist csf, cis controls

All glossary entries