6 posts found
31 August 2026 · By P LarnerBlog post
ISO 31000, NIST CSF 2.0, ISO 27005, COSO ERM and FAIR. What each is genuinely good at, where each is the wrong tool, and how to choose one on purpose.
Frameworks & Standards#ISO 27005#FAIR#risk frameworks#ISO 31000#NIST CSF#COSO ERM
Read more →14 August 2026 · By P LarnerBlog post
The three CMMC 2.0 levels, what pushes you from one to the next, and why self-assessment is not the soft option for UK suppliers to US defence.
Frameworks & Standards#CMMC#NIST SP 800-171#DFARS#CUI#defence supply chain
Read more →12 August 2026 · By P LarnerBlog post
The six functions of NIST CSF 2.0 in plain terms, what the new Govern function changed, and how a three-person team runs an assessment in two weeks.
Frameworks & Standards#cyber security framework#maturity#governance#profiles#NIST CSF
Read more →11 August 2026 · By P LarnerBlog post
Ninety-three broad controls or a thousand fine-grained ones. How Annex A and SP 800-53 differ, and how to let the audience that must trust you choose.
Frameworks & Standards#Annex A#control sets#NIST SP 800-53#ISO 27001#FedRAMP
Read more →10 August 2026 · By P LarnerBlog post
How the NCSC Cyber Assessment Framework actually works, from the four objectives and 41 outcomes to the not-achieved indicators that veto everything else.
Frameworks & Standards#GovAssure#critical national infrastructure#NIS Regulations#CAF#NCSC
Read more →2 August 2026 · By P LarnerBlog post
What the UK Cyber Security Council is, the four titles, which specialisms are actually open, what the assessment involves, and the annual CPD that keeps it.
Frameworks & Standards#CIISec#professional registration#CPD#ChCSP#chartership#UK Cyber Security Council
Read more →