Cybersecurity Standards Scorecard (2025 Edition)

SANS Institute
SANS InstituteMar 3, 2026

Why It Matters

Understanding which standards genuinely fit an organization’s risk profile prevents costly misalignments and ensures security investments deliver measurable, regulator‑approved outcomes.

Key Takeaways

  • Over 120 cyber security standards exist, complicating compliance choices.
  • Organizations often pick familiar frameworks over appropriate ones, causing gaps.
  • SANS upgraded scoring methodology to a database-driven, scalable system.
  • AI hype should not distract from fundamental safeguards like patch management.
  • Clear target state and framework selection essential for effective risk communication.

Summary

The webcast, hosted by veteran SANS instructor James Troll, introduces the 2025 edition of the Cybersecurity Standards Scorecard – an annual research effort that catalogues and evaluates the growing universe of cyber‑security frameworks. Troll notes that the SANS database now tracks roughly 120‑plus standards, a dramatic rise from the handful of frameworks organizations once could simply adopt. Key insights from the presentation highlight the practical challenges of this proliferation. Companies frequently default to familiar names such as NIST or CIS, even when those frameworks do not align with specific initiatives like DevOps, leading to compliance gaps. The discussion also warns against letting AI hype eclipse core controls, citing recurring deficiencies in application control and third‑party patch management across assessments. Troll illustrates his points with vivid analogies – comparing organizations to hikers distracted by side trails – and recounts a recent client who insisted on using the NIS CSF for a DevOps review despite its lack of relevant safeguards. He also references the consistent omission of basic safeguards, reinforcing the need for a disciplined, destination‑focused approach. The implications are clear: leaders must define a concrete target state, select frameworks that truly address their risk profile, and leverage SANS’s upgraded, database‑driven scoring methodology to communicate progress to stakeholders. By prioritizing fundamentals over shiny trends, firms can streamline compliance, reduce audit fatigue, and better align security investments with business objectives.

Original Description

In this webcast, James Tarala, Senior Faculty at the SANS Institute and Managing Partner at Cyverity, will explain the state of cybersecurity standards in 2025 with a scorecard comparison of popular standards based on specific, measurable research. This presentation is an annual report which will focus primarily on the changes to the cybersecurity standards space over the past year. He will also introduce a Cyber Rosetta Stone that simplifies building a cybersecurity control libraries across all the standards. Attendees will leave this webcast with a clear understanding of the differences and gaps in cybersecurity standards that will support their informed decisions about which standards to use when building their own cybersecurity programs.
Visit https://go.sans.org/wh4NBg to access the original presentation slides and unedited recording free of charge.
Learn more about James Tarala here, https://www.sans.org/profiles/james-tarala
This webcast supports content and knowledge from LDR519: Cybersecurity Risk Management and Compliance. To learn more about this course, explore upcoming sessions, and access your FREE preview, visit https://www.sans.org/ldr519

Comments

Want to join the conversation?

Loading comments...