Cybersecurity Standards Scorecard (2025 Edition)
Why It Matters
Understanding which standards genuinely fit an organization’s risk profile prevents costly misalignments and ensures security investments deliver measurable, regulator‑approved outcomes.
Key Takeaways
- •Over 120 cyber security standards exist, complicating compliance choices.
- •Organizations often pick familiar frameworks over appropriate ones, causing gaps.
- •SANS upgraded scoring methodology to a database-driven, scalable system.
- •AI hype should not distract from fundamental safeguards like patch management.
- •Clear target state and framework selection essential for effective risk communication.
Summary
The webcast, hosted by veteran SANS instructor James Troll, introduces the 2025 edition of the Cybersecurity Standards Scorecard – an annual research effort that catalogues and evaluates the growing universe of cyber‑security frameworks. Troll notes that the SANS database now tracks roughly 120‑plus standards, a dramatic rise from the handful of frameworks organizations once could simply adopt. Key insights from the presentation highlight the practical challenges of this proliferation. Companies frequently default to familiar names such as NIST or CIS, even when those frameworks do not align with specific initiatives like DevOps, leading to compliance gaps. The discussion also warns against letting AI hype eclipse core controls, citing recurring deficiencies in application control and third‑party patch management across assessments. Troll illustrates his points with vivid analogies – comparing organizations to hikers distracted by side trails – and recounts a recent client who insisted on using the NIS CSF for a DevOps review despite its lack of relevant safeguards. He also references the consistent omission of basic safeguards, reinforcing the need for a disciplined, destination‑focused approach. The implications are clear: leaders must define a concrete target state, select frameworks that truly address their risk profile, and leverage SANS’s upgraded, database‑driven scoring methodology to communicate progress to stakeholders. By prioritizing fundamentals over shiny trends, firms can streamline compliance, reduce audit fatigue, and better align security investments with business objectives.
Comments
Want to join the conversation?
Loading comments...