ComplianceFrameworks
Structured control frameworks (ISO 27001, NIST CSF, CIS Controls) that map security/operational practices to auditable requirements.
Why we need this / what value this brings
Gives a structured checklist to build controls against, instead of guessing what 'secure enough' means.
When to use this
Once you're preparing for a specific external requirement (an enterprise partner's security questionnaire, a SOC2 audit).
How to use or implement this
Pick the framework the target audit/requirement actually asks for rather than adopting one speculatively.
Research questions
- Which framework, if any, would a future SOC2 audit actually be built on?
Empty folder — drop notes, links, and findings here as you research.