Hermes Wiki

ComplianceFrameworks

Structured control frameworks (ISO 27001, NIST CSF, CIS Controls) that map security/operational practices to auditable requirements.

Why we need this / what value this brings

Gives a structured checklist to build controls against, instead of guessing what 'secure enough' means.

When to use this

Once you're preparing for a specific external requirement (an enterprise partner's security questionnaire, a SOC2 audit).

How to use or implement this

Pick the framework the target audit/requirement actually asks for rather than adopting one speculatively.

Research questions

  • Which framework, if any, would a future SOC2 audit actually be built on?

Empty folder — drop notes, links, and findings here as you research.

Hermes Wiki