San Antonio managed IT & cybersecurity · 24/7 support available for opt-in clients Call 210-979-1886  ·  info@nexgenguard.com
Resource Center

Cybersecurity frameworks

The recognized best practices behind how we protect businesses: what each framework is and how we use it.

A framework is a set of recognized best practices. Following one gives your security program structure and lets you measure progress. These four are the foundation of how we work.

NIST Cybersecurity Framework (CSF) 2.0

Published by: National Institute of Standards and Technology (NIST), February 2024. Cost: free and voluntary. Designed for organizations of every size and industry.

FunctionWhat it means for your business
GovernSet cybersecurity roles, responsibilities, policies and risk priorities.
IdentifyKnow your devices, software, data, vendors and risks.
ProtectPut safeguards in place: access control, training, data security, patching.
DetectFind and analyze possible attacks and suspicious activity.
RespondAct on a detected incident: contain it, communicate and fix it.
RecoverRestore systems and operations, and learn from what happened.

Why it matters: CSF gives a common language for evaluating where a business stands and what to improve next.

Official sources: NIST CSF 2.0 · NIST Small Business Quick-Start Guide (SP 1300)

CIS Critical Security Controls v8.1

Published by: Center for Internet Security (CIS), a nonprofit. 18 prioritized controls that turn strategy into specific technical safeguards. Implementation Group 1 (IG1) is the CIS-defined starting set of "essential cyber hygiene" safeguards for small and mid-sized organizations.

  1. 1Inventory and Control of Enterprise Assets
  2. 2Inventory and Control of Software Assets
  3. 3Data Protection
  4. 4Secure Configuration of Enterprise Assets and Software
  5. 5Account Management
  6. 6Access Control Management
  7. 7Continuous Vulnerability Management
  8. 8Audit Log Management
  9. 9Email and Web Browser Protections
  10. 10Malware Defenses
  11. 11Data Recovery
  12. 12Network Infrastructure Management
  13. 13Network Monitoring and Defense
  14. 14Security Awareness and Skills Training
  15. 15Service Provider Management
  16. 16Application Software Security
  17. 17Incident Response Management
  18. 18Penetration Testing

Why it matters: NIST CSF sets the strategy; CIS Controls tell you exactly what to implement and in what order. Our security baseline maps to these controls.

Official source: CIS Critical Security Controls

CISA cybersecurity guidance

Published by: Cybersecurity and Infrastructure Security Agency, part of the U.S. Department of Homeland Security. CISA is a guidance and alerting agency, not a compliance framework. It publishes:

  • Cybersecurity alerts and advisories on current threats.
  • The Known Exploited Vulnerabilities (KEV) catalog: flaws attackers are actively using, which should be patched first.
  • #StopRansomware prevention and response guidance.
  • Small business guidance on MFA, passwords, backups and incident response.

Official sources: CISA Cyber Guidance for Small Businesses · KEV Catalog · StopRansomware

ISO/IEC 27001:2022

Published by: International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC). An international standard for building and maintaining an Information Security Management System (ISMS): governance, risk assessment, access control, supplier management, incident management and continual improvement.

Why it matters: Larger customers and partners sometimes ask vendors to show formal security management. Organizations can align with ISO 27001 without being certified; certification requires an audit by an accredited certification body.

Official source: ISO/IEC 27001

"Aligned with" is not "certified in"

TermWhat it actually means
Aligned with / based on a frameworkPractices follow the framework's guidance. No outside audit is implied.
ISO/IEC 27001 certificationAn accredited certification body has audited the organization's ISMS.
SOC 2 reportAn attestation examination performed by an independent CPA firm under AICPA standards. It is a report, not a certification.
HIPAAThere is no official government HIPAA certification. Organizations perform risk analyses and may hire outside assessors.
CMMCA Department of Defense program. Depending on the contract, it requires a self-assessment or an assessment by an authorized third party.

Our position: NexGenGuard aligns its practices and recommendations with NIST CSF 2.0 and the CIS Controls. NexGenGuard is not ISO 27001 certified and does not hold a SOC 2 report.

Last reviewed: October 2026. Laws and standards change; always confirm with the official source.

Ready for IT that just works?

Book a free consultation or IT security audit. No sales team, no pressure — just straight answers.