Security Standards
Prepare for standards-based security work with perspectives spanning implementation, controls, readiness and audit. Choose the relevant framework, check the current requirements and use the output to guide human review.
Whose challenge would strengthen the evidence?
Choose the perspective that fits the work. These are structured AI personas, not people or professional approval authorities. Give them the relevant facts and check what they produce.
CAF Assurance Lead (UK)
Helps structure CAF assessment preparation and examine the evidence behind a proposed conclusion. It doesn’t provide independent assurance.
CIS Controls v8 Lead (Global)
Uses the CIS Controls v8 perspective to help examine implementation priorities and the evidence needed to review them.
Cyber Essentials Compliance Lead (UK)
Helps prepare for Cyber Essentials work by examining readiness questions. Certification remains a separate process.
DORA Compliance Lead (EU)
Brings a DORA perspective to ICT-risk assessment preparation, helping identify what needs checking with qualified specialists and current sources.
FedRAMP Authorization Lead (US)
Helps prepare FedRAMP authorisation questions and supporting evidence. It isn’t an authorising body or an assurance provider.
ISO 27001 Implementation Lead (Global)
Helps plan and review an ISO 27001 implementation, including scope and the evidence needed before seeking certification.
ISO 27001 Lead Auditor (Global)
Examines ISO 27001 audit planning, evidence, reporting and follow-up. The persona is a preparation aid, not an independent auditor.
ISO 27005 Risk Management Lead (Global)
Uses the ISO 27005 perspective to help examine information-security risk assessment and treatment arrangements.
ISO 27017 Cloud Security Lead (Global)
Helps examine cloud-security controls from the ISO 27017 perspective, including the implementation questions to take into review.
NIS2 Compliance Lead
Brings a NIS2 perspective to assessment preparation. Verify jurisdiction, applicability and current requirements before making compliance decisions.
NIST 800-218 SSDF Lead (US)
Uses the NIST SSDF perspective to examine secure development practices across the software lifecycle.
NIST 800-53 Controls Lead (US)
Helps examine selection and implementation of NIST SP 800-53 controls in relation to the system’s risks.
NIST CSF 2.0 Lead (US)
Uses the NIST CSF 2.0 perspective to help organise a cybersecurity review and identify priorities for improvement.
OWASP SAMM Lead (Global)
Brings the OWASP SAMM perspective to reviewing software-assurance practices and planning improvements.
PCI DSS Compliance Lead (Global)
Helps prepare a PCI DSS review, including scope and supporting evidence. Assessment and compliance decisions require the appropriate people.
SOC 2 Readiness Lead (US-Native)
Helps organise SOC 2 readiness work and examine evidence against the relevant criteria, without claiming an audit opinion.
SOX Controls Lead (US-Native)
Brings a SOX controls perspective to financial-reporting control preparation and review, including the evidence behind management’s assertions.
Use more than one perspective before the evidence reaches a decision-maker.
Your subscription includes the whole library, so you can bring in another specialist when the work crosses into a different team, responsibility or decision.