What you’ll be able to do
- Map a Riverstone risk to a CSF 2.0 function and an outcome statement.
- Choose a CIS Implementation Group 1 mindset for a first control set without claiming certification.
- Say what ISO/IEC 27001 and NIST SP 800-53 are, in one sentence each, and open the card instead of copying a catalog.
- Write the evidence you would keep so a later reviewer can see the control working.
Outcomes first
A framework is a way to talk about outcomes and organize work. It is not a trophy. NIST CSF 2.0 gives six functions (Govern, Identify, Protect, Detect, Respond, Recover) plus Organizational Profiles and Tiers. Riverstone can say: we need to Identify internet-facing appliances, Protect driver authentication, Detect unusual exports, Respond with reversible account disables, Recover YardOS from immutable copies, and Govern who owns each of those sentences. That is an outcome conversation.
Start with the loss from F1 and the uncertainty from F2. The function name organizes who owns the sentence. It does not finish the work, and it does not pick a product.
A small starting set, and the evidence line
CIS Controls v8.1 offers a prioritized set of Safeguards grouped into Implementation Groups. Implementation Group 1 (IG1) is essential cyber hygiene for a small foundational set: inventory, patching, account hygiene, and log retention as a starting discipline. It is not a certificate that attackers will honor. The evidence line is the record that shows the control ran, such as a patch timestamp, an MFA enrollment report, or the last restore test.
ISO/IEC 27001 is a certifiable management-system standard for a scoped information security management system; open the card instead of copying control text. NIST SP 800-53 is a broad security and privacy control catalog you select and tailor from; open the card instead of reprinting families.
Worked mapping: the VPN and the export
Risk: opportunistic exploitation of the internet-facing VPN leading to driver-account abuse and customer-address disclosure. CSF: Identify assets (the appliance), Protect (patch, MFA, least privilege), Detect (impossible travel plus export alerts), Respond (revoke sessions), Recover (if YardOS is later hit). CIS IG1-minded actions: inventory, patching, account hygiene, log retention. Evidence: KEV ticket, patch timestamp, MFA enrollment report, sample export authorization tests, last restore test.
A framework card is not permission to skip the uncertainty line: we still do not know whether a geofence already limits VPN logins. Write that too. If a named gap still needs a product capability, that reading is the optional next lesson. It is not required to finish this closer, and it is not required to start SOC practice.
CHECK YOUR JUDGMENT
Leadership wants to “get compliant with CSF” after the contractor export scare and asks Maya to print ISO control text into a binder. What is the sound first move?
NEXT FIELD LESSON