CIS CSC
Center for Internet Security
Cybersecurity best practices
For small and large businesses
Applicable and practical
NIST RMF
For federal government and military
NIST CSF
For commercial applications
ISO/IEC 27001
Management systems
ISO/IEC 27002
Controls
ISO/IEC 27701
Privacy
ISO/IEC 31000
Risk management
SSAE SOC 2 type 1
Audit of a single point in time
SSAE SOC 2 type 2
Audit long term like 6 months
CSA CCM
Cloud framework