Skip to main content
Request Assessment

Framework Glossary

Security frameworks made useful for real decisions.

This glossary explains the reference models DataFence may use to structure scope, evidence, findings, remediation planning, secure delivery, and management communication.

Planning Reference Review vocabulary, not certification or endorsement.
  • Scope and evidence maps
  • Control and requirement coverage
  • Remediation sequence
  • Executive-ready summaries
Standards-aware scoping Plain-language outputs Traceable recommendations No unsupported badges

Knowledge Library

Start with the model that best matches the decision you need to make.

Each guide explains what the framework is, why it matters, how DataFence uses it, what client output may look like, and which services it supports.

NIST CSF

Security program and risk posture vocabulary.

Best for security posture, governance, risk communication, and current-to-target improvement planning.

Open NIST CSF Guide
OWASP ASVS

Application security verification requirements.

Best for application review, API security, authentication, access control, and release-readiness depth.

Open OWASP ASVS Guide
MITRE ATT&CK

Adversary behavior mapped to defense and detection.

Best for threat-informed review, exposure mapping, detection logic, and response improvement.

Open MITRE ATT&CK Guide
Secure SDLC

Security built into the software delivery lifecycle.

Best for release guardrails, backlog discipline, dependency review, architecture checkpoints, and handoff quality.

Open Secure SDLC Guide
CIS Controls

Prioritized safeguards for practical cyber hygiene.

Best for baseline control reviews, operational gaps, owner planning, and improvement sequencing.

Open CIS Controls Guide
ISO 27001

Information security management system structure.

Best for governance alignment, policy evidence, management-system readiness, and control-owner communication.

Open ISO 27001 Guide

How To Use This Library

Frameworks are useful when they make client decisions sharper.

DataFence uses these models as structured vocabulary for scope, evidence, risk, remediation, and operating discipline.

1

Clarify the decision.

Identify whether the work is program-level, application-level, threat-informed, lifecycle-focused, or management-system focused.

2

Map evidence.

Connect policies, systems, workflows, tickets, architecture, logs, and observed behavior to the right reference language.

3

Prioritize work.

Turn gaps into practical recommendations with sequence, ownership, and a client-facing output.

Reference Boundary

These guides are planning references.

They are not certifications, attestations, legal advice, compliance guarantees, regulator approvals, or claims of standards-body endorsement.

Next Step

Use the glossary to orient the conversation, then scope the active issue.

The right model depends on the decision, evidence, system, and operating environment involved.