Simon Mayes software engineer · founder, Untether · climber

Security Controls by Layer

77 canonical controls mapped across 8 industry frameworks. Where does your code fit in?

Application Infrastructure Organisational
Showing breakdown of all 77 canonical controls

Application

30%

23 of 77 controls

Examples

  • Secure Software Development
  • Processing Integrity
  • Access Control
  • Logging & Monitoring
  • Patch & Vulnerability Management

Infrastructure

25%

19 of 77 controls

Examples

  • Physical Security
  • Data Protection
  • Network Security
  • Secure Configuration
  • Malware Protection

Organisational

45%

35 of 77 controls

Examples

  • Privacy
  • Organisational Governance
  • Policy & Governance
  • Personnel Security
  • Business Continuity

Compare all frameworks

Data: 77 canonical controls across Cyber Essentials, SOC 2, NIST CSF, ISO 27001, ISO 42001, NCSC CAF, CIS Controls, NIST SSDF.

Framework structure is referenced from its publisher. CIS Controls v8 © Center for Internet Security, used under CC BY-NC-ND 4.0. NCSC material © Crown copyright, used under the Open Government Licence v3.0. ISO and AICPA standards are referenced by control identifier and title only. The mapping and the layer classification are my own analysis, and are not endorsed by any of these publishers.