GRC › Module 4 › Lesson 3
Framework Fit
Framework fit literacy names sector drivers, regulatory triggers, and ISO vs NIST selection factors — document fit rationale for YOUR $GRC_LAB fictional org industry.
Visual · t37_framework_fit
Framework fit literacy. $GRC_LAB only. Original Cyberlium.
Opening
No single framework fits every org — literacy teaches fit factors so fictional org choices on $GRC_LAB reflect sector and customer context, not random checklist picking.
Framework selection considers customer contract requirements — ISO 27001, SOC 2, NIST CSF references — sector regulation, geographic privacy law literacy, org size, maturity, and existing control investments. Many enterprises use ISO for certification and NIST CSF for operational outcome language — crosswalks bridge both on YOUR lab template. Cyberlium writes framework fit row on YOUR $GRC_LAB — fictional industry, primary driver, chosen frameworks, rationale sentence. Next: Frameworks Lab.
1. Fit factors (named)
Customer demand: RFP requires ISO 27001 or SOC 2 attestation. Sector: healthcare HIPAA literacy, finance PCI literacy — named only on lab org. Geography: EU customers raise GDPR literacy questions — consult counsel for real duties. Maturity: young fictional startup may start with CSF profile before ISO scope.
On $GRC_LAB, write fit row — industry, driver, framework choice, one-sentence rationale for fictional org.
Command guide
Try these commands — Fit factors (named)
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
ISO 27001 — https://www.iso.org/isoiec-27001-information-security.html NIST CSF — https://www.nist.gov/cyberframework CIS Controls — https://www.cisecurity.org/controls
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install python3
macOS:
Command — copy this
brew install python3
Windows: Download https://python.org/downloads/
═══ LINUX / macOS ═══
Command — copy this
export GRC_LAB=${GRC_LAB:-$HOME/cyberlium-lab/t37-grc}
cat > "$GRC_LAB/notes/framework-fit.md" <<'EOF'
# Framework Fit — LAB-ORG-001 literacy
## When ISO 27001 fits
- Customer/regulator asks for certifiable ISMS
- Global ops needing formal SoA + internal audit cycle
## When NIST CSF fits
- US-centric risk communication; flexible outcome language
- Mapping existing controls without cert goal
## When CIS Controls fits
- Prioritized technical safeguards (IG1/IG2/IG3)
- Complements ISO/NIST — not a replacement
## LAB-ORG-001 stub choice
- Primary: NIST CSF for board reporting literacy
- Secondary: ISO 27001 Annex A for SoA exercise
- Map both in controls/ folder — avoid framework soup without owners
EOFCommand — copy this
grep -E 'ISO 27001|NIST CSF|CIS|LAB-ORG-001' "$GRC_LAB/notes/framework-fit.md"
python3 -c "print('Framework fit: pick primary + map others — fictional org literacy')"Primary tools to practice this lesson: grep, python3. Reference sites: ISO 27001 (https://www.iso.org/isoiec-27001-information-security.html); NIST CSF (https://www.nist.gov/cyberframework); CIS Controls (https://www.cisecurity.org/controls). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Why fit beats framework shopping
Adopting ISO scope without customer need wastes audit cost. Ignoring contract-mandated frameworks loses deals. Documented fit rationale survives board and auditor questions on integrated programs.
Students document lab fit on notes — production selection follows legal, sales, and risk committee input.
3. Lab boundary
Forbidden: claiming framework fit analysis replaces legal or auditor engagement. Allowed: framework fit card — rationale with $GRC_LAB fictional org example.
Ship: framework fit row for YOUR lab org industry. Next: Frameworks Lab.
4. What you ship: framework fit row for $GRC_LAB
Industry, driver, framework choice, rationale. $GRC_LAB named. chmod 600.
5. What you record before the next lesson
Date. Framework fit row. $GRC_LAB named. File t37-m04-l03-framework-fit.txt chmod 600.
6. Wrong vs right: fraudulent certs vs YOUR lab templates
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Pick ISO because logo looks official. Ignore customer contract framework requirement in fictional scenario.
Right
Write framework fit row for YOUR $GRC_LAB. Next: Frameworks Lab.
Mission: document framework fit on YOUR lab org
1) Name fictional industry and customer driver. 2) Choose ISO, NIST CSF, or both with rationale. 3) Note educational — not legal advice. 4) chmod 600.
Stuck? Ask Cyberlium AI Mentor
Fit follows drivers — contract and sector matter more than framework logos.
Knowledge Check
APPLY: Framework fit primarily considers:
Multiple choice
Knowledge Check
APPLY: True or False: Many orgs use ISO for certification and NIST CSF for outcome language.
True or False
Knowledge Check
APPLY: Framework fit literacy on Cyberlium uses:
Multiple choice