Frameworks & Standards

Fluent in the standards that govern modern enterprise risk.

From control frameworks and zero-trust reference models to the converging EU regulatory landscape — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.

Control & architecture frameworks

FrameworkPurposeWhere it applies
NIST CSF 2.0Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024)Enterprise-wide programme & board reporting
ISO/IEC 27001:2022Information security management system (ISMS) certification standardCertification, audit, supplier assurance
NIST SP 800-207Zero Trust Architecture — identity-first, resource-centric securityArchitecture & access design
CIS ControlsPrioritised, prescriptive technical safeguardsHardening & baseline assurance
SABSABusiness-driven security architecture methodSecurity architecture & design authority
TOGAFEnterprise architecture framework and methodOperating-model & enterprise design

NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.

Regulatory & operational resilience

RegulationScopeStatus
DORADigital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entitiesIn force Jan 2025
NIS2 DirectiveRaised cybersecurity baseline & incident handling for essential/important entities and critical infrastructureTransposing
GDPRPersonal data protection & breach notificationIn force
ISO 27001:2022Shared risk-management foundation that DORA & NIS2 build onCertifiable

DORA builds on — not replaces — ISO 27001, NIS2, and GDPR; the disciplines converge for ICT risk and incident handling.

AI governance & emerging tech

StandardPurposeRelevance
EU AI ActRisk-tiered regulation of AI systems across the EUAI adoption strategy & controls
ISO/IEC 42001AI management system (AIMS) — governance for responsible AICertifiable AI governance
NIST AI RMFVoluntary framework to manage AI riskAI risk identification & mitigation
Post-Quantum ReadinessMigration toward quantum-resistant cryptographyForward-looking resilience

CISOs increasingly manage the "regulatory collision" where NIS2, DORA, and the EU AI Act intersect on AI systems.

Applied outcomes

Standards in service of the business.

Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.

🧭

Harmonised compliance

Consolidating overlapping obligations (DORA · NIS2 · ISO 27001) into a single, defensible control set.

🛡️

Zero-trust resilience

Identity-first architectures aligned to NIST SP 800-207 that limit blast radius and lateral movement.

🤖

Responsible AI

Governance that lets the enterprise adopt AI with control — mapped to the EU AI Act and ISO 42001.

Put the frameworks to work.

Translate standards into a defensible, board-ready control posture.