Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security
Cyber Security Frameworks and Standards: CIA Triad, ISO 27001, NIST
Updated 11 October 2026 · Fact-checked
A cyber security framework is a structured set of principles, controls and processes to protect information. The CIA triad (confidentiality, integrity, availability) sets the goals. Risk management picks the controls. ISO 27001 and the NIST framework give the structure. Policies and incident response put it into practice.
Understand Cyber Security Frameworks and Standards
Cyber security means protecting information and systems from unauthorised access, change, loss or disruption. Every framework starts from three goals, called the CIA triad.
Confidentiality means only authorised people can see the information. Integrity means the information is accurate and has not been changed without authority. Availability means authorised users can reach the information when they need it. Encryption supports confidentiality. Hashing, digital signatures and access logs support integrity. Backups and redundant systems support availability.
You cannot protect everything equally, so you use risk management. You identify assets, find threats and vulnerabilities, assess the likelihood and impact, and then choose to reduce, avoid, transfer (for example, through insurance) or accept the risk. Risk left over after controls is called residual risk.
A standard is a set of requirements you can be certified against. ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It asks the organisation to define scope, assess risk, select controls, operate them, review them and keep improving. It follows a plan-do-check-act cycle. Annex A lists the control set, and an independent body can certify compliance. A framework is more flexible guidance. The NIST Cybersecurity Framework has core functions: Identify, Protect, Detect, Respond and Recover. Version 2.0 added Govern as a sixth function. It is voluntary and used for self-assessment.
Frameworks become real through security policies and incident response. A policy is a written, management-approved statement of rules, such as acceptable use, access control, password, backup and data classification policies. An incident response plan says what to do when a breach occurs: prepare, detect, contain, remove the cause, restore, and learn from it. In India, remember that these frameworks are best practice, and legal duties come from the IT Act, 2000 and CERT-In directions.
Key rules to remember
- CIA triad
- Confidentiality + Integrity + Availability
- Core security goals. Name each, define it, and give one control for each.
- Risk
- Risk = Threat × Vulnerability × Impact (or Likelihood × Impact)
- A conceptual relationship, not a precise calculation. Use it to explain prioritising risks.
- Residual risk
- Residual risk = Inherent risk − Risk reduced by controls
- Conceptual. Management decides whether residual risk is acceptable.
- NIST CSF core functions
- Identify → Protect → Detect → Respond → Recover (Govern added in version 2.0)
- State the version if you list six functions.
- ISO 27001 cycle
- Plan → Do → Check → Act
- Continual improvement of the ISMS. Certification is by an independent body.
- Incident response phases
- Prepare → Detect and analyse → Contain → Eradicate → Recover → Post-incident review
- Common NIST-style sequence. Other models merge or rename phases.
How to solve Cyber Security Frameworks and Standards questions
Use this method for any question on frameworks, standards, policies or incident response. It gives you a structure that examiners can mark easily.
- 1Read the facts and note the asset, the threat and the business context.
- 2Identify which CIA goal is affected and say so in one line.
- 3Name the relevant framework or standard and state what it requires in plain words.
- 4Apply it to the facts: map the situation to the ISO 27001 step or NIST function that fits.
- 5List the policies or controls the organisation should adopt, with a reason for each.
- 6For incidents, give the response phases in order and tie each to a fact in the case.
- 7Add the legal link, such as reporting to CERT-In or liability under the IT Act, 2000, only where the facts support it.
- 8Conclude with a clear recommendation or finding in one or two sentences.
Quickest way: Triad, framework, action
When to use it: Use it when you have little time and the question asks for a short note or a brief case answer.
- Write the CIA goal affected and one control for it.
- Write the framework name and its key idea in one line (ISMS for ISO 27001, five or six functions for NIST).
- Write three or four actions, in order, linked to the facts.
- Close with the legal reporting point if relevant, then a one-line conclusion.
Common mistakes in Cyber Security Frameworks and Standards
Confusing integrity with confidentiality, for example saying encryption alone ensures integrity.
Both sound like protection of data, so the definitions blur.
Fix: Remember: confidentiality is who can see, integrity is whether it is unchanged, availability is whether it is accessible. Link hashing and signatures to integrity.
Calling ISO 27001 a law or saying it is mandatory for all Indian companies.
Students treat any named standard as a legal requirement.
Fix: Say it is a voluntary international standard for an ISMS, certifiable by independent auditors. Mandatory duties come from statutes and regulators.
Listing NIST functions in the wrong order or forgetting Govern.
Students memorise an older list from one source.
Fix: Write Identify, Protect, Detect, Respond, Recover, and mention that version 2.0 added Govern.
Treating a policy as a technical tool rather than a management document.
Policies are confused with controls like firewalls.
Fix: Define a policy as a written, approved statement of rules and responsibilities. Controls are the measures that enforce it.
Jumping to recovery in an incident answer and skipping containment and preparation.
Students focus on getting systems back online.
Fix: Follow the full sequence: prepare, detect, contain, eradicate, recover, review. Containment limits damage first.
Giving a theory definition without applying it to the facts.
Case-based papers are new to many students.
Fix: After each definition, add a sentence starting 'In this case...' using the company, system or data in the question.
Worked examples
Example 1
Sundaram Textiles Ltd stores customer order data on a server. A staff member alters invoice amounts in the database, and the server is also offline for a day after a ransomware infection. Identify which CIA goals were breached and suggest one control for each.
Show the solution
- Altered invoice amounts mean data was changed without authority. This breaches integrity.
- The server being offline means authorised users could not access data. This breaches availability.
- Ransomware that blocks files may also involve data theft. If so, confidentiality is also at risk, but the facts do not say so. Say this as a point to check.
- Control for integrity: role-based access, audit logs of changes and hash or checksum checks.
- Control for availability: regular offline backups, tested restoration and a disaster recovery plan.
- Control for confidentiality, if data was accessed: encryption and least-privilege access.
Answer: Integrity and availability were breached, and confidentiality may be affected if data was exfiltrated. Use access control with audit logs for integrity, and tested backups with a recovery plan for availability.
Example 2
Kaveri Finserv Ltd wants to build a formal security programme. Explain how ISO 27001 and the NIST Cybersecurity Framework can help, and outline how it should respond to a detected data breach.
Show the solution
- ISO 27001: the company sets up an ISMS. It defines scope, assesses risks, selects controls, operates them, reviews them and improves them in a plan-do-check-act cycle. It can seek certification from an independent body.
- NIST framework: the company uses the functions Identify, Protect, Detect, Respond and Recover (plus Govern in version 2.0) to assess its current position and set targets. It is voluntary and flexible.
- Difference: ISO 27001 is a certifiable standard. NIST is guidance used for self-assessment. They can be used together.
- Policies: adopt approved policies on access control, acceptable use, data classification, backup and incident response.
- Breach response: first follow the prepared plan. Detect and analyse the breach to confirm scope.
- Contain by isolating affected systems. Eradicate the cause, such as removing malware or closing the vulnerability.
- Recover systems from clean backups and verify them.
- Report as required, including to CERT-In where applicable, and hold a post-incident review to update controls and policies.
Answer: Kaveri Finserv can use ISO 27001 to build and certify an ISMS and NIST to benchmark its functions. On a breach, it should detect, contain, eradicate, recover, report as required and review, using approved policies throughout.
Exam tips
- Always define the CIA triad in one line each, then give a control for each. This earns easy marks.
- In case questions, tie every framework point to a fact from the scenario. Pure theory scores lower.
- Say clearly that ISO 27001 and NIST are voluntary, and that legal duties come from the IT Act, 2000 and regulator directions.
- Write incident response as a numbered sequence. Examiners look for order and for containment before recovery.
- Do not quote clause numbers or Annex A control counts unless you are certain. Describe the idea instead.
Practice questions from Network Basics and Security
- Under the Information Technology Act, 2000 as taught for this paper, which body is the national nodal agency for responding to computer secu…
- The security team of Bharat Textiles Ltd. deploys a system that monitors network traffic, compares it with known attack signatures and autom…
- A firm's employees in Chennai connect laptops to the office network through wireless access points, and the IT head wants to prevent a forme…
- In the OSI reference model, which layer is responsible for end-to-end delivery of data between processes on two hosts, including segmentatio…
- A firm's IT manager explains that its web portal must move from IPv4 to IPv6 support because available IPv4 addresses are nearly exhausted. …
Cyber Security Frameworks and Standards in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Security Frameworks and Standards: frequently asked questions
What is the CIA triad in cyber security?
It is the three core goals of information security: confidentiality, integrity and availability. Confidentiality limits access to authorised people. Integrity keeps data accurate and unaltered. Availability ensures data can be used when needed.
What is ISO 27001 in simple words?
It is an international standard that sets requirements for an Information Security Management System. The organisation assesses risks, applies controls and keeps improving. An independent body can certify that it meets the standard.
What are the functions of the NIST Cybersecurity Framework?
The core functions are Identify, Protect, Detect, Respond and Recover. Version 2.0 added Govern. The framework is voluntary and helps organisations assess and improve their security.
What are the steps of incident response?
A common sequence is preparation, detection and analysis, containment, eradication, recovery and a post-incident review. Some models group or rename these phases, so state the model you follow.
Is ISO 27001 mandatory in India?
No. It is a voluntary standard. Companies may adopt it for good practice or because clients and regulators expect it, but legal duties arise from statutes and directions.