MASTER OF SCIENCE IN INFORMATION TECHNOLOGY/COMPUTER
SCIENCE
IIT 6244 – Security Audit and Compliance Testing
Presentation: Regulatory Frameworks and Compliance Standards
DATE: September 2025 TIME: 1 WEEK
Presented By: Francis Njambi – MSCIT-01-0004/2024
Date: 28th Sep 2025
Definitions:
Frameworks: It is a structured set of guidelines, principles and best practices that help
organizations design, implement and manage information systems security and
compliance posture.
Standards: A compliance standard is a set of specific mandatory or measurable
requirements that an organization must meet to comply with the law, regulation or
contractual obligation.
Conceptual Comparison between regulatory frameworks and compliance standards:
This is a mention of the various commonly used frameworks and standards, the list
below is by means exhaustive.
Frameworks Compliance Standards
NIST Cybersecurity Frameworks (CSF) PCI DSS (Payment Card Industry Data
- provides “Identify, Protect, Detect, Security Standard) – Requires specific
Respond, recover” functions to guide technical controls for payment card data
cybersecurity risk management. (e.g., firewall rules, encryption).
ISO/IEC 27002 – outlines best practices ISO/IEC 27001 (Vicente, 2023) - defines
for information security controls. auditable requirements for an Information
Security Management System (ISMS)
COBIT – IT governance and HIPAA Security Rule (Vicente, 2023) –
management framework integrating sets mandatory safeguards for protecting
business and IT objectives electronic health information in the U.S.
healthcare sector.
COSO Framework – internal control and Sarbanes–Oxley Act (SOX) – a legal
risk management model used for SOX standard requiring internal control audits
compliance. over financial reporting.
CIS Controls (Center for Internet GDPR (EU General Data Protection
Security) – prioritized best-practice Regulation) (15 Essential Regulatory and
controls for securing systems. Security Compliance Frameworks, n.d.) –
legal standard requiring specific privacy
and data protection measures.
Conceptual Difference
Aspect Framework Compliance Standard
Purpose Provides a methodology or Provides rules or criteria
blueprint for managing that must be satisfied —
security and risk — “what “what you must do and prove
good security management to be compliant.”
looks like.”
Flexibility Usually voluntary and Usually prescriptive and
adaptable to auditable — failure to
organizational context. comply can lead to
penalties or loss of
certification.
Outcome Guides security program Leads to formal
maturity and risk certification, attestation,
management alignment. or regulatory compliance.
Auditors Role Assess how well a Verify whether each
framework is implemented requirement of the
(qualitative assessment) standard is met
(quantitative/pass-fail
assessment)
Practical Differences in Auditing and Compliance Testing
In an Audit e.g., Security When using a framework When testing a
Audit compliance Standard
Objective Evaluate maturity and Verify compliance with
adequacy of security prescribed controls or legal
processes against a best- requirements.
practice model.
Assessment Style Risk-based, flexible, Control-based, evidence-
advisory. driven, mandatory.
Evidence Expectation Policies, procedures, Hard evidence —
management review, configuration files, logs,
improvement plans. system settings, reports,
signed attestations.
Outcome Document Internal audit report or Certification or compliance
maturity score (e.g., “Level attestation (e.g., PCI ROC,
ISO 27001 certificate, SOC
3/5 compliance with NIST 2 report (Farnood Faghihi,
CSF”). 2018)).
Relationship between Frameworks and Standards
Most organizations will use frameworks to achieve or maintain compliance with
standards.
A sample scenario:
1. An organization uses NIST CSF or ISO/IEC 27002 to design a security
program.
2. The organization implements the program so that it satisfies ISO 27001,
PCI DSS, or GDPR requirements (the standards).
3. Undergo an audit or a certification against the standard.
Therefore,
A framework provides guidance and structure
A standard provides a specific benchmark or rules you must meet.
For perspective here is how frameworks, standards, regulations and policies relate in a
broader context.
References
15 Essential Regulatory and Security Compliance Frameworks. (n.d.). From secure frame:
[Link]
Farnood Faghihi, P. (2018, June 18). 15 Essential Regulatory and Security Compliance
Frameworks & Industry Standards. From Security Compass:
[Link]
standards/
Vicente, V. (2023, April 19). Security Audits: A Comprehensive Overview. From Audit Board:
[Link]