The compliance framework has become the enterprise’s way of saying the enterprise is secure. The framework that the auditor signs off on, the board reads the summary of, the regulator accepts as evidence of due diligence. The framework that did not catch the breach the enterprise just disclosed. The honest framing matters here, because the compliance framework the enterprise has been investing in for ten years serves as the compliance framework the postmortem will describe as the framework that did not prevent the breach.
What follows runs as the working version of the honest guide. The shorter version is what the CISO and the auditor both actually have time to read.
What the framework is for
Three things, in roughly that order of how much each one matters. The first runs as the baseline, where the framework defines the minimum control set the enterprise should have, the baseline that the auditor verifies, the baseline that the enterprise can use to know whether the enterprise is missing the control the industry has agreed counts as the minimum. The second runs as the due diligence evidence, where the framework produces the evidence the regulator accepts, the evidence the insurance carrier accepts, the evidence the customer asks for in the procurement questionnaire, the evidence that the framework generates automatically. The third runs as the operational discipline, where the framework forces the enterprise to do the work the enterprise would otherwise skip, the patching cadence, the access review, the vulnerability scan, the discipline the framework imposes on the operations team.
What it does not do
Three things, in roughly that order of how often each one shows up. The first runs as the detect the breach, where the framework does not say the breach will be caught, the framework says the control is in place, the framework does not say the control works against the threat actor the enterprise actually faces, the framework that the auditor signs off on does not test the control against the real attack. The second runs as the prevent the zero day, where the framework does not anticipate the zero day, the framework is updated every few years, the framework is based on the controls the industry knew about when the framework was written, the framework that the auditor signs off on does not protect against the vulnerability the framework did not anticipate. The third runs as the replace the threat intelligence, where the framework does not say which threat actor the enterprise should worry about, the framework does not say which attack pattern the enterprise should defend against, the framework that the auditor signs off on does not include the threat intelligence the SOC team needs to triage the alert.
How to use it for what it is good for
Three moves if you are the CISO that wants the compliance framework to do the work the framework can do without pretending the framework does the work the framework cannot. Use it for the baseline, because the framework the enterprise uses for the baseline controls the enterprise should already have, the framework that the auditor signs off on, the baseline the operations team can use to know which controls the operations team is missing. Layer the threat informed defense on top, because the threat informed defense (the MITRE ATT&CK coverage, the red team validation, the threat intelligence driven detection) sits on top of the framework, the threat informed defense the framework does not provide, the defense that catches the breach the framework did not. Be honest with the board, because the board that hears the CISO say the framework means the enterprise is secure sits as the board that gets surprised by the breach, the board that the CISO should be telling that the framework sits as the floor not the ceiling, the CISO who is honest with the board serves as the CISO who has set the right expectation. The CISO who uses the framework for the baseline, layers the threat informed defense, and is honest with the board serves as the CISO who has used the framework for what it is good for.

The bottom line
Compliance frameworks in 2026 sit as the baseline the enterprise should have, not the security the enterprise should claim. The baseline, the due diligence evidence, the operational discipline, those three are what the framework does. The detection, the zero day, the threat intelligence, those three are what the framework does not. The CISO who uses the framework for the three it does and layers the three it does not serves as the CISO who has stopped pretending the framework stands as the security program.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



