Five functions, and which framework to start with.
NIST's Cybersecurity Framework isn't a checklist to pass — it's a five-function wheel for organizing a security program at any maturity level, referenced inside SOC 2 and ISO 27001 both.
1
IdentifyKnow your assets and real risk
→
2
ProtectThis entire course, module 1-5
→
3
DetectFalco, audit logs, monitoring
→
4
RespondThe leak-response runbook
→
5
RecoverBlameless postmortem, fix the gap
Which framework do you actually pursue first? It's rarely your call alone — a customer contract usually decides it: selling to enterprises → SOC 2. Touching card data → PCI-DSS, mandatory, not optional. Health data → HIPAA. Selling into the EU, or want one broad ISMS → ISO 27001.
NIST CSF organizes the work; SOC 2/ISO/PCI-DSS are what someone external actually asks you to prove — know both layers, not just the acronyms.