← All frameworks

Cyber Control Framework

Control cyber risk through preventive and detective controls.

Methodology

Model across cyber control domains, identity, protection, detection and response controls, drawing on recognised cyber control practice and COBIT.

Components

CISO/IT owns; second line oversees; internal audit assures; board oversees cyber risk.

Governance

Cyber controls reviewIdentity-controls buildDetection-controls build

Maturity levels

L1
Foundational (0–40) — Ad-hoc, undocumented, reactive.
L2
Developing (41–60) — Framework emerging; pockets of practice.
L3
Established (61–80) — Documented, standardised, governed.
L4
Strategic (81–100) — Board-grade competitive differentiator.

Across the Internal Control ecosystem

Knowledge graph · 3 relations