Nine Things a Microsoft 365 Security Review Finds Almost Every Time
The same findings come up in nearly every tenant we assess. Nine of them, what each one actually costs you, and how to check your own as you read.
Frameworks, strategies, standards and regulations are different things. Where NIST CSF, the Essential Eight, CIS, PCI DSS, ISO 27001 and GDPR each sit.

In the complex landscape of cybersecurity and data privacy, organisations navigate through a myriad of compliance requirements. From frameworks and strategies to standards and regulations, each type of compliance requirement serves a distinct purpose and scope. This blog post explores the key differences between these compliance categories, alongside specific examples like the NIST Cybersecurity Framework (CSF), Essential 8, CIS Benchmarks, PCI DSS, ISO/IEC 27001, GDPR, HIPAA, and SOC 2.
A framework provides an overarching structure and methodology for addressing particular aspects of cybersecurity or data management. It is typically flexible, offering a set of best practices and guidelines rather than strict rules.
A strategy refers to a plan of action designed to achieve a long-term or overall aim. It is often more specific than a framework and focuses on achieving particular goals within a defined time frame.
Standards provide a definitive set of criteria or practices that are widely accepted and implemented within an industry. Standards can help ensure that products, services, and systems are safe, reliable, and consistently perform as intended.
Regulations are binding legislative acts that must be followed in the jurisdictions in which they apply. They are typically more prescriptive and legally enforceable compared to frameworks and standards.
While frameworks offer guidance, they do not compel legal compliance but help organisations design their cybersecurity and privacy processes. Strategies provide actionable steps towards achieving specific cybersecurity postures. Standards, often developed by consensus in standards development organisations (SDOs), are regularly incorporated into products and services to ensure safety, reliability, and efficiency. Regulations and legislation, however, are legally binding and must be complied with to avoid legal repercussions.
Each organisation must assess its specific needs, risk profile, and regulatory environment to determine the most applicable and beneficial compliance standards. Compliance is not just about avoiding fines but protecting the organisation from breaches and losses while fostering trust with customers and partners.
Element Digital does cyber security work in Hobart and across Tasmania. If you are working out which of these actually apply to you, get in touch.
Let us talk about what you are trying to achieve, no obligation, just a conversation.