Framework Library

The security context behind your governance program.

NorthStar brings cybersecurity, privacy, and resilience references together in one place — mapped to a single control baseline so your team manages one connected program instead of separate checklists.

Core foundations

Built on NIST from the ground up

Every NorthStar program starts with three NIST publications as its foundation. All other frameworks — federal, state, sector, and privacy — are mapped on top so teams manage one program, not many.

CSF 2.0

NIST Cybersecurity Framework 2.0

The primary lens NorthStar uses to organize your security program. Six functions — Govern, Identify, Protect, Detect, Respond, Recover — give every team a shared language for ownership and progress.

6 core functions · Risk-based · Sector-agnostic
SP 800-53 Rev. 5

NIST SP 800-53 Control Catalog

The control catalog that backs every implementation decision in the portal. Over 1,000 controls across 20 families give teams a precise, auditable record of what is implemented, by whom, and with what evidence.

20 control families · 1,000+ controls · Evidence-linked
Privacy Framework

NIST Privacy Framework

Privacy risk sits alongside cybersecurity risk in NorthStar. The Privacy Framework's five functions — Identify-P, Govern-P, Control-P, Communicate-P, Protect-P — map directly to your data-handling obligations.

5 privacy functions · Data governance · Consumer rights

Coverage by domain

Every obligation, one control baseline

NorthStar maps requirements across six domains onto your NIST control set. When a new obligation appears, it surfaces as a gap in your existing program — not a new spreadsheet.

Federal requirements

FISMA, FedRAMP, CMMC, DFARS, CJIS, and DoD Zero Trust — mapped to your control baseline so federal obligations don't require a separate program.

State & regional obligations

Texas first

Texas leads with TX-RAMP, TAC 202, and DIR requirements. NorthStar maps state statutes to your NIST controls so local obligations are visible alongside federal ones.

Privacy & data protection

GDPR, CCPA, FERPA, COPPA, CIPA, and FTC Safeguards — privacy obligations surfaced in the same control view as your security program.

Customer assurance & questionnaires

SOC 2, ISO 27001, and common security questionnaire frameworks. Evidence already attached to controls is reusable across every customer or auditor request.

Industry & sector standards

HIPAA, HITECH, GLBA, SEC Cybersecurity Rules, NAIC 668, FINRA, DORA, and more — sector-specific requirements mapped to the same control foundation.

Incident readiness

CIRCIA, NERC CIP, CISA CPG, and C2M2 — incident reporting, resilience, and operational technology requirements tracked alongside your broader program.

One program. Every requirement.

NorthStar uses NIST as the common control foundation, then maps your specific obligations on top so teams manage one connected program instead of separate checklists.

See how these frameworks appear inside the portal

Request a demo to see how NorthStar maps your specific obligations to a live control baseline — with evidence, risk, and reporting already connected.