Framework Library
The security context behind your governance program.
NorthStar brings cybersecurity, privacy, and resilience references together in one place — mapped to a single control baseline so your team manages one connected program instead of separate checklists.
Core foundations
Built on NIST from the ground up
Every NorthStar program starts with three NIST publications as its foundation. All other frameworks — federal, state, sector, and privacy — are mapped on top so teams manage one program, not many.
NIST Cybersecurity Framework 2.0
The primary lens NorthStar uses to organize your security program. Six functions — Govern, Identify, Protect, Detect, Respond, Recover — give every team a shared language for ownership and progress.
NIST SP 800-53 Control Catalog
The control catalog that backs every implementation decision in the portal. Over 1,000 controls across 20 families give teams a precise, auditable record of what is implemented, by whom, and with what evidence.
NIST Privacy Framework
Privacy risk sits alongside cybersecurity risk in NorthStar. The Privacy Framework's five functions — Identify-P, Govern-P, Control-P, Communicate-P, Protect-P — map directly to your data-handling obligations.
Coverage by domain
Every obligation, one control baseline
NorthStar maps requirements across six domains onto your NIST control set. When a new obligation appears, it surfaces as a gap in your existing program — not a new spreadsheet.
Federal requirements
FISMA, FedRAMP, CMMC, DFARS, CJIS, and DoD Zero Trust — mapped to your control baseline so federal obligations don't require a separate program.
State & regional obligations
Texas firstTexas leads with TX-RAMP, TAC 202, and DIR requirements. NorthStar maps state statutes to your NIST controls so local obligations are visible alongside federal ones.
Privacy & data protection
GDPR, CCPA, FERPA, COPPA, CIPA, and FTC Safeguards — privacy obligations surfaced in the same control view as your security program.
Customer assurance & questionnaires
SOC 2, ISO 27001, and common security questionnaire frameworks. Evidence already attached to controls is reusable across every customer or auditor request.
Industry & sector standards
HIPAA, HITECH, GLBA, SEC Cybersecurity Rules, NAIC 668, FINRA, DORA, and more — sector-specific requirements mapped to the same control foundation.
Incident readiness
CIRCIA, NERC CIP, CISA CPG, and C2M2 — incident reporting, resilience, and operational technology requirements tracked alongside your broader program.
One program. Every requirement.
NorthStar uses NIST as the common control foundation, then maps your specific obligations on top so teams manage one connected program instead of separate checklists.
See how these frameworks appear inside the portal
Request a demo to see how NorthStar maps your specific obligations to a live control baseline — with evidence, risk, and reporting already connected.
