Standards and Framework Guides
What the recognised standard or framework actually requires, how assessment works, what counts as evidence, and only then where a physical control such as Offline Secure Storage® can contribute to satisfying it.

Read the requirement before the remedy
Some of these certify, some assess, and one is a knowledge base that certifies nothing. Each guide is explicit about which it is, because that determines what an auditor, a regulator or an underwriter will accept as evidence. No product certifies an organisation against any of them.
NIST CSF 2.0
The six Functions, including Govern, what each one asks you to evidence, how Tiers and Profiles are meant to be used, and the difference between adopting the language and improving the outcome.
Read the guideNCSC Cyber Assessment Framework
The four Objectives, the underlying Principles, how Indicators of Good Practice are assessed as achieved, partially achieved or not achieved, and how the CAF is used by regulators.
Read the guideISA/IEC 62443
Zones and conduits, security levels, the difference between capability and achieved security level, and which parts of the series apply to asset owners rather than product suppliers.
Read the guideMITRE ATT&CK Mapping
Tactics, techniques and sub-techniques, the Enterprise and ICS matrices, how to map coverage without flattering yourself, and why a versioned knowledge base is not a compliance framework.
Read the guideThe other two guide families
Role guides cover who is making the decision and what evidence that seat should expect. Technical guides cover how the architecture and the controls actually work.



Which offline secure storage solution is right for you?
Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.
Takes about 2 minutes. No account needed.