top of page

Technical Research Paper

WP-910_cover_pic_2025.png

Comparative Analysis of Cybersecurity Standards: Governance versus Engineering Orientations

Citations (22)  References (20)  Figures (2)

Authored Date:

​​November 14, 2025

​

Publication Date:

​​December 19, 2025

​

​Task Group Chair / Task Group:​

Art Chavez / ISAU-TG62-2025​​

​

​Document Registration  Number:

​​​ISAU-RP-910-2025-TSvsD10S

Abstract

This whitepaper evaluates the extent to which widely used ISO/IEC and NIST publications are applied in practice, distinguishing governance-oriented guidance from engineering-oriented technical standards. ISO and NIST remain essential baselines for governance, risk management, and program oversight. Still, they do not consistently define engineering inputs, measurable outputs, or verification and validation expectations that are required to build defensible architectures. Using five measurement criteria, Technical Specificity, Verifiability, Artifact Output, Granularity, and Lifecycle Integration, and a repeatable scoring method, we compute a composite Engineering Orientation Index and map the results to a quadrant with clearly defined X- and Y-axis definitions. The analysis shows a persistent gap between governance baselines and engineering implementation. The Defensible 10 Standards (D10S) are positioned as the engineering layer that operationalizes baseline intent into measurable requirements, technical specifications, and verification and validation evidence for cybersecurity architecture and engineering practice. This is a coexistence model, not a replacement.

How to Stay Informed

​

  • Subscribe to Updates – Join our newsletter for new report announcements.

  • Access via Library – Browse and download reports through the Technical Whitepaper Library.

  • Suggest a Report Topic – Members may propose high-priority topics for future analysis.

 

For more information, contact the ISAUnited Technical Research Center team below.

Contact Us

Guest

For any questions or concerns, fill out our form or email us at:

research@isaunited.org

Thanks for Submitting!

Members

For any requests or suggestions, click here to generate a support ticket:

ISAUnited-01_white_edited.png

Institute Support Hours

HIn

Monday:          8-5 p.m. CST

Tuesday:         8-5 p.m. CST

Wednesday:  8-5 p.m. CST

Thursday:       8-5 p.m. CST

Friday:             8-5 p.m. CST

Saturday:       CLOSED

Sunsday:        CLOSED

Social Media: 

  • LinkedIn
  • X
  • Instagram
  • Facebook

Headquarters: United States. Houston, Texas.

All Rights Reserved • Property Of ISAUnited.org

© 2019-2026 Institute of Security Architecture United

bottom of page