Every year a new cybersecurity or privacy framework is released, or an existing one is updated. This month it is ISO/IEC 27018:2025, the global standard for protecting personally identifiable information in public cloud environments. Important? Yes. And like most new frameworks it immediately raises the same three questions:
- Are we legally or contractually required to adopt this?
- Does it overlap with what we already do, and does it add administrative work?
- Will customers, partners or investors care if we adopt it?
In most cases the answer is that you do not need to switch. You need to apply what you already have.
Paper and practice
ISO 27001, NIST CSF and ISO 31000 overlap more than they differ. At their core they say the same thing: know your assets, understand your risk, manage it systematically, and keep improving.
The problem is not adding the wrong framework. It is that too many organizations stop at certificates and documents without translating those fundamentals into daily practice.
We see it often. A company shows an ISO 27001 certificate, a neatly formatted Statement of Applicability and a risk register. In reality the controls are not linked to actual threats, and risk-based decision-making is absent.
The usual response is to reach for another framework.
Stop stacking. Start applying.
It is tempting to bolt on NIST CSF, experiment with FAIR, or start a 31000-inspired risk process on top of ISO 27001. Without embedding any of them into daily decision-making you are piling frameworks on frameworks.
A framework does not lead to security, or to resilience. How you apply it does.
These frameworks are not wrong. They are useful when used properly. Adopting more of them will not fix a lack of clarity, accountability or execution.
What proper application looks like
A framework used properly does not live in a shared drive. It shows up in how teams work. Controls align with how systems are built and maintained. Decisions about risk are not theoretical; they are linked to real operations, data, systems and consequences.
In a well-applied framework the inventory is not a static spreadsheet but something dynamic and validated. Risk is not abstract; it drives prioritization. When a new cloud system is deployed, someone checks whether it falls inside the documented responsibilities under ISO 27018. When AI tooling is added, someone asks who approved it, what data it uses, and what access it has.
Most importantly, people across the organization understand the framework, not in technical terms but in practice. They know where their responsibilities begin and end.
Instead of expanding, refactor
Certificates and policies may exist on paper, but without enforcement, accountability and integration into daily work they add little. So where do you start?
Four questions expose whether an implementation is embedded in practice or living in documents:
- Are your governance intentions aligned with the organization’s direction, and do they add business value?
- Are your policies actively enforced, and can you prove it through audit or evidence?
- Do business owners contribute to risk assessments, or is it only a security exercise?
- Are findings, follow-ups and exceptions logged, tracked and closed, or do they fade away?

