フレームワーク選定

自社は、どの基準から始めるべきか。

このページで分かること
  • 3つの質問に答えるだけで、最適なフレームワークが適合度順に分かる
  • 対応する6つのフレームワークの立ち位置と特性
  • 選んだ基準が、他の規格をどれだけカバーできるか
Guided Selection

Not sure which framework to pick?
Three questions, the right framework for you.

Among the security frameworks we support,
we propose the best fits for your purpose, scale, and partner requirements — ranked by suitability.
No expertise required to pick the right axis for your company.

01PROFILE

Scale & industry

Select your headcount range and industry.

02PURPOSE

Assessment purpose

Certification, self-assessment, partner requirements, public procurement, board reporting — pick what fits.

03CONTEXT

Regulation & situation

Personal data handling, listing status, domestic-scheme alignment, international trade — pick what applies.

Based on your answers, frameworks ranked by suitability

We also show why each is recommended and how well it covers other standards.

Sample resultSample

CIS Controls

v8.1.2Recommended
88 / 100

Ideal for organizations that want to start with priority-ordered, practical controls. Even with limited resources, you can start with the highest-leverage countermeasures.

Cross-framework coverage: ~80% of the NIST Cybersecurity Framework (CSF) / ~60% of ISO 27001

NIST Cybersecurity Framework (CSF)

2.0
76 / 100

For organizations that want to brief leadership and manage risk comprehensively in an internationally accepted framework.

Cross-framework coverage: ~85% of SCS

ISO 27001

2022
64 / 100

For organizations seeking certification or that need to satisfy partner / tender requirements.

Suitability is computed from clearly defined criteria; the final choice remains yours.
Actual results depend on your specific answers.

SCS evaluation scheme

Get ready now, before applications open.

The supply-chain security evaluation scheme (SCS, METI/IPA) is expected to begin accepting applications by end of FY2026. Before it becomes a partner requirement, get a clear current-state read at the ★ level — self-assessment automatically scores ★3.

See the full scheme details and readiness support
Start SCS prep with self-assessment
Framework Coverage

Six frameworks —
complementing each other from different angles.

We visualize each framework's position by the specificity of technical controls and the breadth of management coverage.
Pick the right axis for your purpose, scale, and partner requirements.

Supported frameworks as of July 18, 2026 — more are added over time.

  • ISO 27001:2022
    93 controls
    International ISMS standard
    Management82
    Technical22
  • NIST Cybersecurity Framework (CSF) 2.0
    106 sub-categories
    6 functions covering exec to ops
    Management76
    Technical70
  • Supply-chain Security Evaluation Scheme (SCS)
    153 criteria
    Japanese scheme / partner reqs
    Management52
    Technical42
  • CIS Controls v8.1.2
    153 safeguards
    Attack-data-driven implementation baseline
    Management22
    Technical80
  • OWASP Top 10 for LLM 2025
    55 controls
    Generative-AI-specific cyber risk
    Management48
    Technical88
  • AI Governance Maturity Assessment
    68 questions
    AI organizational governance (our own framework referencing NIST AI RMF 1.0 × ISO/IEC 42001:2023)
    Management64
    Technical18

Positions are our own, based on each framework's characteristics — not a judgment of standards.

どの基準が自社に合うか、一緒に確かめる。

診断結果をもとに、評価の進め方まで個別にご相談いただけます。

お問い合わせ