i-Prot

CGF · Cyber Governance Framework

CGF

CGF is i-Prot’s governance model to integrate cybersecurity, risk, compliance, resilience and operations into a single, measurable system aligned with business objectives.

diagram · cgf · cyber governance framework

Hero CGF

CGF is i-Prot’s governance model to integrate cybersecurity, risk, compliance, resilience and operations into a single, measurable system aligned with business objectives.

CGF doesn’t start by asking which standard must be met, but what the organization needs to protect, which risks it must reduce and which capabilities it needs to govern.

The purpose of CGF

The Cyber Governance Framework turns cybersecurity into a governable capability. With CGF, organizations can identify what to protect, understand the risks they face, prioritize investments, implement controls, measure results and sustain a process of continuous improvement.

Its purpose is to enable decisions expressed in terms of business value: risk reduction, resilience, trust, cost, uncertainty, sustainability and operational capacity. CGF is a proprietary i-Prot framework; it is not a standard or a certification.

Guiding principles

Governance before technology

The decision precedes the tool.

Integrated view

Security, risk, compliance and operations as one system.

Traceability

From assets to decisions, with evidence at every step.

Continuous improvement

The cycle is reviewed and adjusted on an ongoing basis.

Results orientation

Everything is expressed as business value.

Multiframework

Standards are sources of requirements, not the end.

Scalability

Applies to organizations of different size and maturity.

The six stages of the cycle

Assess → Prioritize → Design → Implement → Operate & measure → Improve. Each stage has a purpose, activities, deliverables, associated services and its instrumentation in Complyze.

Deliverables: {{ st.deliverables }}

Relationship with standards and frameworks

CGF uses standards and frameworks as sources of requirements, it does not replace them. The cycle integrates their demands into a single governance model, avoiding fragmented, standard-by-standard management.

How it applies across industries

How it is instrumented with services and with Complyze

Complyze · a platform by i-Prot.

CGF glossary

Asset

A resource of value to the organization that must be protected.

Risk

The effect of uncertainty on objectives.

Control

A measure that modifies a risk.

Gap

The difference between the current and the desired state.

Risk appetite

The level of risk the organization is willing to accept.

ISMS

Information security management system.

BIA

Business impact analysis.

RTO / RPO

Recovery time and recovery point objectives.

KPI / KRI

Performance and risk indicators.

Evidence

A record that demonstrates a control is operating.

Maturity

The degree of consolidation of a capability.

Governance

A framework of decisions, roles and accountability.

Download the CGF methodology brief

An executive document with the full cycle, the principles and the relationship with standards. Fill in your details to receive it.

Bring CGF to your organization

A working session with an i-Prot specialist to see how the cycle applies to your context.