A comprehensive FAQ answering the most common questions about NIST, ISO, MITRE, COBIT, Basel, and BSI — what they are, how they differ, and how they fit together.

Frequently Asked Questions About Risk Frameworks

What is NIST?

The National Institute of Standards and Technology (NIST) is a U.S. standards body that defines cybersecurity controls, risk categories, and required outcomes. It provides the “what” — what must be protected and what controls should exist.

What is ISO?

ISO is an international standards organization that defines governance, management, and process discipline. It provides the “how” for organizational governance.

What is MITRE ATT&CK?

MITRE ATT&CK is a knowledge base of adversary behaviors, tactics, and techniques. It explains how attackers operate and how attacks unfold.

What is COBIT?

COBIT is a governance framework for executives. It defines how leadership should govern IT, assign accountability, and align technology with business goals.

What is the Basel Framework?

Basel is a global financial regulatory framework that defines capital requirements, systemic risk thresholds, and macro‑prudential controls for financial stability.

What is the Black Star Institute (BSI)?

BSI is a boundary‑systems governance body that operates in the in‑between spaces where technical systems, human behavior, institutions, and automated decision‑making collide.

What does NIST cover?

NIST covers cybersecurity controls, asset categories, risk management processes, and required security outcomes.

What does ISO 27001 cover?

ISO 27001 covers information security governance, risk management, documentation, and organizational processes.

What does MITRE cover?

MITRE covers adversary behavior, attack chains, detection logic, and threat‑informed defense.

What does COBIT govern?

COBIT governs executive oversight, IT accountability, performance measurement, and enterprise control structures.

What does Basel regulate?

Basel regulates systemic financial risk, capital adequacy, liquidity, and exposure thresholds.

What does BSI govern?

BSI governs boundary failure, machine‑age complexity, and the seams between systems where legacy frameworks cannot operate.

What is the difference between NIST and ISO?

NIST defines controls and requirements. ISO defines governance and management processes. NIST is technical; ISO is organizational.

What is the difference between NIST and MITRE?

NIST defines what must be protected. MITRE explains how attackers behave. They operate at different layers.

What is the difference between ISO and MITRE?

ISO governs organizational processes. MITRE models adversary behavior. One is governance; the other is threat mechanics.

What is the difference between COBIT and ISO?

COBIT focuses on executive governance and accountability. ISO focuses on operational governance and process discipline.

How does BSI compare to legacy frameworks?

BSI does not compete with legacy frameworks. It governs the interstitial spaces where technical, institutional, and adversarial dynamics intersect.

What is the difference between BSI and NIST?

NIST defines what must be protected and what controls should exist. BSI governs the seams between systems — where controls fail, observability collapses, and machine‑age complexity exceeds institutional capacity.

What is the difference between BSI and ISO?

ISO defines organizational governance, process discipline, and management structures. BSI governs boundary‑systems behavior — the interactions between humans, machines, institutions, and automated decisions that ISO does not model.

What is the difference between BSI and MITRE?

MITRE models adversary behavior and attack mechanics. BSI models system‑level boundary failure — where adversaries, automation, and institutional limits interact in nonlinear ways beyond traditional threat frameworks.

What is the difference between BSI and COBIT?

COBIT governs executive oversight, accountability, and enterprise control. BSI governs the interstitial spaces where governance breaks down — when automation outruns leadership capacity and institutional decision‑making becomes insufficient.

What is the difference between BSI and Basel?

Basel governs systemic financial risk and macro‑prudential stability. BSI governs systemic boundary risk — the cross‑domain failures that occur when technical, institutional, and adversarial systems interact beyond the scope of financial regulation.


The Black Star Institute (BSI) is the first and only boundary‑systems institute in the world — a sovereign, independent analytical institution that integrates the capabilities of a think tank, research lab, consultancy, and policy shop without inheriting their structural limitations or vulnerabilities. As a boundary-systems institute, BSI operates across human, machine, and institutional layers to diagnose systemic failure and define governance doctrine.

It is an independent research and governance organization focused on systemic‑risk analysis, automation failures, and human‑layer security. BSI examines how institutions, technologies, and decision systems break under real‑world conditions, producing artifacts that clarify failure modes, strengthen governance, and prevent recurrence. BSI’s sovereign, single‑operator architecture ensures authorship integrity and analytical independence across all research outputs.

BSI’s work integrates over three decades of cross‑sector experience in artificial intelligence (AI), cybersecurity, post-quantum cryptography (PQC), quantum, national security, critical‑infrastructure resilience, and emerging and disruptive technologies (EDT) governance. Its research emphasizes authorship integrity, structural clarity, and practitioner‑driven analysis grounded in operational reality rather than narrative or theory.

Through the Black Star Institute, its founder, Hunter Storm publishes institutional frameworks, case studies, and governance artifacts that support organizations navigating complex technological, regulatory, and hybrid‑threat environments.


Disclaimer

This publication is provided for educational, analytical, and informational purposes. The Black Star Institute does not provide legal, regulatory, or compliance advice. All findings reflect independent, practitioner‑grade analysis based on publicly available information and BSI’s doctrinal frameworks at the time of publication. Institutions, policymakers, and organizations should consult appropriate legal or regulatory professionals before acting on any recommendations.

Explore Black Star Institute (BSI)

About BSI
Identity, mandate, institutional posture, and mission.


Case Studies
Failures in automation, compliance, systems, and governance.


Series
Multi‑part explorations of systems, governance, and institutional behavior


Doctrine
Principles of governance, analysis, and engagement.


Publications
Essays, briefings, educational materials, and institutional artifacts.


Advisory Work
Engagement scope, methods, and governance approach.

Lexicon
Shared structural language for clarity and precision.


Frameworks
Operational models for analysis, diagnosis, and decision-making.


Contact
Institutional channels for inquiry and collaboration.