Frameworks
List of IT business frameworks that I follow and find important in my work as an solutions architect and business developer
CIS 18 Critical Security Controls
The Center for Internet Security (CIS) Critical Security Controls (CIS 18 Controls) are a prescriptive, prioritized, and simplified set of best practices that you can use to strengthen your cybersecurity posture.
Digital Operational Resilience Act (DORA)
DORA (Digital Operational Resilience Act) is an EU regulation that creates a binding, comprehensive cybersecurity and risk management framework for the financial sector. It requires banks, insurance companies, and investment firms to ensure they can withstand, respond to, and recover from severe ICT (Information and Communication Technology) disruptions and threats.
EU AI Act
The use of artificial intelligence in the EU is regulated by the AI Act, the world’s first comprehensive AI law. Find out how it protects you.
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is the toughest privacy and security law in the world. Though it was drafted and passed by the European Union (EU), it imposes obligations onto organizations anywhere, so long as they target or collect data related to people in the EU. The regulation was put into effect on May 25, 2018. The GDPR will levy harsh fines against those who violate its privacy and security standards, with penalties reaching into the tens of millions of euros.
GitHub Well-Architected Framework
The GitHub Well-Architected framework is structured in a fundamental, layered approach:
- Pillars
- Design Principles
- Checklists
- Recommendations
Microsoft AI Adoption Framework
The Cloud Adoption Framework (CAF) provides a structured process for adopting AI solutions in Azure. This framework outlines clear steps, many of which apply to Microsoft Copilot adoption.
- Strategy
- Plan
- Ready
- Govern
- Secure
- Manage
Microsoft Agent Framework (MAF)
The Microsoft Agent Framework is an open-source development kit for building AI agents and multi-agent workflows for .NET and Python. It brings together and extends ideas from Semantic Kernel and AutoGen projects, combining their strengths while adding new capabilities. Built by the same teams, it is the unified foundation for building AI agents going forward.
Agent Framework offers two primary categories of capabilities:
- AI Agents: Individual agents that use LLMs to process user inputs, call tools and MCP servers to perform actions, and generate responses. Agents support model providers including Azure OpenAI, OpenAI, and Azure AI.
- AI Workflows: Graph-based workflows that connect multiple agents and functions to perform complex, multi-step tasks. Workflows support type-based routing, nesting, checkpointing, and request/response patterns for human-in-the-loop scenarios.
The framework also provides foundational building blocks, including model clients (chat completions and responses), an agent thread for state management, context providers for agent memory, middleware for intercepting agent actions, and MCP clients for tool integration. Together, these components give you the flexibility and power to build interactive, robust, and safe AI applications.
Microsoft Azure Well-Architected Framework (WAF)
The Azure Well-Architected Framework (WAF) is a design framework that can improve the quality of a workload by helping it to:
- Be resilient, available, and recoverable.
- Be as secure as you need it to be.
- Deliver a sufficient return on investment.
- Support responsible development and operations.
- Accomplish its purpose within acceptable timeframes.
The framework is founded on the five pillars of architectural excellence, which are mapped to those goals. They are: Reliability, Security, Cost Optimization, Operational Excellence, and Performance Efficiency.
Each pillar provides recommended practices, risk considerations, and tradeoffs. The design decisions must be balanced across all pillars, given the business requirements. The technical and actionable guidance is broad enough for all workloads and applies to a specific scenario. This guidance is centered on Azure.
Microsoft Cloud Adoption Framework (CAF)
Microsoft Responsible AI (RAI)
- Fairness
- Reliability and safety
- Privacy and security
- Transparency
- Accountability
- Inclusiveness
Microsoft Security Adoption Framework (SAF)
The Security Adoption Framework (SAF) provides guidance for organizations through end-to-end security modernization across a ‘hybrid of everything’ multi-cloud and multi-platform technical estate.
Network and Information Security Directive (NIS2)
NIS2 aims to enhance the security of network and information systems within the EU by requiring operators of critical infrastructure and essential services to implement appropriate security measures and report any incidents to the relevant authorities.
