This document provides guidance on how to leverage existing ISO and IEC standards in a cybersecurity framework.