Skip to content
IT Atlas

Reference

Frameworks and standards

Frameworks are not interchangeable and they are not competitors. Each answers a different question: what outcomes matter, what to do next, how to prove it, how to run services, and how adversaries actually behave. This page states the purpose of each and how they fit together.

10 frameworks

Choosing between them

  • Need to describe posture to leadership and set a target state, start with NIST CSF.
  • Need a prioritised list of technical work, use CIS Controls, and CIS Benchmarks for hardening.
  • Need certifiable assurance for customers or contracts, ISO/IEC 27001.
  • Need exhaustive control depth or formal authorisation, NIST SP 800-53 with the RMF.
  • Need to run service operations predictably, ITIL 4, governed above by COBIT.
  • Need to measure detection coverage, MITRE ATT&CK.
  • Need to ground a Zero Trust programme in architecture, NIST SP 800-207.
  • Need to build or review cloud workloads, the cloud adoption and well architected frameworks.

The frameworks

NIST Cybersecurity Framework 2.0

NIST (US)

Organise cybersecurity outcomes into functions that can be assessed and communicated to leadership.

Audience
Any organisation; widely used as a common language between technical teams and executives.
Best used for
Assessing overall security posture and building an improvement roadmap that non specialists can follow.
Core concepts
GovernIdentifyProtectDetectRespondRecoverProfiles and tiers for current and target state
Relationship to others
Maps to CIS Controls and ISO 27001 control sets; often used as the umbrella with CIS providing the technical detail.
Primary source

CIS Critical Security Controls v8

Center for Internet Security

Provide a prioritised, prescriptive set of defensive actions with implementation groups by organisation size.

Audience
Practitioners who want concrete, ordered technical work rather than outcome statements.
Best used for
Deciding what to do next, and hardening systems using the accompanying CIS Benchmarks.
Core concepts
18 controls with safeguardsImplementation Groups 1, 3Asset and software inventory firstBenchmarks for hardening
Relationship to others
Maps to NIST CSF and ISO 27001; the Benchmarks complement endpoint and server baselines.
Primary source

ISO/IEC 27001 & 27002

ISO / IEC

Define requirements for an information security management system, with a reference control set.

Audience
Organisations needing certifiable assurance, often driven by customer or contractual requirements.
Best used for
Formal certification and demonstrating systematic management of information security risk.
Core concepts
ISMS scope and contextRisk assessment and treatmentStatement of applicabilityAnnex A control themesInternal audit and management review
Relationship to others
Control set overlaps substantially with CIS and NIST; ISO 27005 covers risk, 27017/27018 cover cloud and privacy.
Primary source

NIST SP 800-53 & the Risk Management Framework

NIST (US)

Provide a comprehensive control catalogue and a process for authorising systems based on risk.

Audience
Federal systems, contractors, and enterprises wanting depth beyond a prioritised list.
Best used for
Environments with formal authorisation requirements or a need for exhaustive control coverage.
Core concepts
Control familiesBaselines by impact levelPrepare, categorise, select, implement, assess, authorise, monitorContinuous monitoring
Relationship to others
Underpins FedRAMP; maps to CSF functions and to ISO 27001 Annex A.
Primary source

ITIL 4

Axelos / PeopleCert

Describe service management practices and a value system for delivering and improving IT services.

Audience
Service desks, operations teams and IT leadership.
Best used for
Structuring incident, request, change, problem, asset and configuration practices.
Core concepts
Service value systemGuiding principles34 management practicesContinual improvement
Relationship to others
Complements COBIT for governance; overlaps with SRE practice in monitoring and incident response.
Primary source

COBIT 2019

ISACA

Provide a governance framework linking enterprise objectives to IT objectives, processes and metrics.

Audience
CIOs, governance forums, internal audit.
Best used for
Establishing decision rights, accountability and measurement for IT as a whole.
Core concepts
Governance and management objectivesDesign factorsPerformance managementAlignment to enterprise goals
Relationship to others
Governs above ITIL's operational practices; often paired with ISO 27001 for security management.
Primary source

MITRE ATT&CK

MITRE

Catalogue adversary tactics, techniques and procedures observed in the real world.

Audience
Detection engineers, threat hunters, red and purple teams.
Best used for
Measuring detection coverage, planning hunts and communicating adversary behaviour precisely.
Core concepts
Tactics as adversary goalsTechniques and sub techniquesEnterprise, Mobile and ICS matricesMitigations and data sources
Relationship to others
Complements NIST CSF's Detect and Respond functions; the ICS matrix is the OT counterpart.
Primary source

NIST SP 800-207, Zero Trust Architecture

NIST (US)

Define Zero Trust concepts, logical components and deployment patterns in vendor neutral terms.

Audience
Architects and security leaders designing access control models.
Best used for
Grounding a Zero Trust programme in an architecture rather than a product roadmap.
Core concepts
Policy decision and enforcement pointsPer session authorisationResource centric protectionTrust algorithm inputs
Relationship to others
CISA's Zero Trust Maturity Model provides staged assessment against these principles.
Primary source

Cloud Adoption & Well Architected Frameworks

Microsoft, AWS, Google (parallel frameworks)

Guide cloud adoption strategy and evaluate workload design against defined quality pillars.

Audience
Cloud architects, platform teams and programme leads.
Best used for
Establishing a landing zone and reviewing workloads before and after production.
Core concepts
Strategy, plan, ready, adopt, govern, manageLanding zonesReliability, security, cost, operations and performance pillarsWorkload review process
Relationship to others
Governance elements align with COBIT and ISO 27001; security pillar aligns with CSF.
Primary source

NIST SP 800-61, Incident Handling

NIST (US)

Define an incident response lifecycle with practical guidance on preparation and handling.

Audience
Security operations, incident responders, IT leadership.
Best used for
Writing and testing an incident response plan and playbooks.
Core concepts
PreparationDetection and analysisContainment, eradication and recoveryPost incident activity
Relationship to others
Pairs with CISA playbooks for operational detail and with ISO 27035 as an international equivalent.
Primary source

A note on OT frameworks

Industrial environments use a different set, IEC 62443, NIST SP 800-82, the Purdue reference model and MITRE ATT&CK for ICS. Applying IT frameworks unmodified to control systems produces requirements that cannot safely be met. Those frameworks are covered on OT Atlas.