Skip to content
IT Atlas

Secure

How the standards relate

Practitioners are rarely confused about what NIST CSF or ISO 27001 say. They are confused about which one to use for a given question, and how the four documents on the table overlap. This page places each framework in the layer where it belongs, maps the same control across them, and gives a defensible order of adoption.

Layers, not competitors

Each framework operates at a different level of abstraction. Conflict usually comes from using one at the wrong level.

Governance and direction, what the organisation must decide
COBIT 2019ISO 27001 clauses 4, 10NIST CSF 2.0 Govern function
Outcomes and risk language, what good looks like, described once
NIST CSF 2.0 (Identify, Protect, Detect, Respond, Recover)ISO 27005NIST RMF
Control catalogues, the statements you assess against
ISO 27002 controlsNIST SP 800-53 Rev. 5CIS Controls v8.1 Safeguards
Prioritised implementation, what to do first
CIS Controls Implementation Groups 1, 3CIS Benchmarksvendor security baselines
Adversary behaviour, proof the controls face real activity
MITRE ATT&CK EnterpriseMITRE D3FENDNIST SP 800-61 response process
Service and operational practice, how the work runs
ITIL 4 practicesISO 20000SRE practice (error budgets, toil reduction)

Choosing by question asked

Which framework answers which question
The question being askedUseWhy this one
What outcomes should our security programme produce, in language a board accepts?NIST CSF 2.0Six functions and a risk vocabulary, deliberately technology neutral and free to use.
What should we actually do first, with limited people?CIS Controls v8.1Safeguards ordered into implementation groups, so scope matches organisational capability.
How do we prove to a customer or regulator that security is managed?ISO/IEC 27001The only one of these that is certifiable; it audits the management system, not just controls.
How do we harden a specific product to a defensible configuration?CIS Benchmarks and vendor baselinesSetting level guidance with rationale, per platform and version.
Do our detections cover how intruders actually behave?MITRE ATT&CK EnterpriseA shared technique taxonomy that turns coverage into something measurable.
How should the service desk, changes and incidents be run?ITIL 4Service management practices covering value streams, change enablement and incident flow.
Who decides, who is accountable, and how is IT value governed?COBIT 2019Governance objectives separating direction and oversight from execution.
What does a mature federal grade control set look like in detail?NIST SP 800-53 Rev. 5The most granular catalogue, useful as a reference even outside US federal scope.
How do we architect access without a trusted internal network?NIST SP 800-207Defines Zero Trust architecture components and the policy decision and enforcement split.
How do we run an incident end to end?NIST SP 800-61Preparation, detection and analysis, containment, eradication, recovery, lessons learned.

One control, four vocabularies

Mappings are approximate by nature: control statements have different scopes and the boundaries do not align perfectly. Use them to avoid duplicate work, not as a certification shortcut.

The same control seen through four frameworks
OutcomeNIST CSF 2.0CIS Controls v8.1ISO/IEC 27001:2022
Know what you haveID.AM, Asset ManagementControls 1 and 2, enterprise and software assetsA.5.9, A.5.10
Authenticate and authorise accessPR.AA, Identity, Authentication, Access ControlControls 5 and 6, accounts and access managementA.5.15 to A.5.18, A.8.2, A.8.5
Configure and maintain systemsPR.PS, Platform SecurityControls 4 and 7, secure configuration and vulnerability managementA.8.8, A.8.9, A.8.19
Collect and monitor telemetryDE.CM, Continuous MonitoringControl 8, audit log managementA.8.15, A.8.16
Recover from data lossPR.DS and RC.RP, data security and recovery executionControl 11, data recoveryA.8.13, A.5.29, A.5.30
Manage suppliersGV.SC, Cybersecurity Supply Chain Risk ManagementControl 15, service provider managementA.5.19 to A.5.22
Respond to incidentsRS.MA and RS.CO, incident management and communicationControl 17, incident response managementA.5.24 to A.5.28

Order of adoption

A defensible order of adoption
  1. 1Pick one outcome language and stop translating: for most organisations that is NIST CSF 2.0.
  2. 2Assess current state against those outcomes honestly, evidence in hand, and record the gaps.
  3. 3Choose the CIS implementation group that matches your actual capacity, not your ambition.
  4. 4Implement the foundational safeguards, inventory, identity, configuration, logging, recovery.
  5. 5Map detections to ATT&CK techniques and record the coverage you have deliberately chosen not to build.
  6. 6Adopt ITIL practices for the operational disciplines that keep the controls working day to day.
  7. 7Only then pursue ISO 27001 certification, if a customer, tender or regulator requires it.

Running four framework programmes simultaneously produces four sets of documentation and one unchanged risk profile.

Where organisations get this wrong

Common failures

  • Treating a framework as a checklist to be closed rather than a set of outcomes to be sustained. Controls decay; assessment is a state, not a project.
  • Adopting a control catalogue with no prioritisation, then implementing alphabetically instead of by risk.
  • Certifying a narrow scope and describing the whole organisation as certified.
  • Building detection content with no technique mapping, so coverage cannot be stated or defended.
  • Writing policy in framework language nobody in the operational teams reads or applies.

What good looks like

  • One outcome vocabulary used consistently in board reporting, risk register and control assessment.
  • A control set with named owners, an evidence artefact each, and a review date.
  • Assessment results expressed as trend over time, not a single maturity number.
  • Detection coverage mapped to techniques, with deliberate gaps recorded and accepted.
  • Exceptions with compensating controls and expiry dates, reviewed rather than accumulated.

The frameworks in detail

Steward, purpose and best use for each framework referenced above.

NIST (US)

NIST Cybersecurity Framework 2.0

Organise cybersecurity outcomes into functions that can be assessed and communicated to leadership.

Best used for
Assessing overall security posture and building an improvement roadmap that non specialists can follow.

Primary source

Center for Internet Security

CIS Critical Security Controls v8

Provide a prioritised, prescriptive set of defensive actions with implementation groups by organisation size.

Best used for
Deciding what to do next, and hardening systems using the accompanying CIS Benchmarks.

Primary source

ISO / IEC

ISO/IEC 27001 & 27002

Define requirements for an information security management system, with a reference control set.

Best used for
Formal certification and demonstrating systematic management of information security risk.

Primary source

NIST (US)

NIST SP 800-53 & the Risk Management Framework

Provide a comprehensive control catalogue and a process for authorising systems based on risk.

Best used for
Environments with formal authorisation requirements or a need for exhaustive control coverage.

Primary source

Axelos / PeopleCert

ITIL 4

Describe service management practices and a value system for delivering and improving IT services.

Best used for
Structuring incident, request, change, problem, asset and configuration practices.

Primary source

ISACA

COBIT 2019

Provide a governance framework linking enterprise objectives to IT objectives, processes and metrics.

Best used for
Establishing decision rights, accountability and measurement for IT as a whole.

Primary source

MITRE

MITRE ATT&CK

Catalogue adversary tactics, techniques and procedures observed in the real world.

Best used for
Measuring detection coverage, planning hunts and communicating adversary behaviour precisely.

Primary source

NIST (US)

NIST SP 800-207, Zero Trust Architecture

Define Zero Trust concepts, logical components and deployment patterns in vendor neutral terms.

Best used for
Grounding a Zero Trust programme in an architecture rather than a product roadmap.

Primary source

Microsoft, AWS, Google (parallel frameworks)

Cloud Adoption & Well Architected Frameworks

Guide cloud adoption strategy and evaluate workload design against defined quality pillars.

Best used for
Establishing a landing zone and reviewing workloads before and after production.

Primary source

NIST (US)

NIST SP 800-61, Incident Handling

Define an incident response lifecycle with practical guidance on preparation and handling.

Best used for
Writing and testing an incident response plan and playbooks.

Primary source

Full field-by-field comparison is on the frameworks and standards page, and the control statements themselves are on control baselines.