Secure
How the standards relate
Practitioners are rarely confused about what NIST CSF or ISO 27001 say. They are confused about which one to use for a given question, and how the four documents on the table overlap. This page places each framework in the layer where it belongs, maps the same control across them, and gives a defensible order of adoption.
Layers, not competitors
Each framework operates at a different level of abstraction. Conflict usually comes from using one at the wrong level.
Choosing by question asked
| The question being asked | Use | Why this one |
|---|---|---|
| What outcomes should our security programme produce, in language a board accepts? | NIST CSF 2.0 | Six functions and a risk vocabulary, deliberately technology neutral and free to use. |
| What should we actually do first, with limited people? | CIS Controls v8.1 | Safeguards ordered into implementation groups, so scope matches organisational capability. |
| How do we prove to a customer or regulator that security is managed? | ISO/IEC 27001 | The only one of these that is certifiable; it audits the management system, not just controls. |
| How do we harden a specific product to a defensible configuration? | CIS Benchmarks and vendor baselines | Setting level guidance with rationale, per platform and version. |
| Do our detections cover how intruders actually behave? | MITRE ATT&CK Enterprise | A shared technique taxonomy that turns coverage into something measurable. |
| How should the service desk, changes and incidents be run? | ITIL 4 | Service management practices covering value streams, change enablement and incident flow. |
| Who decides, who is accountable, and how is IT value governed? | COBIT 2019 | Governance objectives separating direction and oversight from execution. |
| What does a mature federal grade control set look like in detail? | NIST SP 800-53 Rev. 5 | The most granular catalogue, useful as a reference even outside US federal scope. |
| How do we architect access without a trusted internal network? | NIST SP 800-207 | Defines Zero Trust architecture components and the policy decision and enforcement split. |
| How do we run an incident end to end? | NIST SP 800-61 | Preparation, detection and analysis, containment, eradication, recovery, lessons learned. |
One control, four vocabularies
Mappings are approximate by nature: control statements have different scopes and the boundaries do not align perfectly. Use them to avoid duplicate work, not as a certification shortcut.
| Outcome | NIST CSF 2.0 | CIS Controls v8.1 | ISO/IEC 27001:2022 |
|---|---|---|---|
| Know what you have | ID.AM, Asset Management | Controls 1 and 2, enterprise and software assets | A.5.9, A.5.10 |
| Authenticate and authorise access | PR.AA, Identity, Authentication, Access Control | Controls 5 and 6, accounts and access management | A.5.15 to A.5.18, A.8.2, A.8.5 |
| Configure and maintain systems | PR.PS, Platform Security | Controls 4 and 7, secure configuration and vulnerability management | A.8.8, A.8.9, A.8.19 |
| Collect and monitor telemetry | DE.CM, Continuous Monitoring | Control 8, audit log management | A.8.15, A.8.16 |
| Recover from data loss | PR.DS and RC.RP, data security and recovery execution | Control 11, data recovery | A.8.13, A.5.29, A.5.30 |
| Manage suppliers | GV.SC, Cybersecurity Supply Chain Risk Management | Control 15, service provider management | A.5.19 to A.5.22 |
| Respond to incidents | RS.MA and RS.CO, incident management and communication | Control 17, incident response management | A.5.24 to A.5.28 |
Order of adoption
- 1Pick one outcome language and stop translating: for most organisations that is NIST CSF 2.0.
- 2Assess current state against those outcomes honestly, evidence in hand, and record the gaps.
- 3Choose the CIS implementation group that matches your actual capacity, not your ambition.
- 4Implement the foundational safeguards, inventory, identity, configuration, logging, recovery.
- 5Map detections to ATT&CK techniques and record the coverage you have deliberately chosen not to build.
- 6Adopt ITIL practices for the operational disciplines that keep the controls working day to day.
- 7Only then pursue ISO 27001 certification, if a customer, tender or regulator requires it.
Running four framework programmes simultaneously produces four sets of documentation and one unchanged risk profile.
Where organisations get this wrong
Common failures
- Treating a framework as a checklist to be closed rather than a set of outcomes to be sustained. Controls decay; assessment is a state, not a project.
- Adopting a control catalogue with no prioritisation, then implementing alphabetically instead of by risk.
- Certifying a narrow scope and describing the whole organisation as certified.
- Building detection content with no technique mapping, so coverage cannot be stated or defended.
- Writing policy in framework language nobody in the operational teams reads or applies.
What good looks like
- One outcome vocabulary used consistently in board reporting, risk register and control assessment.
- A control set with named owners, an evidence artefact each, and a review date.
- Assessment results expressed as trend over time, not a single maturity number.
- Detection coverage mapped to techniques, with deliberate gaps recorded and accepted.
- Exceptions with compensating controls and expiry dates, reviewed rather than accumulated.
The frameworks in detail
Steward, purpose and best use for each framework referenced above.
NIST (US)
NIST Cybersecurity Framework 2.0
Organise cybersecurity outcomes into functions that can be assessed and communicated to leadership.
Best used for
Assessing overall security posture and building an improvement roadmap that non specialists can follow.
Center for Internet Security
CIS Critical Security Controls v8
Provide a prioritised, prescriptive set of defensive actions with implementation groups by organisation size.
Best used for
Deciding what to do next, and hardening systems using the accompanying CIS Benchmarks.
ISO / IEC
ISO/IEC 27001 & 27002
Define requirements for an information security management system, with a reference control set.
Best used for
Formal certification and demonstrating systematic management of information security risk.
NIST (US)
NIST SP 800-53 & the Risk Management Framework
Provide a comprehensive control catalogue and a process for authorising systems based on risk.
Best used for
Environments with formal authorisation requirements or a need for exhaustive control coverage.
Axelos / PeopleCert
ITIL 4
Describe service management practices and a value system for delivering and improving IT services.
Best used for
Structuring incident, request, change, problem, asset and configuration practices.
ISACA
COBIT 2019
Provide a governance framework linking enterprise objectives to IT objectives, processes and metrics.
Best used for
Establishing decision rights, accountability and measurement for IT as a whole.
MITRE
MITRE ATT&CK
Catalogue adversary tactics, techniques and procedures observed in the real world.
Best used for
Measuring detection coverage, planning hunts and communicating adversary behaviour precisely.
NIST (US)
NIST SP 800-207, Zero Trust Architecture
Define Zero Trust concepts, logical components and deployment patterns in vendor neutral terms.
Best used for
Grounding a Zero Trust programme in an architecture rather than a product roadmap.
Microsoft, AWS, Google (parallel frameworks)
Cloud Adoption & Well Architected Frameworks
Guide cloud adoption strategy and evaluate workload design against defined quality pillars.
Best used for
Establishing a landing zone and reviewing workloads before and after production.
NIST (US)
NIST SP 800-61, Incident Handling
Define an incident response lifecycle with practical guidance on preparation and handling.
Best used for
Writing and testing an incident response plan and playbooks.
Full field-by-field comparison is on the frameworks and standards page, and the control statements themselves are on control baselines.
