CROSSWALK MAPPINGVerified Data

Mapping ISO/IEC 27001 to NIST Cybersecurity Framework

A practitioner-grade, domain-level crosswalk between ISO/IEC 27001 and NIST Cybersecurity Framework. Understand how these compliance standards overlap to streamline your audit programs.

Basis for Alignment

NIST publishes an official informative-reference mapping from CSF 2.0 to ISO/IEC 27001:2022 through its Online Informative References (OLIR) catalog and CSF 2.0 Reference Tool (nist.gov/cyberframework/informative-references).

Overall Confidence:high
Last Verified:2026-08-07

Domain Correspondences

ISO/IEC 27001
A.5: Organizational Controls
NIST Cybersecurity Framework
GV: GOVERN

ISO's Organizational Controls theme covers policy, roles, and supply-chain security — the same governance ground CSF 2.0 formalized into the new GOVERN function.

ISO/IEC 27001
A.5: Organizational Controls
NIST Cybersecurity Framework
ID: IDENTIFY

Asset management and information classification within Organizational Controls correspond to CSF's IDENTIFY function, which covers asset management and risk assessment.

ISO/IEC 27001
A.5: Organizational Controls
NIST Cybersecurity Framework
RS: RESPOND

ISO 27001's incident-management controls sit within the Organizational theme, matching CSF's RESPOND function for incident handling and reporting.

ISO/IEC 27001
A.5: Organizational Controls
NIST Cybersecurity Framework
RC: RECOVER

Business-continuity controls within the Organizational theme correspond to CSF's RECOVER function for executing and communicating recovery plans.

ISO/IEC 27001
A.6: People Controls
NIST Cybersecurity Framework
PR: PROTECT

People Controls (screening, training, off-boarding) map to the awareness-and-training component explicitly named in CSF's PROTECT function.

ISO/IEC 27001
A.8: Technological Controls
NIST Cybersecurity Framework
PR: PROTECT

Technological Controls' access management, authentication, and data-security provisions are the technical core of CSF's PROTECT function.

ISO/IEC 27001
A.8: Technological Controls
NIST Cybersecurity Framework
DE: DETECT

Technological Controls' monitoring and vulnerability-management provisions correspond to CSF's DETECT function for continuous monitoring and event analysis.

Explore Interactively

Use our interactive crosswalk matrix to explore mappings between ISO/IEC 27001, NIST Cybersecurity Framework, and 10 other compliance frameworks simultaneously.

Open Interactive Matrix