A practitioner-grade, domain-level crosswalk between NIST Cybersecurity Framework and ISO/IEC 27001. Understand how these compliance standards overlap to streamline your audit programs.
NIST publishes an official informative-reference mapping from CSF 2.0 to ISO/IEC 27001:2022 through its Online Informative References (OLIR) catalog and CSF 2.0 Reference Tool (nist.gov/cyberframework/informative-references).
ISO's Organizational Controls theme covers policy, roles, and supply-chain security — the same governance ground CSF 2.0 formalized into the new GOVERN function.
Asset management and information classification within Organizational Controls correspond to CSF's IDENTIFY function, which covers asset management and risk assessment.
ISO 27001's incident-management controls sit within the Organizational theme, matching CSF's RESPOND function for incident handling and reporting.
Business-continuity controls within the Organizational theme correspond to CSF's RECOVER function for executing and communicating recovery plans.
People Controls (screening, training, off-boarding) map to the awareness-and-training component explicitly named in CSF's PROTECT function.
Technological Controls' access management, authentication, and data-security provisions are the technical core of CSF's PROTECT function.
Technological Controls' monitoring and vulnerability-management provisions correspond to CSF's DETECT function for continuous monitoring and event analysis.
Use our interactive crosswalk matrix to explore mappings between NIST Cybersecurity Framework, ISO/IEC 27001, and 10 other compliance frameworks simultaneously.
Open Interactive Matrix