CROSSWALK MAPPINGVerified Data

Mapping NIST Cybersecurity Framework to ISO/IEC 27001

A practitioner-grade, domain-level crosswalk between NIST Cybersecurity Framework and ISO/IEC 27001. Understand how these compliance standards overlap to streamline your audit programs.

Basis for Alignment

NIST publishes an official informative-reference mapping from CSF 2.0 to ISO/IEC 27001:2022 through its Online Informative References (OLIR) catalog and CSF 2.0 Reference Tool (nist.gov/cyberframework/informative-references).

Overall Confidence:high
Last Verified:2026-08-07

Domain Correspondences

NIST Cybersecurity Framework
GV: GOVERN
ISO/IEC 27001
A.5: Organizational Controls

ISO's Organizational Controls theme covers policy, roles, and supply-chain security — the same governance ground CSF 2.0 formalized into the new GOVERN function.

NIST Cybersecurity Framework
ID: IDENTIFY
ISO/IEC 27001
A.5: Organizational Controls

Asset management and information classification within Organizational Controls correspond to CSF's IDENTIFY function, which covers asset management and risk assessment.

NIST Cybersecurity Framework
RS: RESPOND
ISO/IEC 27001
A.5: Organizational Controls

ISO 27001's incident-management controls sit within the Organizational theme, matching CSF's RESPOND function for incident handling and reporting.

NIST Cybersecurity Framework
RC: RECOVER
ISO/IEC 27001
A.5: Organizational Controls

Business-continuity controls within the Organizational theme correspond to CSF's RECOVER function for executing and communicating recovery plans.

NIST Cybersecurity Framework
PR: PROTECT
ISO/IEC 27001
A.6: People Controls

People Controls (screening, training, off-boarding) map to the awareness-and-training component explicitly named in CSF's PROTECT function.

NIST Cybersecurity Framework
PR: PROTECT
ISO/IEC 27001
A.8: Technological Controls

Technological Controls' access management, authentication, and data-security provisions are the technical core of CSF's PROTECT function.

NIST Cybersecurity Framework
DE: DETECT
ISO/IEC 27001
A.8: Technological Controls

Technological Controls' monitoring and vulnerability-management provisions correspond to CSF's DETECT function for continuous monitoring and event analysis.

Explore Interactively

Use our interactive crosswalk matrix to explore mappings between NIST Cybersecurity Framework, ISO/IEC 27001, and 10 other compliance frameworks simultaneously.

Open Interactive Matrix