While the NIST Cybersecurity Framework (CSF) provides guidance to manage cybersecurity risks, it does not contain prescriptive controls.
It is possible for an organizations to leverage an existing ISO 27001 Information Security Management System (ISMS) to implement NIST CSF functions, categories and subcategories.
NIST CSF 2.0 is organized according to six (6) Functions, supported by twenty-two (22) Categories with a further one-hundred and six (106) Subcategories. Steps to leverage an ISO-based ISMS would include:
By combining ISO 27001’s management rigor with NIST CSF’s cybersecurity focus, organizations create a robust, scalable cybersecurity program aligned with business goals and compliance requirements.