Frameworks

Map a control once, satisfy every framework it touches

Most organisations are assessed against more than one standard, and most standards ask for the same things in different words. Multi-factor authentication satisfies a NIST CSF subcategory, an ISO 27001 Annex A control, and a CIS safeguard simultaneously. Recording that once is the difference between a week of work and an afternoon.

NIST Cybersecurity Framework

2.0

A voluntary framework of cybersecurity outcomes organised into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Widely used as the common language between security teams and executives, and the basis for many sector regulations.

Publisher
National Institute of Standards and Technology
Requirements
106 assessable
Maturity
Four implementation tiers
Read the standard

ISO/IEC 27001

2022

The international standard for information security management systems. Annex A lists 93 controls across organizational, people, physical, and technological themes, which an organization selects from and justifies in a Statement of Applicability.

Publisher
International Organization for Standardization
Requirements
93 assessable
Read the standard

CIS Critical Security Controls

8.1

A prioritised set of eighteen defensive actions, ordered so that implementing them in sequence blocks the most common attack patterns first. Useful as an implementation roadmap alongside an outcome framework such as NIST CSF.

Publisher
Center for Internet Security
Requirements
18 assessable
Read the standard

How assessment scoring works

Each requirement is assessed as fully, largely, partially, or not implemented, and the score is the weighted average. The decision that matters most is how requirements you have scoped out are treated.

A requirement marked not applicable is excluded from the calculation entirely, from both the numerator and the denominator. Counting it as satisfied would let an organisation reach a hundred per cent by scoping everything out; counting it as a failure would punish honest scoping. Scoping everything out therefore produces a zero, not a hundred, which is the correct answer to "how much have you demonstrated".

An overall NIST CSF implementation tier is suggested from the twenty-fifth percentile of per-requirement ratings rather than the mean, because a programme is only as repeatable as its least repeatable practice.

On copyright

Control titles and reference identifiers are reproduced so you can navigate and report. ISO/IEC 27001's normative guidance text is copyright ISO and must be licensed separately, so the product links out to it rather than embedding it. The NIST framework is a US government publication and is freely available.

× Something went wrong. Reload the page to continue.