Map a control once, satisfy every framework it touches
Most organisations are assessed against more than one standard, and most
standards ask for the same things in different words. Multi-factor
authentication satisfies a NIST CSF subcategory, an ISO 27001 Annex A control,
and a CIS safeguard simultaneously. Recording that once is the difference
between a week of work and an afternoon.
NIST Cybersecurity Framework
2.0
A voluntary framework of cybersecurity outcomes organised into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Widely used as the common language between security teams and executives, and the basis for many sector regulations.
The international standard for information security management systems. Annex A lists 93 controls across organizational, people, physical, and technological themes, which an organization selects from and justifies in a Statement of Applicability.
A prioritised set of eighteen defensive actions, ordered so that implementing them in sequence blocks the most common attack patterns first. Useful as an implementation roadmap alongside an outcome framework such as NIST CSF.
Each requirement is assessed as fully, largely, partially, or not implemented,
and the score is the weighted average. The decision that matters most is how
requirements you have scoped out are treated.
A requirement marked not applicable is excluded from the calculation
entirely, from both the numerator and the denominator. Counting it as
satisfied would let an organisation reach a hundred per cent by scoping
everything out; counting it as a failure would punish honest scoping. Scoping
everything out therefore produces a zero, not a hundred, which is the correct
answer to "how much have you demonstrated".
An overall NIST CSF implementation tier is suggested from the twenty-fifth
percentile of per-requirement ratings rather than the mean, because a programme
is only as repeatable as its least repeatable practice.
On copyright
Control titles and reference identifiers are reproduced so you can navigate and
report. ISO/IEC 27001's normative guidance text is copyright ISO and must be
licensed separately, so the product links out to it rather than embedding it. The
NIST framework is a US government publication and is freely available.