Skip to content

CIS Controls, ISO 27001 and NIST CSF Compared

Three frameworks, three different jobs — and how to choose without buying all of them.

Editorial team 2 min read

These three come up in every programme discussion and answer different questions.

CIS Controls

A prioritised list of technical safeguards, ordered roughly by what stops the most common attacks first: inventory, software inventory, data protection, secure configuration, account management, vulnerability management, logging. Implementation Groups scale it by organisation size.

Best for: a team that needs to know what to do next.

ISO/IEC 27001

A management system standard. It specifies how you run an information security programme — scope, risk assessment, treatment, objectives, internal audit, management review — with Annex A as a reference set of controls. It is certifiable, which is often the real reason it is adopted.

Best for: demonstrating to customers and regulators that a programme exists and is managed.

NIST Cybersecurity Framework

A set of outcomes grouped under Govern, Identify, Protect, Detect, Respond and Recover, with profiles for current and target state. It is a vocabulary and a gap-analysis tool rather than a checklist.

Best for: structuring a conversation with leadership about where to invest.

Choosing

Most organisations end up with two: one for doing (CIS) and one for proving (ISO 27001), with the NIST CSF as the language for reporting. Mapping between them is routine, so the choice matters less than picking one and keeping evidence as you go, rather than reconstructing it before an audit.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025