Lesson 1 of 4
Choosing a framework for the question you have
CIS to decide what to do, ISO 27001 to prove a programme exists, NIST CSF to have the conversation.
13 min 3-question quiz 3 guides to read next
On this page
Framework arguments are usually a proxy for an unasked question: why are we assessing at all? The answer picks the framework.
To know what to do next
CIS Controls are a prioritised list of technical safeguards, ordered roughly by what prevents the most common attacks: asset and software inventory, data protection, secure configuration, account and access management, vulnerability management, logging, malware defences, recovery. Implementation Groups scale the expectation by organisation size.
Use it when the honest position is "we know we are behind and need an order of work".
To prove a programme exists
ISO/IEC 27001 specifies a management system: scope, risk assessment, treatment, objectives, competence, internal audit and management review, with Annex A as a reference control set. It is certifiable, which is usually the actual reason it is chosen — customers ask for the certificate.
Note what this means: certification says a managed system exists, not that any particular control is strong. Both are worth having and they are not the same claim.
To structure the conversation
NIST Cybersecurity Framework organises outcomes under Govern, Identify, Protect, Detect, Respond and Recover, with current and target profiles. It is a vocabulary and a gap-analysis tool, and it is unusually good at explaining a programme to people outside it.
Sector obligations
Payment card, health, critical infrastructure and financial regulation bring their own requirements, and those are not optional. Map them to whatever you adopt rather than running separate programmes — one control set, several mappings, is far cheaper than several programmes.
The practical answer
Most organisations end up with CIS for doing, ISO 27001 for proving, and the NIST language for reporting. Pick deliberately, record the mapping once, and collect evidence as you go rather than reconstructing it a month before an audit.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
CIS Controls, ISO 27001 and NIST CSF Compared
Three frameworks, three different jobs — and how to choose without buying all of them.
2 min read
-
Building a Secure AI Programme
How organisations can organise AI security: ownership, inventory, policy, controls and continuous improvement.
1 min read
-
Evidence and Sampling in Control Assessments
Testing whether a control works, not whether somebody says it does.
2 min read