Skip to content

Lesson 1 of 4

Free preview

Choosing a framework for the question you have

CIS to decide what to do, ISO 27001 to prove a programme exists, NIST CSF to have the conversation.

13 min 3-question quiz 3 guides to read next

On this page
  1. To know what to do next
  2. To prove a programme exists
  3. To structure the conversation
  4. Sector obligations
  5. The practical answer

Framework arguments are usually a proxy for an unasked question: why are we assessing at all? The answer picks the framework.

To know what to do next

CIS Controls are a prioritised list of technical safeguards, ordered roughly by what prevents the most common attacks: asset and software inventory, data protection, secure configuration, account and access management, vulnerability management, logging, malware defences, recovery. Implementation Groups scale the expectation by organisation size.

Use it when the honest position is "we know we are behind and need an order of work".

To prove a programme exists

ISO/IEC 27001 specifies a management system: scope, risk assessment, treatment, objectives, competence, internal audit and management review, with Annex A as a reference control set. It is certifiable, which is usually the actual reason it is chosen — customers ask for the certificate.

Note what this means: certification says a managed system exists, not that any particular control is strong. Both are worth having and they are not the same claim.

To structure the conversation

NIST Cybersecurity Framework organises outcomes under Govern, Identify, Protect, Detect, Respond and Recover, with current and target profiles. It is a vocabulary and a gap-analysis tool, and it is unusually good at explaining a programme to people outside it.

Sector obligations

Payment card, health, critical infrastructure and financial regulation bring their own requirements, and those are not optional. Map them to whatever you adopt rather than running separate programmes — one control set, several mappings, is far cheaper than several programmes.

The practical answer

Most organisations end up with CIS for doing, ISO 27001 for proving, and the NIST language for reporting. Pick deliberately, record the mapping once, and collect evidence as you go rather than reconstructing it a month before an audit.

Check your understanding

3 questions · pass with 2 correct

1. Which framework best answers 'what should we do next'?
2. What does an ISO 27001 certificate assert?
3. How should sector obligations be handled alongside a framework?

You'll see your score; enrol to have it count towards your certificate.

Enrol for free to save your progress, unlock every lesson and earn a certificate.

Sign in to enrol

Further reading

Guides that go deeper on this lesson.