One organization, three regulators, five frameworks. The secret to not duplicating effort is mastering control mapping — showing how one well-designed control satisfies requirements across multiple frameworks simultaneously.
| Framework | Purpose | Mandatory? | Best For |
|---|---|---|---|
| NIST CSF 2.0 | Risk-based cybersecurity governance | No (US federal agencies yes) | All organizations; strategic baseline |
| ISO 27001 | ISMS certification standard | No (certification optional) | Organizations seeking external certification |
| COBIT 2019 | IT governance and management | No | Large enterprises; IT audit focus |
| NIST 800-53 | Security and privacy controls catalog | Yes (US federal) | Federal agencies and contractors |
| PCI-DSS | Payment card security | Yes (card processors) | Any org processing payment cards |
| SOC 2 | Trust Services assurance | No (customer-driven) | SaaS/cloud service providers |
NIST CSF 2.0 (released 2024) reorganized the framework into 6 core functions, adding GOVERN to the original 5:
Establishes and monitors the organization's cybersecurity risk management strategy, expectations, and policy. Covers governance, risk management strategy, roles and responsibilities, policies, and supply chain risk. Reflects the recognition that governance is the foundation of all other functions.
Develop an understanding of the organization's risk environment. Asset management, business environment, governance, risk assessment, risk management strategy, supply chain. You cannot protect what you do not know you have.
Develop and implement appropriate safeguards to limit impact. Identity management, access control, awareness training, data security, process/procedure protection, maintenance, protective technology.
Develop and implement activities to identify cybersecurity events. Anomalies and events, security continuous monitoring, detection processes. Identifies when a security event occurs.
Take action regarding a detected cybersecurity incident. Response planning, communications, analysis, mitigation, improvements. Limits impact of security events.
Maintain plans for resilience and restore impaired capabilities. Recovery planning, improvements, communications. Restores normal operations after an incident.
ISO 27001:2022 is the only internationally recognized certification standard for information security management. Its structure:
The ISMS framework requirements: Context, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement. All mandatory for certification — no exclusions permitted.
93 controls across 4 themes (People, Organisational, Physical, Technological). Organizations select applicable controls based on risk assessment. Non-applicable controls must be justified in the Statement of Applicability (SoA).
The SoA is the critical document that maps each Annex A control to the organization, stating: applicable or not, justification, implementation status, and evidence reference. The SoA is the core deliverable for ISO 27001 certification.
ISO 27001 requires control selection to be driven by the risk assessment. Controls chosen arbitrarily (not risk-justified) will not satisfy an ISO 27001 auditor. Every selected control must trace back to a risk in the register.
A control crosswalk maps each control to every framework requirement it satisfies. Example crosswalk for Multi-Factor Authentication:
| Control | NIST CSF 2.0 | ISO 27001 | NIST 800-53 | PCI-DSS | SOC 2 |
|---|---|---|---|---|---|
| MFA for privileged access | PR.AA-01, PR.AA-03 | A.8.5, A.8.2 | IA-2(1), IA-2(2) | Req 8.4 | CC6.1, CC6.3 |
| Access review (quarterly) | PR.AA-05 | A.5.18, A.8.2 | AC-2 | Req 7.2, 8.2 | CC6.2, CC6.3 |
| Encryption at rest (AES-256) | PR.DS-01 | A.8.24 | SC-28 | Req 3.5 | CC6.1 |
| Security awareness training (annual) | PR.AT-01 | A.6.3 | AT-2 | Req 12.6 | CC1.4, CC2.2 |
A mature organization implements controls once, maps them to all applicable frameworks, and tests them once — satisfying multiple compliance requirements with a single evidence collection exercise.
A gap analysis compares your current control implementation against a framework's requirements, identifying deficiencies and prioritizing remediation:
Choose the target framework and scope (e.g., NIST CSF for enterprise security program, or ISO 27001 Annex A for ISMS certification). Scoping determines which controls apply.
Document all currently implemented controls with implementation status (fully implemented, partially implemented, not implemented) and evidence availability.
For each framework requirement, identify which existing control(s) address it. Gaps are requirements with no existing control or only partial coverage.
Score gaps by risk exposure. High-risk gaps (directly related to top risk register items) are highest priority. Low-risk gaps in non-critical areas can be deferred.
Assign owners, budgets, and timelines to each gap. Prioritize by risk score. Report progress to governance quarterly. Use gap closure metrics as a program maturity indicator.
You are a GRC analyst at a company subject to NIST CSF 2.0, ISO 27001, and GDPR. Complete each crosswalk task to build the core technique that cuts integrated compliance effort by 40–60%.