GOVERNANCE

Standards crosswalk explorer

The frameworks largely say the same things in different vocabularies. Pick a control area, put the five columns side by side, and narrate the same requirement in each framework's language. A teaching aid — not an official mapping or compliance attestation.

Side-by-side: Governance & risk oversight
NIST CSF 2.0
GOVERN (GV) — whole function
NIST SP 800-53 r5.2.0
PM family; RA-1; PL-1
ISO/IEC 27001:2022
A.5 Organizational (5.1–5.8 policies, roles)
CIS Controls v8.1
Control 14 (Security awareness) + program governance across IGs
ISA/IEC 62443
Part 2-1 (CSMS / program); FR-driven risk management
Practiced in:Week 1Week 12
Control areaNIST CSF 2.0NIST SP 800-53 r5.2.0ISO/IEC 27001:2022CIS Controls v8.1ISA/IEC 62443
Governance & risk oversightGOVERN (GV) — whole functionPM family; RA-1; PL-1A.5 Organizational (5.1–5.8 policies, roles)Control 14 (Security awareness) + program governance across IGsPart 2-1 (CSMS / program); FR-driven risk management
Asset inventory & managementIDENTIFY (ID.AM)CM-8; PM-5A.5.9–A.5.10 (asset inventory, acceptable use)Control 1 (Enterprise assets); Control 2 (Software assets)SR 7.8 (asset inventory); zones/conduits identification
Risk assessmentIDENTIFY (ID.RA)RA family (RA-3, RA-5)A.5 + Clause 6.1 (risk process)Underlies IG selection; Control 7 (Vuln mgmt)ZCR risk assessment; SL-target determination
Identity & access controlPROTECT (PR.AA)AC family; IA familyA.5.15–A.5.18; A.8.2–A.8.5 (access, privileged, auth)Control 5 (Account mgmt); Control 6 (Access control)FR 1 — Identification & Authentication Control; FR 2 — Use Control
Data protection & cryptographyPROTECT (PR.DS)SC family; MP familyA.8.10–A.8.12; A.8.24 (crypto)Control 3 (Data protection)FR 4 — Data Confidentiality; FR 3 — System Integrity
Secure configuration & hardeningPROTECT (PR.PS)CM family; SC-7A.8.9 (configuration mgmt)Control 4 (Secure configuration)SR 7.6 (network & security config); hardening guidance
Network security & segmentationPROTECT (PR.IR / PR.PS)SC-7; AC-4A.8.20–A.8.22 (network security, segregation)Control 12 (Network infrastructure); Control 13 (Network monitoring)FR 5 — Restricted Data Flow (zones & conduits, IDMZ)
Vulnerability & patch managementIDENTIFY (ID.RA) / PROTECT (PR.PS)RA-5; SI-2; SA-11A.8.8 (technical vulnerabilities)Control 7 (Continuous vulnerability mgmt)SR 3.4/3.10 (integrity, patch); Part 2-3 patch mgmt
Logging & monitoring / detectionDETECT (DE.CM / DE.AE)AU family; SI-4A.8.15–A.8.16 (logging, monitoring)Control 8 (Audit log mgmt); Control 13 (Network monitoring)FR 6 — Timely Response to Events; FR 7 — Resource Availability
Malware & endpoint defensePROTECT (PR.PS) / DETECT (DE.CM)SI-3; SI-4A.8.7 (protection against malware)Control 10 (Malware defenses)FR 3 — System Integrity; SR 3.2 (malicious code protection)
Email & web / social-engineering defensePROTECT (PR.AT) / DETECT (DE.CM)AT-2; SC-7; SI-8A.6.3 (awareness); A.8.23 (web filtering)Control 9 (Email/web protections); Control 14 (Awareness)Part 2-1 personnel/awareness; FR 1 (auth to resist spoofing)
Secure software developmentPROTECT (PR.PS) / IDENTIFY (ID.RA)SA family (SA-8, SA-11, SA-15); SR familyA.8.25–A.8.28 (secure development)Control 16 (Application software security)Part 4-1 (secure product development lifecycle – SDL)
Supply-chain & third-party riskGOVERN (GV.SC)SR family; SA-4; SA-9A.5.19–A.5.23 (supplier relationships)Control 15 (Service provider mgmt)Part 4-1 SM; component-level SR requirements
Data recovery & continuityRECOVER (RC.RP) / PROTECT (PR.DS)CP family; CP-9 (backup)A.8.13 (backup); A.5.29–A.5.30 (continuity)Control 11 (Data recovery)FR 7 — Resource Availability; SR 7.3/7.4 (backup, recovery)
Incident responseRESPOND (RS) + RECOVER (RC)IR family (IR-4, IR-6, IR-8)A.5.24–A.5.28 (incident mgmt)Control 17 (Incident response mgmt)FR 6 — Timely Response to Events; Part 2-1 IR
Penetration testing & control validationIDENTIFY (ID.RA) / DETECTCA-8; RA-5; SA-11A.8.8 + Clause 9 (evaluation)Control 18 (Penetration testing)SL verification testing; conduit/zone validation
Physical & environmental securityPROTECT (PR.AA / PR.IR)PE familyA.7 Physical (7.1–7.14)Cross-cutting (asset & facility controls)Physical access to zones; SR 2.x use control at site

Versions: NIST CSF 2.0 (2024); NIST SP 800-53 Release 5.2.0 (2025); ISO/IEC 27001:2022 Annex A; CIS Controls v8.1 (2024); ISA/IEC 62443 (FRs and 3-3 SRs). Current as of September 2026 — confirm each row against the latest published source before any audit use. Framework alignment is not certification and not legal compliance.