GOVERNANCE
Standards crosswalk explorer
The frameworks largely say the same things in different vocabularies. Pick a control area, put the five columns side by side, and narrate the same requirement in each framework's language. A teaching aid — not an official mapping or compliance attestation.
Side-by-side: Governance & risk oversight
NIST CSF 2.0
GOVERN (GV) — whole function
NIST SP 800-53 r5.2.0
PM family; RA-1; PL-1
ISO/IEC 27001:2022
A.5 Organizational (5.1–5.8 policies, roles)
CIS Controls v8.1
Control 14 (Security awareness) + program governance across IGs
ISA/IEC 62443
Part 2-1 (CSMS / program); FR-driven risk management
| Control area | NIST CSF 2.0 | NIST SP 800-53 r5.2.0 | ISO/IEC 27001:2022 | CIS Controls v8.1 | ISA/IEC 62443 |
|---|---|---|---|---|---|
| Governance & risk oversight | GOVERN (GV) — whole function | PM family; RA-1; PL-1 | A.5 Organizational (5.1–5.8 policies, roles) | Control 14 (Security awareness) + program governance across IGs | Part 2-1 (CSMS / program); FR-driven risk management |
| Asset inventory & management | IDENTIFY (ID.AM) | CM-8; PM-5 | A.5.9–A.5.10 (asset inventory, acceptable use) | Control 1 (Enterprise assets); Control 2 (Software assets) | SR 7.8 (asset inventory); zones/conduits identification |
| Risk assessment | IDENTIFY (ID.RA) | RA family (RA-3, RA-5) | A.5 + Clause 6.1 (risk process) | Underlies IG selection; Control 7 (Vuln mgmt) | ZCR risk assessment; SL-target determination |
| Identity & access control | PROTECT (PR.AA) | AC family; IA family | A.5.15–A.5.18; A.8.2–A.8.5 (access, privileged, auth) | Control 5 (Account mgmt); Control 6 (Access control) | FR 1 — Identification & Authentication Control; FR 2 — Use Control |
| Data protection & cryptography | PROTECT (PR.DS) | SC family; MP family | A.8.10–A.8.12; A.8.24 (crypto) | Control 3 (Data protection) | FR 4 — Data Confidentiality; FR 3 — System Integrity |
| Secure configuration & hardening | PROTECT (PR.PS) | CM family; SC-7 | A.8.9 (configuration mgmt) | Control 4 (Secure configuration) | SR 7.6 (network & security config); hardening guidance |
| Network security & segmentation | PROTECT (PR.IR / PR.PS) | SC-7; AC-4 | A.8.20–A.8.22 (network security, segregation) | Control 12 (Network infrastructure); Control 13 (Network monitoring) | FR 5 — Restricted Data Flow (zones & conduits, IDMZ) |
| Vulnerability & patch management | IDENTIFY (ID.RA) / PROTECT (PR.PS) | RA-5; SI-2; SA-11 | A.8.8 (technical vulnerabilities) | Control 7 (Continuous vulnerability mgmt) | SR 3.4/3.10 (integrity, patch); Part 2-3 patch mgmt |
| Logging & monitoring / detection | DETECT (DE.CM / DE.AE) | AU family; SI-4 | A.8.15–A.8.16 (logging, monitoring) | Control 8 (Audit log mgmt); Control 13 (Network monitoring) | FR 6 — Timely Response to Events; FR 7 — Resource Availability |
| Malware & endpoint defense | PROTECT (PR.PS) / DETECT (DE.CM) | SI-3; SI-4 | A.8.7 (protection against malware) | Control 10 (Malware defenses) | FR 3 — System Integrity; SR 3.2 (malicious code protection) |
| Email & web / social-engineering defense | PROTECT (PR.AT) / DETECT (DE.CM) | AT-2; SC-7; SI-8 | A.6.3 (awareness); A.8.23 (web filtering) | Control 9 (Email/web protections); Control 14 (Awareness) | Part 2-1 personnel/awareness; FR 1 (auth to resist spoofing) |
| Secure software development | PROTECT (PR.PS) / IDENTIFY (ID.RA) | SA family (SA-8, SA-11, SA-15); SR family | A.8.25–A.8.28 (secure development) | Control 16 (Application software security) | Part 4-1 (secure product development lifecycle – SDL) |
| Supply-chain & third-party risk | GOVERN (GV.SC) | SR family; SA-4; SA-9 | A.5.19–A.5.23 (supplier relationships) | Control 15 (Service provider mgmt) | Part 4-1 SM; component-level SR requirements |
| Data recovery & continuity | RECOVER (RC.RP) / PROTECT (PR.DS) | CP family; CP-9 (backup) | A.8.13 (backup); A.5.29–A.5.30 (continuity) | Control 11 (Data recovery) | FR 7 — Resource Availability; SR 7.3/7.4 (backup, recovery) |
| Incident response | RESPOND (RS) + RECOVER (RC) | IR family (IR-4, IR-6, IR-8) | A.5.24–A.5.28 (incident mgmt) | Control 17 (Incident response mgmt) | FR 6 — Timely Response to Events; Part 2-1 IR |
| Penetration testing & control validation | IDENTIFY (ID.RA) / DETECT | CA-8; RA-5; SA-11 | A.8.8 + Clause 9 (evaluation) | Control 18 (Penetration testing) | SL verification testing; conduit/zone validation |
| Physical & environmental security | PROTECT (PR.AA / PR.IR) | PE family | A.7 Physical (7.1–7.14) | Cross-cutting (asset & facility controls) | Physical access to zones; SR 2.x use control at site |
Versions: NIST CSF 2.0 (2024); NIST SP 800-53 Release 5.2.0 (2025); ISO/IEC 27001:2022 Annex A; CIS Controls v8.1 (2024); ISA/IEC 62443 (FRs and 3-3 SRs). Current as of September 2026 — confirm each row against the latest published source before any audit use. Framework alignment is not certification and not legal compliance.