Information Security Frameworks: NIST, ISO, CIS
Compare major information security frameworks including NIST CSF, ISO 27001, and CIS Controls, with guidance on how IS auditors evaluate framework adoption.
Why Security Frameworks Matter
Information security frameworks provide structured approaches to managing cybersecurity risk. For IS auditors, understanding these frameworks is essential because they serve as benchmarks for evaluating an organization's security posture. The CISA exam expects candidates to understand the purpose, structure, and application of major security frameworks and how auditors assess organizational compliance with them.
Frameworks help organizations establish consistent security practices, communicate security requirements to stakeholders, and demonstrate due diligence to regulators and business partners.
NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework, developed by the National Institute of Standards and Technology, organizes security activities into five core functions:
- Identify: Asset management, risk assessment, governance, and business environment understanding
- Protect: Access control, awareness training, data security, and protective technology
- Detect: Anomaly detection, continuous monitoring, and detection processes
- Respond: Response planning, communications, analysis, mitigation, and improvements
- Recover: Recovery planning, improvements, and communications
The framework includes implementation tiers (Partial, Risk Informed, Repeatable, Adaptive) that describe the degree of rigor in an organization's cybersecurity practices. Auditors can use these tiers to assess maturity levels.
ISO/IEC 27001
ISO 27001 is an international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information through a defined set of policies, processes, and controls. Key elements include:
- Plan-Do-Check-Act (PDCA) cycle: A continuous improvement model for the ISMS
- Risk assessment methodology: A structured approach to identifying and treating information security risks
- Statement of Applicability (SoA): Documentation of which controls from Annex A are applicable and implemented
- Internal audit requirements: Regular audits to verify ISMS effectiveness
Organizations can achieve ISO 27001 certification through external audits conducted by accredited certification bodies. IS auditors should understand the certification process and how to evaluate whether an organization's ISMS is effectively implemented.
CIS Controls
The Center for Internet Security (CIS) Controls provide a prioritized set of actions to protect organizations from common cyber attacks. The controls are organized into three implementation groups based on organizational size and risk profile:
- Implementation Group 1 (IG1): Essential cyber hygiene for all organizations
- Implementation Group 2 (IG2): Additional controls for organizations with moderate risk
- Implementation Group 3 (IG3): Comprehensive controls for organizations managing sensitive data or facing sophisticated threats
Audit Considerations
When evaluating framework adoption, IS auditors should assess whether the selected framework is appropriate for the organization's industry and risk profile, whether implementation is genuine or superficial, whether gaps between the framework requirements and actual practices are documented and tracked, and whether management regularly reviews the security program against the framework. Auditors should also verify that framework adoption is supported by adequate resources and executive sponsorship.