Frameworks (ISO 27001, NIST, ENS, CIS)
Security frameworks give a recognized structure to govern cybersecurity: which controls to implement, how to measure them, and how to demonstrate them. Choosing and combining the right framework avoids reinventing the wheel and eases compliance and certification.
The main frameworks
Section titled “The main frameworks”ISO/IEC 27001 CERTIFIABLE standard for an ISMS (Information Security Management System) Annex A (controls, ISO 27002); risk-management approach + continuous improvementNIST CSF framework (Identify, Protect, Detect, Respond, Recover, +Govern in v2.0) flexible, by function; widely used as a common languageENS (Spain) National Security Scheme: MANDATORY for the Spanish public sector and its providers; basic/medium/high categories (RD 311/2022)CIS Controls 18 prioritized, actionable controls (groups IG1/IG2/IG3); very technicalWhen to use each
Section titled “When to use each”ISO 27001 when you need to be CERTIFIED (clients/contracts require it); formal managementNIST CSF to structure the program and communicate with management (maturity by function)ENS mandatory if you work with/for the Spanish public administrationCIS to START with the technical and prioritized (IG1 = basic hygiene)# they combine: ISO 27001 for governance + CIS for concrete technical controlsISO 27001 — the ISMS
Section titled “ISO 27001 — the ISMS”- context, leadership, planning (risk assessment), support, operation, evaluation, improvement- Statement of Applicability (SoA): which Annex A controls apply and why- PDCA cycle (Plan-Do-Check-Act): continuous improvement- internal audit + certification audit (see grc-auditoria)NIST CSF 2.0 (functions)
Section titled “NIST CSF 2.0 (functions)”Govern (new in 2.0) governance and risk managementIdentify assets, risks, contextProtect preventive controls (access, training, data)Detect event detection (see def-deteccion)Respond incident response (see dfir)Recover recovery (see def-backup)Mapping between frameworks
Section titled “Mapping between frameworks”- the frameworks OVERLAP: one control (e.g. MFA) meets requirements of several at once- mapping controls across ISO/NIST/ENS/CIS avoids duplicating work (comply once, demonstrate in several)- official tools and "crosswalks" ease the mappingBlue Team / GRC
Section titled “Blue Team / GRC”- Choose the framework by obligation (ENS for public sector, ISO 27001 if certification is required) and combine with CIS for the technical side.
- Base everything on the risk assessment (Risk management): controls respond to real risks.
- Map controls across frameworks to comply once and demonstrate in several.
- Continuous improvement (PDCA) with audit (Audit & compliance) and metrics; don’t “certify and forget”.
Real cases and fines
Section titled “Real cases and fines”- Contracts and tenders (especially public ones in Spain) that require ENS or ISO 27001.
- Organizations starting with CIS IG1 (basic hygiene) reduce most of the risk at low cost.
- NIST CSF as a common language between technical staff and management in maturity programs.
Testing checklist
Section titled “Testing checklist”- Identify mandatory frameworks (ENS, sectoral) and client-required (ISO 27001)
- Base controls on a risk assessment (Risk management)
- ISO 27001: ISMS, SoA, and PDCA if seeking certification
- CIS Controls (IG1 first) for the prioritized technical part
- NIST CSF to structure and communicate maturity
- Map controls across frameworks (avoid duplication)
- Audit and continuous improvement (Audit & compliance)