Skip to content

Frameworks (ISO 27001, NIST, ENS, CIS)

Security frameworks give a recognized structure to govern cybersecurity: which controls to implement, how to measure them, and how to demonstrate them. Choosing and combining the right framework avoids reinventing the wheel and eases compliance and certification.

ISO/IEC 27001 CERTIFIABLE standard for an ISMS (Information Security Management System)
Annex A (controls, ISO 27002); risk-management approach + continuous improvement
NIST CSF framework (Identify, Protect, Detect, Respond, Recover, +Govern in v2.0)
flexible, by function; widely used as a common language
ENS (Spain) National Security Scheme: MANDATORY for the Spanish public sector
and its providers; basic/medium/high categories (RD 311/2022)
CIS Controls 18 prioritized, actionable controls (groups IG1/IG2/IG3); very technical
ISO 27001 when you need to be CERTIFIED (clients/contracts require it); formal management
NIST CSF to structure the program and communicate with management (maturity by function)
ENS mandatory if you work with/for the Spanish public administration
CIS to START with the technical and prioritized (IG1 = basic hygiene)
# they combine: ISO 27001 for governance + CIS for concrete technical controls
- context, leadership, planning (risk assessment), support, operation, evaluation, improvement
- Statement of Applicability (SoA): which Annex A controls apply and why
- PDCA cycle (Plan-Do-Check-Act): continuous improvement
- internal audit + certification audit (see grc-auditoria)
Govern (new in 2.0) governance and risk management
Identify assets, risks, context
Protect preventive controls (access, training, data)
Detect event detection (see def-deteccion)
Respond incident response (see dfir)
Recover recovery (see def-backup)
- the frameworks OVERLAP: one control (e.g. MFA) meets requirements of several at once
- mapping controls across ISO/NIST/ENS/CIS avoids duplicating work (comply once, demonstrate in several)
- official tools and "crosswalks" ease the mapping
  • Choose the framework by obligation (ENS for public sector, ISO 27001 if certification is required) and combine with CIS for the technical side.
  • Base everything on the risk assessment (Risk management): controls respond to real risks.
  • Map controls across frameworks to comply once and demonstrate in several.
  • Continuous improvement (PDCA) with audit (Audit & compliance) and metrics; don’t “certify and forget”.
  • Contracts and tenders (especially public ones in Spain) that require ENS or ISO 27001.
  • Organizations starting with CIS IG1 (basic hygiene) reduce most of the risk at low cost.
  • NIST CSF as a common language between technical staff and management in maturity programs.
  • Identify mandatory frameworks (ENS, sectoral) and client-required (ISO 27001)
  • Base controls on a risk assessment (Risk management)
  • ISO 27001: ISMS, SoA, and PDCA if seeking certification
  • CIS Controls (IG1 first) for the prioritized technical part
  • NIST CSF to structure and communicate maturity
  • Map controls across frameworks (avoid duplication)
  • Audit and continuous improvement (Audit & compliance)