Skip to content
atlas

Don't confuse these

ISO 27000 series vs NIST Cybersecurity Framework (CSF)

Why they differ

The ISO series is a set of certifiable standards; the NIST framework is a free, voluntary guide without certification.

ISO 27000 series

Compliance & regulation

The family of international standards for information security, with ISO 27001 at its centre and guides built around it.

Formal

A set of ISO/IEC standards on information security management - ISO 27000 (shared terms and the big picture), ISO 27001 (requirements for an ISMS, the only one you can be certified against), ISO 27002 (guidance on controls), ISO 27005 (risk management) and many more for specific areas.

In plain English

Like the booklets that come with a new car - one lists what the car must meet to pass its inspection, and the others explain the brakes, the lights and the engine in detail.

In practice

A Danish payroll service building its ISMS uses ISO 27001 for what it must do, ISO 27002 for how to carry out each control, and ISO 27005 to shape its method for assessing risk.

Why it matters

The series gives a shared, worldwide language for security, so customers, auditors and authorities can compare organisations on the same terms.

NIST Cybersecurity Framework (CSF)

Compliance & regulation

A free US framework that sorts security work into six broad goals, from steering it to recovering after an attack.

Formal

A voluntary framework from the US National Institute of Standards and Technology, first published in February 2014 and updated to version 2.0 in February 2024. Version 2.0 groups outcomes into six functions - Govern, Identify, Protect, Detect, Respond and Recover - and lets a firm compare a current profile with a target profile.

In plain English

A map with six regions rather than a checklist - it shows where you are, where you want to be and which roads connect them, but not exactly how to drive.

In practice

The security lead at a Danish software company with US customers scores the firm against the six functions, finds Detect and Recover weak, and uses the gap between current and target profile to argue for next year's budget.

Why it matters

Leaders and technical staff often talk past each other about security; the framework gives them one free, shared language that suits any size of firm and maps onto ISO 27001 and the CIS Controls.

Shared connections

Atlas is in beta.