Skip to content
atlas

Don't confuse these

ISO 27001 vs NIST Cybersecurity Framework (CSF)

Why they differ

ISO 27001 is a management system a firm can be certified against; the NIST CSF is a free, voluntary framework of outcomes with no certificate.

ISO 27001

Compliance & regulation

The international standard for running an information security management system that can be certified.

Formal

An international standard, current edition 2022, whose clauses 4-10 set the requirements for an information security management system - context, leadership, planning, support, operation, performance evaluation and improvement - with Annex A listing 93 controls to choose from.

In plain English

A set of house rules for running security as a daily routine rather than a one-off clean-up - written so that an outside inspector can check it is really followed.

In practice

Danish state bodies must follow ISO 27001, so the security lead at a ministry uses its clauses to set the scope, run the risk assessment, pick controls from Annex A and report maturity each year - without seeking a certificate.

Why it matters

Without a common measure every customer, auditor and authority would ask for security to be shown in a different way; ISO 27001 gives one structure that can be recognised, audited and mapped to laws such as NIS2.

NIST Cybersecurity Framework (CSF)

Compliance & regulation

A free US framework that sorts security work into six broad goals, from steering it to recovering after an attack.

Formal

A voluntary framework from the US National Institute of Standards and Technology, first published in February 2014 and updated to version 2.0 in February 2024. Version 2.0 groups outcomes into six functions - Govern, Identify, Protect, Detect, Respond and Recover - and lets a firm compare a current profile with a target profile.

In plain English

A map with six regions rather than a checklist - it shows where you are, where you want to be and which roads connect them, but not exactly how to drive.

In practice

The security lead at a Danish software company with US customers scores the firm against the six functions, finds Detect and Recover weak, and uses the gap between current and target profile to argue for next year's budget.

Why it matters

Leaders and technical staff often talk past each other about security; the framework gives them one free, shared language that suits any size of firm and maps onto ISO 27001 and the CIS Controls.

Shared connections

Atlas is in beta.