=Paper= {{Paper |id=Vol-3288/paper3 |storemode=property |title=Analysis and Comparison of the NIST SP 800-53 and ISO/IEC 27001:2013 |pdfUrl=https://ceur-ws.org/Vol-3288/paper3.pdf |volume=Vol-3288 |authors=Yevhenii Kurii,Ivan Opirskyy |dblpUrl=https://dblp.org/rec/conf/cpits/KuriiO22 }} ==Analysis and Comparison of the NIST SP 800-53 and ISO/IEC 27001:2013== https://ceur-ws.org/Vol-3288/paper3.pdf
Analysis and Comparison of the NIST SP 800-53
and ISO/IEC 27001:2013
Yevhenii Kurii1 and Ivan Opirskyy1
1
    Lviv Polytechnic National University, 12 Stepan Bandera str., Lviv, 79000, Ukraine

                  Abstract
                  Managing information security in the organization may be a daunting task, especially
                  considering that it may encompass many areas from physical and network security to human
                  resources security and management of suppliers. This may be especially hard for young
                  specialists or not experienced enough specialists, who may miss some important areas due to
                  lack of practical experience. This is where security frameworks come in handy and put formality
                  into the process of the design and implementation of the security strategy. With a framework in
                  place, it becomes much easier to define the processes and procedures that your organization
                  must take to assess, monitor, and mitigate cybersecurity risk and apply proper controls to protect
                  valuable information. But another problem came up when you are to choose the “just right”
                  framework for your organization taking into account more business-specific characteristics like
                  the context of the organization, area of operation, applicable laws, regulations and contractual
                  obligations, as well as more general ones like framework’s maturity, comprehensiveness or
                  popularity. While there are a bunch of different information security frameworks out in the
                  wild, the most commonly-found and preferred by security professionals worldwide are NIST
                  SP 800-53 and ISO/IEC 27001:2013. They combine both the quite comprehensive set of
                  security controls to cover the most important security areas and wide applicability which allows
                  applying these frameworks to all kinds of organizations. But they also have a set of distinct
                  features, that define their relevance to the particular organization. The article is aimed at giving
                  a brief overview of these two most popular security frameworks as well as describing their key
                  characteristics and providing a comparison of their controls.

                  Keywords 1
                  Information security, cybersecurity framework, security controls, information security
                  management system, ISMS, ISO 27001, NIST 800-53, controls mapping.


1. Introduction                                                                                            These frameworks are a blueprint for managing
                                                                                                        and reducing organizational risk. Information
                                                                                                        security professionals use frameworks to define
    To successfully achieve the objectives of
                                                                                                        and prioritize the tasks required to manage the
implementing cybersecurity at different levels, a
                                                                                                        organization's security program. Frameworks are
range of procedures and standards should be
                                                                                                        also used to help prepare for compliance and other
followed. Cybersecurity standards determine the
                                                                                                        IT and security audits. When you are choosing
requirements that an organization should follow to
                                                                                                        from the number of leading information security
achieve cybersecurity objectives and facilitate
                                                                                                        frameworks, you would primarily assess the
against cybercrimes [1] and ensure the ongoing
                                                                                                        number of unique information security controls
management of information security controls.
                                                                                                        (requirements) in each of them [3–5].
    Additionally, the framework establishes a
common language for defining a cybersecurity
program, enabling organizations to set risk-based
cybersecurity goals at the executive level that can
be translated to the operations team [2].

CPITS-2022: Cybersecurity Providing in Information and Telecommunication Systems, October 13, 2022, Kyiv, Ukraine
EMAIL: yevhenii.o.kurii@lpnu.ua (Y. Kurii); ivan.r.opirskyi@lpnu.ua (I. Opirskyy)
ORCID: 0000-0002-3423-5655 (Y. Kurii); 0000-0002-8461-8996 (I. Opirskyy)
              ©️ 2022 Copyright for this paper by its authors.
              Use permitted under Creative Commons License Attribution 4.0 International (CC BY 4.0).
              CEUR Workshop Proceedings (CEUR-WS.org)



                                                                                               21
Figure 1: Information security frameworks based on their specialization and coverage

    The volume of these controls directly impacts         the framework of frameworks) to address more
the number of domains covered by that                     complex compliance requirements (e.g., when the
framework. The lesser number of controls in a             organization is holding the personal data of EU
framework might make it easier to implement, but          citizens and process cardholder data, it should
it also might not provide the necessary coverage          comply with both GDPR and PCI DSS
that your organization needs from the perspective         requirements).
of administrative, technical, and physical                    A key consideration for choosing an
information security practices [6].                       information security framework would be
    This is where defining the applicable and             understanding the level of content and robustness
relevant framework is primarily a business                each framework offers. This will directly impact
decision [7], based on your organization's context        the available information security controls within
and risk profile, which needs to consider                 each framework [24].
applicable laws and regulations, that are required
to support existing or planned business processes.        2. Overview     and   Comparison
    Commonly, this selection process generally
leads to adopting one of the following                       between NIST SP 800-53 and
frameworks:                                                  ISO/IEC 27001:2013
 ISO 27001/002 [8, 9]
 NIST Special Publication 800-53 [10]                        The Special Publication (SP) 800-53 Security
 NIST Cybersecurity Framework [11]                       and Privacy Controls for Information Systems and
 PCI DSS [12]                                            Organizations from the National Institute of
 CIS Controls [13, 14]                                   Standards and Technology (NIST) is currently in
 HITRUST Common Security Framework [15]                  its 5th revision (rev5) dated September 2020. It
 HIPAA [16]                                              was initially designed to protect the US federal
 CSA CCM [17]                                            government, but quickly gained popularity among
 GDPR [18]                                               private industry and now is considered as one of
 ISO 27701 [19]                                          the most popular and respectable information
 AICPA Trust Services Criteria (SOC 2) [20]              security frameworks in the world. It was partially
                                                          caused due to the significant outsourcing to private
 COBIT [21]
                                                          companies that do business with the US federal
    Each information security framework has its
                                                          government.
own unique specialization and depth of coverage.
                                                              According to the official web page of the
However, understanding this can help you make
                                                          standard “This publication [Special Publication
an informed decision on the most appropriate
                                                          (SP) 800-53] provides a catalog of security and
framework for your needs. [22, 23] You may even
                                                          privacy controls for information systems and
find you need to leverage a metaframework (e.g.,


                                                     22
Table 1                                                       organizations to protect organizational operations
Key differences between NIST SP 800-53 to ISO                 and assets, individuals, other organizations, and
27001                                                         the Nation from a diverse set of threats and risks,
                        NIST               ISO                including hostile attacks, human errors, natural
                                                              disasters, structural failures, foreign intelligence
                 A recognized
                 framework that
                                                              entities, and privacy risks” [25].
                 contains security
                                                                 SO 27001 is a well-respected international
                                     An                       information security standard that outlines the key
                 and privacy
                                     internationally          processes and approaches a business needs to
                 controls for
                                     recognized               manage information security risk in a practical
                 information
                                     standard that            way [26]. ISO 27001 consists of the main part and
                 systems and
 Description                         describes how            Annex A, that contains the basic overview of the
                 organizations to
                                     to manage                security controls needed to build an Information
                 protect
                                     information              Security      Management        System      (ISMS).
                 organizational
                                     security in an           Additionally, there is a separate standard ISO
                 operations and
                                     organization             27002 that provides a detailed description of the
                 assets with aim
                 to effectively                               specific controls that are necessary to actually
                 manage risk                                  implement ISO 27001 (essentially, you can't meet
                                     Can be                   ISO 27001 without implementing ISO 27002).
                                     implemented              [27, 28]. The important thing about ISO is that it
                                     in any kind of           provides the companies with the possibility to
                 Was primarily
                                     organization,            undergo an external audit and get certified against
 Target          created to help
                                     profit or non-           ISO 27001.
 organizations   US federal
                                     profit, private
                 agencies
                                     or state-
                                     owned, small
                                                              2.1.      Detailed Mapping of Controls
                                     or large
                                                                 Table 2 provides a mapping from the security
                                     Annex A
                 Contains 1007                                controls in NIST Special Publication 800-53 to the
                                     provides 14
                 controls broken                              security controls in ISO/IEC 27001:2013 [29].
 Structure                           control
                 down into 20
                                     categories with          Table 2
                 control families
                                     114 controls             Mapping NIST SP 800-53 to ISO 27001
                                     Is less
                                     technical, with                                        ISO/IEC 27001
                 Is very detailed    more emphasis                                            CONTROLS
                                                                        NIST SP 800-53        Note: An asterisk (*)     Effected CIA triad
 Complexity      and technical in    on risk-based                                         indicates that the ISO/IEC
                                                                                                                             element
                                                                          CONTROLS           control does not fully
                 its nature          approach to                                            satisfy the intent of the
                                                                                                  NIST control.
                                     managing
                                     security                                            5.2, 5.3, 7.5.1,
                                                                                         7.5.2, 7.5.3,
                                     Enables                                             A.5.1.1, A.5.1.2,
                                                                   Access Control Policy
                                     companies to             AC-1
                                                                   and Procedures
                                                                                         A.6.1.1, A.9.1.1,
                                     become                                              A.12.1.1,
                 Is voluntary and                                                        A.18.1.1,
                                     certified, relies
                 relies on self-                                                         A.18.2.2
 Certification                       on
                 assessment and                                      Account
                                                                                          A.9.2.1, A.9.2.2,
                                     independent              AC-2                        A.9.2.3, A.9.2.5,
                 self-compliance                                     Management
                                     audit and                                            A.9.2.6
                                     certification                                        A.6.2.2, A.9.1.2,
                                     bodies                                               A.9.4.1, A.9.4.4,
                                                                                          A.9.4.5,
                                     Distributed on           AC-3 Access Enforcement     A.13.1.1,
                 Can be freely
                                     the commercial                                       A.14.1.2,
                 downloaded
 Availability                        basis through                                        A.14.1.3,
                 from official                                                            A.18.1.3
                                     the official
                 source                                                                   A.13.1.3,
                                     website
                                                                     Information Flow     A.13.2.1,
                                                              AC-4
                                                                     Enforcement          A.14.1.2,
                                                                                          A.14.1.3




                                                         23
AC-5 Separation of Duties A.6.1.2                                                                        5.2, 5.3, 7.5.1,
                               A.9.1.2, A.9.2.3,                                                         7.5.2, 7.5.3,
AC-6 Least Privilege                                                               Audit and             A.5.1.1, A.5.1.2,
                               A.9.4.4, A.9.4.5
                                                                              AU-1 Accountability Policy A.6.1.1,
        Unsuccessful Logon                                                         and Procedures        A.12.1.1,
AC-7                           A.9.4.2
        Attempts                                                                                         A.18.1.1,
        System Use                                                                                       A.18.2.2
AC-8                           A.9.4.2
        Notification                                                                                                          Confidentiality,
                                                                              AU-2 Event Logging            None
        Previous Logon                                                                                                        Integrity, Availability
AC-9                           A.9.4.2
        Notification                                                                  Content of Audit
                                                                              AU-3                          A.12.4.1*
      Concurrent Session                           Confidentiality,                   Records
AC-10                          None
      Control                                      Integrity                          Audit Log Storage
                                                                              AU-4                          A.12.1.3
                               A.11.2.8,                                              Capacity
AC-11 Device Lock
                               A.11.2.9                                            Response to Audit
                                                   Confidentiality,           AU-5 Logging Process          None              Integrity, Availability
AC-12 Session Termination None
                                                   Integrity                       Failures
AC-13 Withdrawn                ---                                                 Audit Record Review, A.12.4.1,
      Permitted Actions                                                       AU-6 Analysis, and        A.16.1.2,
                                                   Confidentiality,                Reporting            A.16.1.4
AC-14 without Identification None
                                                   Integrity
      or Authentication                                                            Audit Record
AC-15 Withdrawn                ---                                            AU-7 Reduction and            None              Integrity, Availability
                                                                                   Report Generation
        Security and Privacy                       Confidentiality,
AC-16                          None                                           AU-8 Time Stamps              A.12.4.4
        Attributes                                 Integrity
                               A.6.2.1, A.6.2.2,                                                            A.12.4.2,
                                                                                      Protection of Audit
                               A.13.1.1,                                      AU-9                          A.12.4.3,
AC-17 Remote Access                                                                   Information
                               A.13.2.1,                                                                    A.18.1.3
                               A.14.1.2                                       AU-10 Non-repudiation         None              Integrity
                               A.6.2.1,                                             Audit Record            A.12.4.1,
                                                                              AU-11
AC-18 Wireless Access          A.13.1.1,                                            Retention               A.16.1.7
                               A.13.2.1                                               Audit Record          A.12.4.1,
                                                                              AU-12
                               A.6.2.1,                                               Generation            A.12.4.3
        Access Control for     A.11.1.5,                                            Monitoring for
AC-19
        Mobile Devices         A.11.2.6,                                      AU-13 Information             None              Confidentiality
                               A.13.2.1                                             Disclosure
                               A.11.2.6,                                      AU-14 Session Audit           A.12.4.1*
        Use of External
AC-20                          A.13.1.1,
        Systems                                                               AU-15 Withdrawn               ---
                               A.13.2.1
AC-21 Information Sharing      None                Confidentiality                  Cross-Organizational                      Confidentiality,
                                                                              AU-16                      None
                                                                                    Audit Logging                             Integrity
        Publicly Accessible
AC-22                          None                Confidentiality                                        5.2, 5.3, 7.5.1,
        Content
                                                                                                          7.5.2, 7.5.3,
        Data Mining                                Confidentiality,                Assessment and         A.5.1.1, A.5.1.2,
AC-23                          None
        Protection                                 Integrity, Availability    CA-1 Authorization Policies A.6.1.1,
        Access Control                                                             and Procedures         A.12.1.1,
AC-24                          A.9.4.1*
        Decisions                                                                                         A.18.1.1,
AC-25 Reference Monitor        None                Confidentiality                                        A.18.2.2
                               5.2, 5.3, 7.5.1,                                                        A.14.2.8,
                               7.5.2, 7.5.3,                                  CA-2 Control Assessments A.18.2.2,
        Awareness and          A.5.1.1, A.5.1.2,                                                       A.18.2.3
AT-1    Training Policy and    A.6.1.1,                                                                     A.13.1.2,
                                                                                      Information
        Procedures             A.12.1.1,                                      CA-3                          A.13.2.1,
                               A.18.1.1,                                              Exchange
                                                                                                            A.13.2.2
                               A.18.2.2                                       CA-4 Withdrawn                ---
        Literacy Training and 7.3, A.7.2.2,                                        Plan of Action and
AT-2                                                                          CA-5                          8.3, 9.2, 10.1*
        Awareness             A.12.2.1                                             Milestones
AT-3    Role-Based Training    A.7.2.2*                                       CA-6 Authorization            9.3*
AT-4    Training Records       None                Integrity                                                9.1, 9.2,
                                                                                      Continuous
AT-5    Withdrawn              ---                                            CA-7                          A.18.2.2,
                                                                                      Monitoring
AT-6    Training Feedback      None                Integrity                                                A.18.2.3*
                                                                                                                              Confidentiality,
                                                                              CA-8 Penetration Testing      None
                                                                                                                              Integrity, Availability
                                                                                      Internal System                         Confidentiality,
                                                                              CA-9                          None
                                                                                      Connections                             Integrity, Availability




                                                                         24
                              5.2, 5.3, 7.5.1,                                     Alternate
                              7.5.2, 7.5.3,                                  CP-11 Communications          A.17.1.2*
     Configuration            A.5.1.1, A.5.1.2,                                    Protocols
CM-1 Management Policy        A.6.1.1,                                       CP-12 Safe Mode               None                Integrity, Availability
     and Procedures           A.12.1.1,
                              A.18.1.1,                                            Alternative Security
                                                                             CP-13                         A.17.1.2*
                              A.18.2.2                                             Mechanisms

        Baseline                                                                                          5.2, 5.3, 7.5.1,
CM-2                          None                Integrity                                               7.5.2, 7.5.3,
        Configuration
                                                                                    Identification and    A.5.1.1, A.5.1.2,
                          8.1, A.12.1.2,                                     IA-1   Authentication Policy A.6.1.1,
     Configuration Change A.14.2.2,                                                 and Procedures        A.12.1.1,
CM-3
     Control              A.14.2.3,                                                                       A.18.1.1,
                          A.14.2.4                                                                        A.18.2.2
CM-4 Impact Analyses          A.14.2.3                                              Identification and
                              A.9.2.3, A.9.4.5,                                     Authentication
                                                                             IA-2                          A.9.2.1
        Access Restrictions   A.12.1.2,                                             (Organizational
CM-5
        for Change            A.12.1.4,                                             Users)
                              A.12.5.1                                              Device Identification                      Confidentiality,
                                                                             IA-3                         None
     Configuration                                                                  and Authentication                         Integrity
CM-6                          None                Integrity
     Settings                                                                       Identifier
                                                                             IA-4                          A.9.2.1
CM-7 Least Functionality      A.12.5.1*                                             Management
        System Component                                                            Authenticator          A.9.2.1, A.9.2.4,
CM-8                          A.8.1.1, A.8.1.2                               IA-5
        Inventory                                                                   Management             A.9.3.1, A.9.4.3
        Configuration                                                               Authentication
CM-9                          A.6.1.1*                                       IA-6                          A.9.4.2
        Management Plan                                                             Feedback
CM-     Software Usage                                                              Cryptographic
                              A.18.1.2
10      Restrictions                                                         IA-7   Module                 A.18.1.5
CM-     User-Installed        A.12.5.1,                                             Authentication
11      Software              A.12.6.2                                              Identification and
CM-                                               Confidentiality,           IA-8   Authentication (Non- A.9.2.1
        Information Location None                                                   Organizational Users)
12                                                Integrity, Availability
CM-                                               Confidentiality,                  Service Identification                     Confidentiality,
        Data Action Mapping None                                             IA-9                          None
13                                                Integrity, Availability           and Authentication                         Integrity
CM-                                                                                Adaptive
        Signed Components     None                Integrity                                                                    Confidentiality,
14                                                                           IA-10 Identification and      None
                                                                                                                               Integrity
                                                                                   Authentication
                             5.2, 5.3, 7.5.1,
                             7.5.2, 7.5.3,                                                                                     Confidentiality,
                                                                             IA-11 Re-authentication       None
        Contingency Planning A.5.1.1, A.5.1.2,                                                                                 Integrity
CP-1    Policy and           A.6.1.1,                                                                                          Confidentiality,
                                                                             IA-12 Identity Proofing       None
        Procedures           A.12.1.1,                                                                                         Integrity
                             A.18.1.1,                                                                     5.2, 5.3, 7.5.1,
                             A.18.2.2                                                                      7.5.2, 7.5.3,
                                                                                    Incident Response
                              7.5.1, 7.5.2,                                                                A.5.1.1, A.5.1.2,
                                                                             IR-1   Policy and
                              7.5.3, A.6.1.1,                                                              A.6.1.1, A.12.1.1
CP-2    Contingency Plan                                                            Procedures
                              A.17.1.1,                                                                    A.18.1.1,
                              A.17.2.1                                                                     A.18.2.2
CP-3    Contingency Training A.7.2.2*                                               Incident Response
                                                                             IR-2                          A.7.2.2*
        Contingency Plan                                                            Training
CP-4                          A.17.1.3
        Testing                                                                     Incident Response
                                                                             IR-3                          None                Availability
CP-5    Withdrawn             ---                                                   Testing
                              A.11.1.4,                                                                    A.16.1.4,
        Alternate Storage                                                    IR-4   Incident Handling      A.16.1.5,
CP-6                          A.17.1.2,
        Site                                                                                               A.16.1.6
                              A.17.2.1
                             A.11.1.4,                                                                                         Confidentiality,
        Alternate Processing                                                 IR-5   Incident Monitoring    None
CP-7                         A.17.1.2,                                                                                         Integrity, Availability
        Site
                             A.17.2.1                                        IR-6   Incident Reporting     A.6.1.3, A.16.1.2
        Telecommunications A.11.2.2,                                                Incident Response                          Confidentiality,
CP-8                                                                         IR-7                          None
        Services           A.17.1.2                                                 Assistance                                 Integrity, Availability
                              A.12.3.1,                                             Incident Response      7.5.1, 7.5.2,
                                                                             IR-8
CP-9    System Backup         A.17.1.2,                                             Plan                   7.5.3, A.16.1.1
                              A.18.1.3                                              Information Spillage                       Confidentiality,
                                                                             IR-9                          None
        System Recovery and                                                         Response                                   Integrity, Availability
CP-10                       A.17.1.2
        Reconstitution                                                       IR-10 Withdrawn               ---




                                                                        25
                        5.2, 5.3, 7.5.1,                                     PE-11 Emergency Power          A.11.2.2
                        7.5.2, 7.5.3,                                        PE-12 Emergency Lighting       A.11.2.2*
     System Maintenance A.5.1.1, A.5.1.2,
MA-1 Policy and         A.6.1.1,                                                                            A.11.1.4,
                                                                             PE-13 Fire Protection
     Procedures         A.12.1.1,                                                                           A.11.2.1
                        A.18.1.1,                                                                           A.11.1.4,
                                                                                     Environmental
                        A.18.2.2                                             PE-14                          A.11.2.1,
                                                                                     Controls
       Controlled             A.11.2.4*,                                                                    A.11.2.2
MA-2
       Maintenance            A.11.2.5*                                                                     A.11.1.4,
                                                                                     Water Damage
MA-3 Maintenance Tools        None                Integrity, Availability    PE-15                          A.11.2.1,
                                                                                     Protection
                                                                                                            A.11.2.2
       Nonlocal
MA-4                          None                Integrity, Availability                               A.8.2.3,
       Maintenance
                                                                             PE-16 Delivery and Removal A.11.1.6,
       Maintenance                                                                                      A.11.2.5
MA-5                          None                Integrity, Availability
       Personnel
                                                                                                            A.6.2.2,
MA-6 Timely Maintenance A.11.2.4                                             PE-17 Alternate Work Site      A.11.2.6,
MA-7 Field Maintenance        None                Integrity, Availability                                   A.13.2.1
                              5.2, 5.3, 7.5.1,                                                              A.8.2.3,
                                                                                     Location of System
                              7.5.2, 7.5.3,                                  PE-18                          A.11.1.4,
                                                                                     Components
     Media Protection         A.5.1.1, A.5.1.2,                                                             A.11.2.1
MP-1 Policy and               A.6.1.1,                                                                      A.11.1.4,
     Procedures               A.12.1.1,                                      PE-19 Information Leakage
                                                                                                            A.11.2.1
                              A.18.1.1,
                              A.18.2.2                                               Asset Monitoring and
                                                                             PE-20                        A.8.2.3*
                                                                                     Tracking
                              A.8.2.3, A.8.3.1,
MP-2 Media Access                                                                    Electromagnetic
                              A.11.2.9                                       PE-21                          None                Availability
                                                                                     Pulse Protection
MP-3 Media Marking            A.8.2.2
                                                                             PE-22 Component Marking A.8.2.2
                              A.8.2.3, A.8.3.1,
MP-4 Media Storage                                                                                          A.11.1.4,
                              A.11.2.9                                       PE-23 Facility Location
                                                                                                            A.11.2.1
                              A.8.2.3, A.8.3.1,
                              A.8.3.3,                                                                      5.2, 5.3, 7.5.1,
MP-5 Media Transport                                                                                        7.5.2, 7.5.3,
                              A.11.2.5,
                              A.11.2.6                                                                      A.5.1.1, A.5.1.2,
                                                                                     Planning Policy and
                                                                             PL-1                           A.6.1.1,
                              A.8.2.3, A.8.3.1,                                      Procedures
MP-6 Media Sanitization                                                                                     A.12.1.1,
                              A.8.3.2, A.11.2.7                                                             A.18.1.1,
MP-7 Media Use                A.8.2.3, A.8.3.1                                                              A.18.2.2
MP-8 Media Downgrading None                       Confidentiality                                           7.5.1, 7.5.2,
                                                                                     System Security and
                             5.2, 5.3, 7.5.1,                                PL-2                           7.5.3, 10.1,
                                                                                     Privacy Plans
                             7.5.2, 7.5.3,                                                                  A.14.1.1
       Physical and
                             A.5.1.1, A.5.1.2,                               PL-3    Withdrawn              ---
       Environmental
PE-1                         A.6.1.1,                                                                       A.7.1.2, A.7.2.1,
       Protection Policy and                                                 PL-4    Rules of Behavior
                             A.12.1.1,                                                                      A.8.1.3
       Procedures
                             A.18.1.1,
                             A.18.2.2                                        PL-5    Withdrawn              ---

       Physical Access                                                       PL-6    Withdrawn              ---
PE-2                          A.11.1.2*
       Authorizations                                                                Concept of
                                                                             PL-7                           8.1, A.14.1.1
                              A.11.1.1,                                              Operations
       Physical Access
PE-3                          A.11.1.2,                                              Security and Privacy
       Control                                                               PL-8                           A.14.1.1*
                              A.11.1.3                                               Architectures
       Access Control for                                                                                                       Confidentiality,
                              A.11.1.2,                                      PL-9    Central Management None
PE-4   Transmission                                                                                                             Integrity, Availability
                              A.11.2.3
       Medium                                                                                                                   Confidentiality,
                                                                             PL-10 Baseline Selection       None
       Access Control for     A.11.1.2,                                                                                         Integrity, Availability
PE-5
       Output Devices         A.11.1.3                                                                                          Confidentiality,
                                                                             PL-11 Baseline Tailoring       None
       Monitoring Physical                                                                                                      Integrity, Availability
PE-6                          None                Confidentiality
       Access                                                                                          4.1, 4.2, 4.3, 4.4,
PE-7   Withdrawn              ---                                                                      5.2, 5.3, 6.1.1,
       Visitor Access                                                                                  6.2, 7.4, 7.5.1,
PE-8                          None                Confidentiality                                      7.5.2, 7.5.3, 8.1,
       Records                                                                    Information Security
                                                                             PM-1                      9.3, 10.2,
                              A.11.1.4,                                           Program Plan
                                                                                                       A.5.1.1, A.5.1.2,
       Power Equipment        A.11.2.1,                                                                A.6.1.1,
PE-9
       and Cabling            A.11.2.2,                                                                A.18.1.1,
                              A.11.2.3                                                                 A.18.2.2
PE-10 Emergency Shutoff       A.11.2.2*




                                                                        26
     Information Security                                                     PM-    Complaint                                  Confidentiality,
                                                                                                           None
PM-2 Program Leadership 5.1, 5.3, A.6.1.1                                     26     Management                                 Integrity, Availability
     Role                                                                     PM-                                               Confidentiality,
                                                                                     Privacy Reporting     None
     Information Security                                                     27                                                Integrity, Availability
PM-3 and Privacy          5.1, 6.2, 7.1                                                                    4.3, 6.1.2, 6.2,
     Resources                                                                PM-
                                                                                     Risk Framing          7.4, 7.5.1, 7.5.2,
                                                                              28
                              6.1.1, 6.2, 7.5.1,                                                           7.5.3
       Plan of Action and
PM-4                          7.5.2, 7.5.3, 8.3,                                     Risk Management
       Milestones Process                                                     PM-                          5.1, 5.3, 9.2,
                              9.2, 9.3, 10.1                                         Program Leadership
                                                                              29                           A.6.1.1
PM-5 System Inventory         None                 Integrity, Availability           Roles
     Measures of              5.3, 6.1.1, 6.2,                                       Supply Chain Risk     4.4, 6.2, 7.5.1,
PM-6                                                                          PM-
     Performance              9.1,                                                   Management            7.5.2, 7.5.3,
                                                                              30
       Enterprise                                  Confidentiality,                  Strategy              10.2*
PM-7                          None
       Architecture                                Integrity, Availability                                 4.4, 6.2, 7.4,
       Critical Infrastructure                                                PM-    Continuous            7.5.1, 7.5.2,
PM-8                           None                Availability               31     Monitoring Strategy   7.5.3, 9.1, 10.1,
       Plan
                                                                                                           10.2
                              4.3, 4.4, 6.1.1,
     Risk Management          6.1.2, 6.2, 7.5.1,                              PM-                                               Confidentiality,
PM-9                                                                                 Purposing             None
     Strategy                 7.5.2, 7.5.3, 9.3,                              32                                                Integrity, Availability
                              10.2                                                                         5.2, 5.3, 7.5.1,
PM-    Authorization                                                                                       7.5.2, 7.5.3,
                              9.3, A.6.1.1*                                          Personnel Security    A.5.1.1, A.5.1.2,
10     Process
                                                                              PS-1   Policy and            A.6.1.1,
PM-    Mission and Business                                                          Procedures            A.12.1.1,
                            4.1
11     Process Definition                                                                                  A.18.1.1,
PM-    Insider Threat                              Confidentiality,                                        A.18.2.2
                              None
12     Program                                     Integrity                         Position Risk                              Confidentiality,
                                                                              PS-2                         None
PM-    Security and Privacy                                                          Designation                                Integrity
                              7.2, A.7.2.2*
13     Workforce                                                              PS-3   Personnel Screening A.7.1.1
PM-    Testing, Training, and                                                        Personnel
                              6.2*                                            PS-4                         A.7.3.1, A.8.1.4
14     Monitoring                                                                    Termination
       Security and Privacy                                                   PS-5   Personnel Transfer    A.7.3.1, A.8.1.4
PM-
       Groups and             7.4, A.6.1.4
15                                                                                                         A.7.1.2, A.7.2.1,
       Associations                                                           PS-6   Access Agreements
                                                                                                           A.13.2.4
PM-    Threat Awareness                            Confidentiality,
                              None                                                   External Personnel
16     Program                                     Integrity                  PS-7                         A.6.1.1, A.7.2.1*
                                                                                     Security
       Protecting Controlled
PM-    Unclassified                                                           PS-8   Personnel Sanctions   7.3, A.7.2.3
                             None                  Confidentiality
17     Information on                                                         PS-9   Position Descriptions A.6.1.1
       External Systems                                                              Personally
PM-                                                Confidentiality,                  Identifiable
       Privacy Program Plan None
18                                                 Integrity                         Information                                Confidentiality,
                                                                              PT-1                         None
PM-    Privacy Program                             Confidentiality,                  Processing and                             Integrity, Availability
                              None                                                   Transparency Policy
19     Leadership Role                             Integrity
                                                                                     and Procedures
       Dissemination of
PM-                                                Confidentiality,                  Authority to Process
       Privacy Program        None
20                                                 Integrity                         Personally                                 Confidentiality,
       Information                                                            PT-2                        None
                                                                                     Identifiable                               Integrity, Availability
PM-    Accounting of                               Confidentiality,                  Information
                              None
21     Disclosures                                 Integrity
                                                                                     Personally
       Personally                                                                    Identifiable                               Confidentiality,
PM-    Identifiable                                Confidentiality,           PT-3                       None
                              None                                                   Information                                Integrity
22     Information Quality                         Integrity, Availability           Processing Purposes
       Management
                                                                              PT-4   Consent               None                 Integrity
PM-    Data Governance                             Confidentiality,
                              None                                            PT-5   Privacy Notice        None                 Integrity
23     Body                                        Integrity, Availability
PM-                                                Confidentiality,                  System of Records
       Data Integrity Board None                                              PT-6                         None                 Integrity
24                                                 Integrity                         Notice
       Minimization of                                                               Specific Categories of
       Personally                                                                    Personally
                                                                              PT-7                          None                Integrity
PM-    Identifiable                                Confidentiality,                  Identifiable
                              None                                                   Information
25     Information Used in                         Integrity
       Testing, Training, and                                                        Computer Matching
                                                                              PT-8                         None                 Integrity
       Research                                                                      Requirements




                                                                         27
                              5.2, 5.3, 7.5.1,                                     Development
                              7.5.2, 7.5.3,                                  SA-15 Process, Standards,      A.6.1.5, A.14.2.1
     Risk Assessment          A.5.1.1, A.5.1.2,                                    and Tools
RA-1 Policy and               A.6.1.1,                                               Developer-Provided                         Confidentiality,
     Procedures               A.12.1.1,                                      SA-16                          None
                                                                                     Training                                   Integrity, Availability
                              A.18.1.1,
                              A.18.2.2                                               Developer Security
                                                                                     and Privacy            A.14.2.1,
        Security                                                             SA-17
RA-2                          A.8.2.1                                                Architecture and       A.14.2.5
        Categorization                                                               Design
                              6.1.2, 8.2,                                    SA-18 Withdrawn                ---
RA-3 Risk Assessment
                              A.12.6.1*
                                                                             SA-19 Withdrawn                ---
RA-4 Withdrawn                ---
                                                                                   Customized
     Vulnerability                                                                                                              Confidentiality,
                                                                             SA-20 Development of      None
RA-5 Monitoring and           A.12.6.1*                                                                                         Integrity, Availability
                                                                                   Critical Components
     Scanning
                                                                             SA-21 Developer Screening A.7.1.1
     Technical
     Surveillance                                 Confidentiality,                   Unsupported System
RA-6                          None                                           SA-22                      None                    Integrity, Availability
     Countermeasures                              Integrity, Availability            Components
     Survey                                                                  SA-23 Specialization           None                Availability
RA-7 Risk Response            6.1.3, 8.3, 10.1                                                             5.2, 5.3, 7.5.1,
     Privacy Impact                               Confidentiality,                                         7.5.2, 7.5.3,
RA-8                          None                                                   System and
     Assessments                                  Integrity                                                A.5.1.1, A.5.1.2,
                                                                                     Communications
                                                                             SC-1                          A.6.1.1,
RA-9 Criticality Analysis     A.15.2.2*                                              Protection Policy and
                                                                                                           A.12.1.1,
                                                                                     Procedures
                                                  Confidentiality,                                         A.18.1.1,
RA-10 Threat Hunting          None
                                                  Integrity, Availability                                  A.18.2.2
                            5.2, 5.3, 7.5.1,                                         Separation of System
                                                                                                                                Confidentiality,
                            7.5.2, 7.5.3, 8.1,                               SC-2    and User             None
                                                                                                                                Integrity
        System and Services A.5.1.1, A.5.1.2,                                        Functionality
SA-1    Acquisition Policy  A.6.1.1,                                                 Security Function                          Confidentiality,
        and Procedures      A.12.1.1,                                        SC-3                           None
                                                                                     Isolation                                  Integrity
                            A.18.1.1,
                            A.18.2.2                                                 Information In
                                                                                                                                Confidentiality,
                                                                             SC-4    Shared System          None
        Allocation of                                                                                                           Integrity
SA-2                          None                Availability                       Resources
        Resources
                                                                                     Denial-of Service-
                           A.6.1.1, A.6.1.5,                                 SC-5                           None                Availability
                                                                                     Protection
        System Development A.14.1.1,
SA-3                                                                         SC-6    Resource Availability None                 Availability
        Life Cycle         A.14.2.1,
                           A.14.2.6                                                                      A.13.1.1,
                              8.1, A.14.1.1,                                                             A.13.1.3,
                                                                             SC-7    Boundary Protection
                              A.14.2.7,                                                                  A.13.2.1,
SA-4    Acquisition Process                                                                              A.14.1.3
                              A.14.2.9,
                              A.15.1.2                                                                      A.8.2.3,
        System                7.5.1, 7.5.2,                                                                 A.13.1.1,
SA-5                                                                                 Transmission
        Documentation         7.5.3, A.12.1.1*                                                              A.13.2.1,
                                                                             SC-8    Confidentiality and
                                                                                                            A.13.2.3,
SA-6    Withdrawn             ---                                                    Integrity
                                                                                                            A.14.1.2,
SA-7    Withdrawn             ---                                                                           A.14.1.3
        Security Engineering                                                 SC-9    Withdrawn              ---
SA-8                         A.14.2.5
        Principles                                                           SC-10 Network Disconnect A.13.1.1
                              A.6.1.1, A.6.1.5,                                                                                 Confidentiality,
                              A.7.2.1,                                       SC-11 Trusted Path             None
                                                                                                                                Integrity
        External System       A.13.1.2,
SA-9                                                                               Cryptographic Key
        Services              A.13.2.2,
                              A.15.2.1,                                      SC-12 Establishment and        A.10.1.2
                              A.15.2.2                                             Management

                              A.12.1.2,                                                                     A.10.1.1,
      Developer                                                                    Cryptographic            A.14.1.2,
                              A.14.2.2,                                      SC-13
SA-10 Configuration                                                                Protection               A.14.1.3,
                              A.14.2.4,
      Management                                                                                            A.18.1.5
                              A.14.2.7
        Developer Testing     A.14.2.7,                                      SC-14 Withdrawn                ---
SA-11
        and Evaluation        A.14.2.8                                             Collaborative
SA-12 Withdrawn               ---                                            SC-15 Computing Devices        A.13.2.1*
                                                                                   and Applications
SA-13 Withdrawn               ---
SA-14 Withdrawn               ---




                                                                        28
      Transmission of                                                                                                  Confidentiality,
                                          Confidentiality,           SC-43 Usage Restrictions       None
SC-16 Security and Privacy    None                                                                                     Integrity
                                          Integrity
      Attributes                                                             Detonation                                Confidentiality,
                                                                     SC-44                          None
      Public Key                                                             Chambers                                  Integrity, Availability
SC-17 Infrastructure          A.10.1.2                                       System Time
      Certificates                                                   SC-45                          None               Integrity
                                                                             Synchronization
                                          Confidentiality,                   Cross Domain Policy                       Confidentiality,
SC-18 Mobile Code             None                                   SC-46                          None
                                          Integrity                          Enforcement                               Integrity, Availability
SC-19 Withdrawn                                                            Alternate
      Secure                                                         SC-47 Communications           None               Availability
      Name/Address                                                         Paths
SC-20 Resolution Service      None        Integrity                                                                    Confidentiality,
      (Authoritative                                                 SC-48 Sensor Relocation        None
                                                                                                                       Integrity
      Source)
                                                                           Hardware-Enforced
      Secure                                                                                                           Confidentiality,
                                                                     SC-49 Separation and Policy None
      Name/Address                                                                                                     Integrity, Availability
                                                                           Enforcement
SC-21 Resolution Service    None          Integrity
      (Recursive or Caching                                                Software-Enforced
                                                                                                                       Confidentiality,
      Resolver)                                                      SC-50 Separation and Policy None
                                                                                                                       Integrity, Availability
                                                                           Enforcement
        Architecture and
        Provisioning for                                                     Hardware-Based                            Confidentiality,
SC-22                         None        Integrity                  SC-51                          None
        Name/Address                                                         Protection                                Integrity, Availability
        Resolution Service                                                                         5.2, 5.3, 7.5.1,
                                          Confidentiality,                                         7.5.2, 7.5.3,
SC-23 Session Authenticity None                                              System and
                                          Integrity                                                A.5.1.1, A.5.1.2,
                                                                             Information Integrity
                                                                     SI-1                          A.6.1.1,
                                          Confidentiality,                   Policy and
SC-24 Fail in Known State     None                                                                 A.12.1.1,
                                          Integrity                          Procedures
                                                                                                   A.18.1.1,
                                          Confidentiality,                                         A.18.2.2
SC-25 Thin Nodes              None
                                          Integrity, Availability                                   A.12.6.1,
                                          Confidentiality,                                          A.14.2.2,
SC-26 Decoys                  None                                   SI-2    Flaw Remediation
                                          Integrity, Availability                                   A.14.2.3,
      Platform-                                                                                     A.16.1.3
SC-27 Independent             None        Availability                       Malicious Code
                                                                     SI-3                           A.12.2.1
      Applications                                                           Protection
        Protection of                                                                                                  Confidentiality,
SC-28                         A.8.2.3*                               SI-4    System Monitoring      None
        Information at Rest                                                                                            Integrity, Availability
SC-29 Heterogeneity           None        Availability                       Security Alerts,
      Concealment and                     Confidentiality,           SI-5    Advisories, and        A.6.1.4*
SC-30                         None                                           Directives
      Misdirection                        Integrity, Availability
        Covert Channel                                                       Security and Privacy                      Confidentiality,
SC-31                         None        Confidentiality            SI-6                          None
        Analysis                                                             Function Verification                     Integrity
                                          Confidentiality,                   Software, Firmware,
SC-32 System Partitioning     None                                   SI-7    and Information     None                  Integrity
                                          Availability
                                                                             Integrity
SC-33 Withdrawn               ---
                                                                     SI-8    Spam Protection        None               Integrity, Availability
      Non-Modifiable
SC-34                     None            Integrity,                 SI-9    Withdrawn              ---
      Executable Programs
      External Malicious                  Confidentiality,                 Information Input
SC-35                         None                                   SI-10                          None               Integrity
      Code Identification                 Integrity, Availability          Validation
      Distributed                                                                                                      Confidentiality,
                                                                     SI-11 Error Handling           None
SC-36 Processing and          None        Availability                                                                 Integrity, Availability
      Storage                                                              Information
                                                                                                                       Confidentiality,
      Out-of-Band                         Confidentiality,           SI-12 Management and           None
SC-37                         None                                                                                     Integrity, Availability
      Channels                            Integrity, Availability          Retention
SC-38 Operations Security     A.12.x                                         Predictable Failure
                                                                     SI-13                          None               Integrity, Availability
                                                                             Prevention
      Process
                                          Confidentiality,                                                             Confidentiality,
SC-39 Isolation               None                                   SI-14 Non-Persistence          None
                                          Integrity, Availability                                                      Integrity, Availability
        Wireless Link                     Confidentiality,                   Information Output                        Confidentiality,
SC-40                         None                                   SI-15                          None
        Protection                        Integrity                          Filtering                                 Integrity, Availability
        Port and I/O Device               Confidentiality,                                                             Confidentiality,
SC-41                         None                                   SI-16 Memory Protection        None
        Access                            Integrity                                                                    Integrity, Availability
        Sensor Capability and                                                                                          Confidentiality,
SC-42                         A.11.1.5*                              SI-17 Fail-Safe Procedures None
        Data                                                                                                           Integrity, Availability




                                                                29
      Personally                                                                 [AT-4 Training Records], [AT-6 Training
      Identifiable                                Confidentiality,           Feedback]. These two controls require the
SI-18                         None
      Information Quality                         Integrity, Availability
      Operations                                                             organization to document and monitor
                                                  Confidentiality,           information security and privacy training
SI-19 De-identification       None                                           activities, including security and privacy
                                                  Integrity
                                                  Confidentiality,           awareness training and specific role-based
SI-20 Tainting                None
                                                  Integrity                  security and privacy training, retain individual
SI-21 Information Refresh     None                Confidentiality            training records, and gather feedback on
SI-22 Information Diversity None                  Integrity                  organizational training results [10]. These could
      Information                                 Confidentiality,           be important indicators of the awareness process
SI-23                         None
      Fragmentation                               Integrity
                                                                             effectiveness in the organization. These controls
                              5.2, 5.3, 7.5.1,
                                                                             very often are audited by auditors during the ISO
                              7.5.2, 7.5.3,
                              A.5.1.1, A.5.1.2,                              27001 certification process; however, they are not
        Supply Chain Risk
SR-1    Management Policy
                              A.6.1.1,                                       explicitly mentioned in ISO 27001.
                              A.12.1.1,                                          [CM-2 Baseline Configuration], [CM-6
        and Procedures
                              A.15.1.1,
                              A.18.1.1,                                      Configuration Settings]. These controls force
                              A.18.2.2                                       organizations to develop, document, and maintain
        Supply Chain Risk                                                    under configuration control, a current baseline
SR-2                          A.14.2.7*
        Management Plan                                                      configuration of the system, and configuration
        Supply Chain                                                         settings for components. Baseline configurations
                              A.15.1.2,
SR-3    Controls and
        Processes
                              A.15.1.3*                                      for systems and system components include
SR-4    Provenance            A.14.2.7*
                                                                             connectivity, operational, and communications
        Acquisition
                                                                             aspects of systems. Baseline configurations are
SR-5    Strategies, Tools, and A.15.1.3                                      documented, formally reviewed, and agreed-upon
        Methods                                                              specifications for systems or configuration items
SR-6
        Supplier Assessments
                             A.15.2.1
                                                                             within those systems. Baseline configurations
        and Reviews                                                          serve as a basis for future builds, releases, or
        Supply Chain                                                         changes to systems and include security and
SR-7                          A.15.2.2*
        Operations Security
                                                                             privacy control implementations, operational
        Notification                              Confidentiality,
SR-8
        Agreements
                              None
                                                  Integrity                  procedures,      information      about     system
        Tamper Resistance                                                    components, network topology, and logical
SR-9                          None                Integrity                  placement of components in the system
        and Detection
        Inspection of Systems                                                architecture [10]. These controls are important for
SR-10                         None                Integrity
        or Components                                                        maintaining the integrity of the security
        Component                                                            configurations for the systems and components
SR-11                         None                Integrity
        Authenticity
                                                                             and ensuring the standard configuration for the
SR-12 Component Disposal None                     Confidentiality
                                                                             infrastructure systems and components. Again,
                                                                             these aspects are not explicitly highlighted in the
   As may be seen from the table there is an                                 ISO 27001 but commonly are checked during the
overlapping between the controls from ISO and                                ISO certification process.
NIST frameworks. But the most important                                          [PE-6 Monitoring Physical Access], [PE-8
specifics of these frameworks is that NIST 800-53                            Visitor Access Records]. NIST 800-53 requires
can be considered a super-set of ISO 27001. In                               from organizations to monitor physical access to
particular, all the controls from ISO 27001 can be                           the facility where the system resides to detect and
covered by NIST 800-53. However, ISO 27001                                   respond to physical security incidents and to
does not cover all of the areas of NIST 800-53.                              maintain and periodically review visitor access
From the coverage perspective, NIST 800-53 is                                records to the facility where the system resides
more comprehensive and contains much more                                    [10]. These are other examples of controls that are
areas and controls than ISO 27001. While the                                 extremely relevant for the protection of the
detailed analysis of the missing controls is out of                          organization’s assets. They are especially
the scope of this investigation let’s take a look at a                       important for small representative offices that
few examples which would show in which areas                                 often are lacking baseline security controls
NIST, in contrast to ISO, provide more                                       established within headquarters and are also quite
comprehensive coverage of the security-related                               often emphasized during the ISO certification
areas.                                                                       audits. Nevertheless, they have been overlooked


                                                                        30
for a quite long time until the issue of the revised         be tightened to the organization’s context and
version of the ISO 27002 earlier this year (so they          needs and expectations of interested parties.
should appear in the new version of the ISO 27001                A common misunderstanding is that
as well).                                                    companies have to pick one or the other
    [RA-10 Threat Hunting]. Threat hunting is an             framework and stick with it, or that one is better
active means of cyber defense in contrast to                 than the other. In fact, both frameworks can be
traditional protection measures, such as firewalls,          applied to a single organization due to their
intrusion detection and prevention systems,                  synergy and can greatly increase its information
quarantining malicious code in sandboxes, and                security, risk management, and security program.
Security Information and Event Management                        It is not always necessary to choose between
technologies and systems. Cyber threat hunting               NIST 800-53 and ISO 27001. In fact, the two are
involves proactively searching organizational                complementary and can be used in the same
systems, networks, and infrastructure for                    organization. However, if certification is your
advanced threats. The objective is to track and              goal, you should definitely look closer at ISO
disrupt cyber adversaries as early as possible in the        27001. Being externally audited and achieving
attack sequence and to measurably improve the                accredited certification against ISO 27001’s
speed and accuracy of organizational responses.              requirements would likely provide a higher level
[10]. Likewise the previous controls, this one has           of confidence among clients and stakeholders and
been also overlooked by the ISO 27001                        would be a prerequisite for securing certain
publications, despite its extreme importance and             contracts. Accredited certification to ISO 27001
relevance      for   the     organizations.     This         demonstrates that your organization follows
inconsistency should be partially eliminated with            information security best practices, and delivers
the new version of the ISO 27001 standard - this             an independent, expert assessment of whether
year's revised version of ISO 27002 already                  your valuable information and information assets
contains a new control defining requirements for             are adequately protected. At the same time, while
threat intelligence which is an integral part of the         implementing the ISO 27001 requirements you
threat hunting process.                                      still can leverage NIST 800-53 to strengthen the
    [PM-18 Privacy Program Plan], [PT-1                      areas that are missing or not sufficiently covered
Personally Identifiable Information Processing               in the ISO.
and Transparency Policy and Procedures],
[PT-2 Authority to Process Personally                        4. References
Identifiable Information], [PT-4 Consent], [PT-
5 Privacy Notice] and other controls related to the
protection of personally identifiable information            [1] H. Taherdoost, Understanding Cybersecurity
                                                                 Frameworks and Information Security
(PII) processing. The defining characteristic of the
                                                                 Standards—A Review and Comprehensive
NIST 800-53 is that it contains a set of controls to
                                                                 Overview,      2022.       doi:     10.3390/
address privacy requirements for the processing of
PII while ISO 27001 does not specifically address                electronics11142181.
privacy beyond the inherent benefits provided by             [2] T. Conkle,        G. Witte,       Improving
maintaining the security of PII, therefore we can                Cybersecurity through the Use of the
assume that the ISO 27001 controls do not satisfy                Cybersecurity      Framework,      in    9th
privacy requirements with respect to PII                         International Topical Meeting on Nuclear
processing [29]. From this perspective, NIST has                 Plant Instrumentation, Control, and Human-
an advantage over ISO 27001 in regard to the                     Machine Interface Technologies, NPIC and
protection of the PII processing and may be                      HMIT, vol. 3, 2015, pp. 2479–2486.
considered a good basis for GDPR compliance.                 [3] V. Buriachok, V. Sokolov, P. Skladannyi,
                                                                 Security Rating Metrics for Distributed
                                                                 Wireless Systems, in 8th International
3. Conclusion                                                    Conference on “Mathematics. Information
                                                                 Technologies. Education:” Modern Machine
   Understanding both the differences and                        Learning Technologies and Data Science
similarities between these two the most known and                (MoMLeT and DS), vol. 2386, 2019, pp.
adopted security frameworks—ISO 27001 and                        222–233.
NIST 800-53 is crucial for implementing an                   [4] F. Kipchuk, et al., Assessing Approaches of
effective information security program that would                IT Infrastructure Audit, in IEEE 8th



                                                        31
     International Conference on Problems of                 [18] Regulation (EU) 2016/679 of the European
     Infocommunications,          Science        and              Parliament and of the Council on the
     Technology,        PICST,       2021.      doi:              Protection of Natural Persons with Regard to
     10.1109/picst54195.2021.9772181.                             the Processing of Personal Data and on the
[5] I. Kuzminykh, et al., Investigation of the IoT                Free Movement of Such Data, 2018, pp. 1–
     Device Lifetime with Secure Data                             88.
     Transmission, Internet of Things, Smart                 [19] ISO/IEC 27701:2019, Security Techniques
     Spaces, and Next Generation Networks and                     — Extension to ISO/IEC 27001 and ISO/IEC
     Systems, 2019, pp. 16–27. doi: 10.1007/978-                  27002 for Privacy Information Management
     3-030-30859-9_2.                                             — Requirements and Guidelines, 2019,
[6] NIST Cybersecurity Framework vs ISO                           https://www.iso.org/standard/71670.html
     27001/27002 vs NIST 800-53 vs Secure                    [20] Trust Services Criteria Issued by the AICPA
     Controls            Framework.            URL:               Assurance Services Executive Committee,
     https://www.complianceforge.com/faq/nist-                    2017, https://www.aicpa.org/content/dam/
     800-53-vs-iso-27002-vs-nist-csf-vs-scf                       aicpa/interestareas/frc/assuranceadvisoryser
[7] A. Zahoor, et al., Information Security                       vices/downloadabledocuments/trust-
     Management Needs More Holistic Approach:                     services-criteria.pdf
     A     Literature     Review,      2016.     doi:        [21] COBIT 5, A Framework for the Governance
     10.1016/j.ijinfomgt.2015.11.009                              and Management of Enterprise IT, 2012.
[8] ISO/IEC 27001: Information Technology—                   [22] D. Sulistyowati, F. Handayani, Y. Suryanto,
     Security Techniques—Information Security                     Comparative Analysis and Design of
     Management Systems—Requirements, 2013,                       Cybersecurity        Maturity       Assessment
     https://www.iso.org/standard/54534.html.                     Methodology Using NIST CSF COBIT
[9] ISO/IEC 27002: Information Technology—                        ISO/IEC 27002 and PCI DSS, International
     Security Techniques—Code of Practice for                     Journal on Informatics Visualization, vol. 4,
     Information Security Controls, 2013,                         no. 4, 2020, pp. 225–230.
     https://www.iso.org/standard/54533.html.                [23] M. Siponen, R. Willison, Information
[10] (2020) Security and Privacy Controls for                     Security Management Standards: Problems
     Information Systems and Organizations                        and      Solutions,    J.     Information      &
     Special Publication (SP) 800-53 Rev 5, U.S.                  Management, vol. 46, 2009, pp. 267–270.
     Department        of    Commerce,         2020,         [24] S. Yevseiev, et al. Synergy of Building
     https://csrc.nist.gov/publications/detail/sp/8               Cybersecurity Systems: Monograph, PC
     00-53/rev-5/final.                                           Technology Center, 2021.
[11] Overview of the NIST Cybersecurity                      [25] Computer Security Resource Center - SP
     Framework,        2018,    https://1path2020b.               800-53       Rev. 5.       https://csrc.nist.gov/
     websitetotalcare.com/blog/overviewof-                        publications/detail/sp/800-53/rev-5/final
     thenist-cybersecurity-framework.                        [26] V. Susukailo, I. Opirsky, O. Yaremko,
[12] PCI DSS Quick Reference Guide,                               Methodology of ISMS Establishment
     Understanding the Payment Card Industry                      Against Modern Cybersecurity Threats, in
     Data Security Standard, ver. 3.2.1, 2018,                    Future Intent-Based Networking. Lecture
     https://www.pcisecuritystandards.org/docu                    Notes in Electrical Engineering, vol. 831,
     ments/PCI_DSS-QRG-v3_2_1.pdf                                 2022. doi: 10.1007/978-3-030-92435-5_15.
[13] CIS Controls v8, Center for Internet Security,          [27] ISO Official website—ISO/IEC 27001
     2021, https://www.cisecurity.org/controls/                   Information         security       management,
     v8/.                                                         https://www.iso.org/isoiec-27001-
[14] CIS Controls v8 Mapping to NIST SP 800-                      information-security.html
     53 Rev 5, Center for Internet Security, 2021.           [28] Best Practice ISO 27001 Required
[15] HITRUST CSF Framework, HITRUST                               Documentation.        https://www.riskmanage
     Alliance, 2021, https://hitrustalliance.net/                 mentstudio.com/best-practice-iso-27001-
     product-tool/hitrust-csf/                                    required-documentation/
[16] HIPAA; Pub. L. 104-191, 110 Stat. 1936,                 [29] NIST SP 800-53, Revision 5 Control
     enacted August 21, 1996                                      Mappings to ISO/IEC 27001 URL:
[17] Cloud Controls Matrix, Cloud Security                        https://csrc.nist.gov/CSRC/media/Publicatio
     Alliance, 2021, https://cloudsecurityalliance.               ns/sp/800-53/rev-5/final/documents/sp800-
     org/artifacts/cloud-controls-matrix-v4/                      53r5-to-iso-27001-mapping.docx


                                                        32