=Paper=
{{Paper
|id=Vol-3288/paper3
|storemode=property
|title=Analysis and Comparison of the NIST SP 800-53 and ISO/IEC 27001:2013
|pdfUrl=https://ceur-ws.org/Vol-3288/paper3.pdf
|volume=Vol-3288
|authors=Yevhenii Kurii,Ivan Opirskyy
|dblpUrl=https://dblp.org/rec/conf/cpits/KuriiO22
}}
==Analysis and Comparison of the NIST SP 800-53 and ISO/IEC 27001:2013==
Analysis and Comparison of the NIST SP 800-53
and ISO/IEC 27001:2013
Yevhenii Kurii1 and Ivan Opirskyy1
1
Lviv Polytechnic National University, 12 Stepan Bandera str., Lviv, 79000, Ukraine
Abstract
Managing information security in the organization may be a daunting task, especially
considering that it may encompass many areas from physical and network security to human
resources security and management of suppliers. This may be especially hard for young
specialists or not experienced enough specialists, who may miss some important areas due to
lack of practical experience. This is where security frameworks come in handy and put formality
into the process of the design and implementation of the security strategy. With a framework in
place, it becomes much easier to define the processes and procedures that your organization
must take to assess, monitor, and mitigate cybersecurity risk and apply proper controls to protect
valuable information. But another problem came up when you are to choose the “just right”
framework for your organization taking into account more business-specific characteristics like
the context of the organization, area of operation, applicable laws, regulations and contractual
obligations, as well as more general ones like framework’s maturity, comprehensiveness or
popularity. While there are a bunch of different information security frameworks out in the
wild, the most commonly-found and preferred by security professionals worldwide are NIST
SP 800-53 and ISO/IEC 27001:2013. They combine both the quite comprehensive set of
security controls to cover the most important security areas and wide applicability which allows
applying these frameworks to all kinds of organizations. But they also have a set of distinct
features, that define their relevance to the particular organization. The article is aimed at giving
a brief overview of these two most popular security frameworks as well as describing their key
characteristics and providing a comparison of their controls.
Keywords 1
Information security, cybersecurity framework, security controls, information security
management system, ISMS, ISO 27001, NIST 800-53, controls mapping.
1. Introduction These frameworks are a blueprint for managing
and reducing organizational risk. Information
security professionals use frameworks to define
To successfully achieve the objectives of
and prioritize the tasks required to manage the
implementing cybersecurity at different levels, a
organization's security program. Frameworks are
range of procedures and standards should be
also used to help prepare for compliance and other
followed. Cybersecurity standards determine the
IT and security audits. When you are choosing
requirements that an organization should follow to
from the number of leading information security
achieve cybersecurity objectives and facilitate
frameworks, you would primarily assess the
against cybercrimes [1] and ensure the ongoing
number of unique information security controls
management of information security controls.
(requirements) in each of them [3–5].
Additionally, the framework establishes a
common language for defining a cybersecurity
program, enabling organizations to set risk-based
cybersecurity goals at the executive level that can
be translated to the operations team [2].
CPITS-2022: Cybersecurity Providing in Information and Telecommunication Systems, October 13, 2022, Kyiv, Ukraine
EMAIL: yevhenii.o.kurii@lpnu.ua (Y. Kurii); ivan.r.opirskyi@lpnu.ua (I. Opirskyy)
ORCID: 0000-0002-3423-5655 (Y. Kurii); 0000-0002-8461-8996 (I. Opirskyy)
©️ 2022 Copyright for this paper by its authors.
Use permitted under Creative Commons License Attribution 4.0 International (CC BY 4.0).
CEUR Workshop Proceedings (CEUR-WS.org)
21
Figure 1: Information security frameworks based on their specialization and coverage
The volume of these controls directly impacts the framework of frameworks) to address more
the number of domains covered by that complex compliance requirements (e.g., when the
framework. The lesser number of controls in a organization is holding the personal data of EU
framework might make it easier to implement, but citizens and process cardholder data, it should
it also might not provide the necessary coverage comply with both GDPR and PCI DSS
that your organization needs from the perspective requirements).
of administrative, technical, and physical A key consideration for choosing an
information security practices [6]. information security framework would be
This is where defining the applicable and understanding the level of content and robustness
relevant framework is primarily a business each framework offers. This will directly impact
decision [7], based on your organization's context the available information security controls within
and risk profile, which needs to consider each framework [24].
applicable laws and regulations, that are required
to support existing or planned business processes. 2. Overview and Comparison
Commonly, this selection process generally
leads to adopting one of the following between NIST SP 800-53 and
frameworks: ISO/IEC 27001:2013
ISO 27001/002 [8, 9]
NIST Special Publication 800-53 [10] The Special Publication (SP) 800-53 Security
NIST Cybersecurity Framework [11] and Privacy Controls for Information Systems and
PCI DSS [12] Organizations from the National Institute of
CIS Controls [13, 14] Standards and Technology (NIST) is currently in
HITRUST Common Security Framework [15] its 5th revision (rev5) dated September 2020. It
HIPAA [16] was initially designed to protect the US federal
CSA CCM [17] government, but quickly gained popularity among
GDPR [18] private industry and now is considered as one of
ISO 27701 [19] the most popular and respectable information
AICPA Trust Services Criteria (SOC 2) [20] security frameworks in the world. It was partially
caused due to the significant outsourcing to private
COBIT [21]
companies that do business with the US federal
Each information security framework has its
government.
own unique specialization and depth of coverage.
According to the official web page of the
However, understanding this can help you make
standard “This publication [Special Publication
an informed decision on the most appropriate
(SP) 800-53] provides a catalog of security and
framework for your needs. [22, 23] You may even
privacy controls for information systems and
find you need to leverage a metaframework (e.g.,
22
Table 1 organizations to protect organizational operations
Key differences between NIST SP 800-53 to ISO and assets, individuals, other organizations, and
27001 the Nation from a diverse set of threats and risks,
NIST ISO including hostile attacks, human errors, natural
disasters, structural failures, foreign intelligence
A recognized
framework that
entities, and privacy risks” [25].
contains security
SO 27001 is a well-respected international
An information security standard that outlines the key
and privacy
internationally processes and approaches a business needs to
controls for
recognized manage information security risk in a practical
information
standard that way [26]. ISO 27001 consists of the main part and
systems and
Description describes how Annex A, that contains the basic overview of the
organizations to
to manage security controls needed to build an Information
protect
information Security Management System (ISMS).
organizational
security in an Additionally, there is a separate standard ISO
operations and
organization 27002 that provides a detailed description of the
assets with aim
to effectively specific controls that are necessary to actually
manage risk implement ISO 27001 (essentially, you can't meet
Can be ISO 27001 without implementing ISO 27002).
implemented [27, 28]. The important thing about ISO is that it
in any kind of provides the companies with the possibility to
Was primarily
organization, undergo an external audit and get certified against
Target created to help
profit or non- ISO 27001.
organizations US federal
profit, private
agencies
or state-
owned, small
2.1. Detailed Mapping of Controls
or large
Table 2 provides a mapping from the security
Annex A
Contains 1007 controls in NIST Special Publication 800-53 to the
provides 14
controls broken security controls in ISO/IEC 27001:2013 [29].
Structure control
down into 20
categories with Table 2
control families
114 controls Mapping NIST SP 800-53 to ISO 27001
Is less
technical, with ISO/IEC 27001
Is very detailed more emphasis CONTROLS
NIST SP 800-53 Note: An asterisk (*) Effected CIA triad
Complexity and technical in on risk-based indicates that the ISO/IEC
element
CONTROLS control does not fully
its nature approach to satisfy the intent of the
NIST control.
managing
security 5.2, 5.3, 7.5.1,
7.5.2, 7.5.3,
Enables A.5.1.1, A.5.1.2,
Access Control Policy
companies to AC-1
and Procedures
A.6.1.1, A.9.1.1,
become A.12.1.1,
Is voluntary and A.18.1.1,
certified, relies
relies on self- A.18.2.2
Certification on
assessment and Account
A.9.2.1, A.9.2.2,
independent AC-2 A.9.2.3, A.9.2.5,
self-compliance Management
audit and A.9.2.6
certification A.6.2.2, A.9.1.2,
bodies A.9.4.1, A.9.4.4,
A.9.4.5,
Distributed on AC-3 Access Enforcement A.13.1.1,
Can be freely
the commercial A.14.1.2,
downloaded
Availability basis through A.14.1.3,
from official A.18.1.3
the official
source A.13.1.3,
website
Information Flow A.13.2.1,
AC-4
Enforcement A.14.1.2,
A.14.1.3
23
AC-5 Separation of Duties A.6.1.2 5.2, 5.3, 7.5.1,
A.9.1.2, A.9.2.3, 7.5.2, 7.5.3,
AC-6 Least Privilege Audit and A.5.1.1, A.5.1.2,
A.9.4.4, A.9.4.5
AU-1 Accountability Policy A.6.1.1,
Unsuccessful Logon and Procedures A.12.1.1,
AC-7 A.9.4.2
Attempts A.18.1.1,
System Use A.18.2.2
AC-8 A.9.4.2
Notification Confidentiality,
AU-2 Event Logging None
Previous Logon Integrity, Availability
AC-9 A.9.4.2
Notification Content of Audit
AU-3 A.12.4.1*
Concurrent Session Confidentiality, Records
AC-10 None
Control Integrity Audit Log Storage
AU-4 A.12.1.3
A.11.2.8, Capacity
AC-11 Device Lock
A.11.2.9 Response to Audit
Confidentiality, AU-5 Logging Process None Integrity, Availability
AC-12 Session Termination None
Integrity Failures
AC-13 Withdrawn --- Audit Record Review, A.12.4.1,
Permitted Actions AU-6 Analysis, and A.16.1.2,
Confidentiality, Reporting A.16.1.4
AC-14 without Identification None
Integrity
or Authentication Audit Record
AC-15 Withdrawn --- AU-7 Reduction and None Integrity, Availability
Report Generation
Security and Privacy Confidentiality,
AC-16 None AU-8 Time Stamps A.12.4.4
Attributes Integrity
A.6.2.1, A.6.2.2, A.12.4.2,
Protection of Audit
A.13.1.1, AU-9 A.12.4.3,
AC-17 Remote Access Information
A.13.2.1, A.18.1.3
A.14.1.2 AU-10 Non-repudiation None Integrity
A.6.2.1, Audit Record A.12.4.1,
AU-11
AC-18 Wireless Access A.13.1.1, Retention A.16.1.7
A.13.2.1 Audit Record A.12.4.1,
AU-12
A.6.2.1, Generation A.12.4.3
Access Control for A.11.1.5, Monitoring for
AC-19
Mobile Devices A.11.2.6, AU-13 Information None Confidentiality
A.13.2.1 Disclosure
A.11.2.6, AU-14 Session Audit A.12.4.1*
Use of External
AC-20 A.13.1.1,
Systems AU-15 Withdrawn ---
A.13.2.1
AC-21 Information Sharing None Confidentiality Cross-Organizational Confidentiality,
AU-16 None
Audit Logging Integrity
Publicly Accessible
AC-22 None Confidentiality 5.2, 5.3, 7.5.1,
Content
7.5.2, 7.5.3,
Data Mining Confidentiality, Assessment and A.5.1.1, A.5.1.2,
AC-23 None
Protection Integrity, Availability CA-1 Authorization Policies A.6.1.1,
Access Control and Procedures A.12.1.1,
AC-24 A.9.4.1*
Decisions A.18.1.1,
AC-25 Reference Monitor None Confidentiality A.18.2.2
5.2, 5.3, 7.5.1, A.14.2.8,
7.5.2, 7.5.3, CA-2 Control Assessments A.18.2.2,
Awareness and A.5.1.1, A.5.1.2, A.18.2.3
AT-1 Training Policy and A.6.1.1, A.13.1.2,
Information
Procedures A.12.1.1, CA-3 A.13.2.1,
A.18.1.1, Exchange
A.13.2.2
A.18.2.2 CA-4 Withdrawn ---
Literacy Training and 7.3, A.7.2.2, Plan of Action and
AT-2 CA-5 8.3, 9.2, 10.1*
Awareness A.12.2.1 Milestones
AT-3 Role-Based Training A.7.2.2* CA-6 Authorization 9.3*
AT-4 Training Records None Integrity 9.1, 9.2,
Continuous
AT-5 Withdrawn --- CA-7 A.18.2.2,
Monitoring
AT-6 Training Feedback None Integrity A.18.2.3*
Confidentiality,
CA-8 Penetration Testing None
Integrity, Availability
Internal System Confidentiality,
CA-9 None
Connections Integrity, Availability
24
5.2, 5.3, 7.5.1, Alternate
7.5.2, 7.5.3, CP-11 Communications A.17.1.2*
Configuration A.5.1.1, A.5.1.2, Protocols
CM-1 Management Policy A.6.1.1, CP-12 Safe Mode None Integrity, Availability
and Procedures A.12.1.1,
A.18.1.1, Alternative Security
CP-13 A.17.1.2*
A.18.2.2 Mechanisms
Baseline 5.2, 5.3, 7.5.1,
CM-2 None Integrity 7.5.2, 7.5.3,
Configuration
Identification and A.5.1.1, A.5.1.2,
8.1, A.12.1.2, IA-1 Authentication Policy A.6.1.1,
Configuration Change A.14.2.2, and Procedures A.12.1.1,
CM-3
Control A.14.2.3, A.18.1.1,
A.14.2.4 A.18.2.2
CM-4 Impact Analyses A.14.2.3 Identification and
A.9.2.3, A.9.4.5, Authentication
IA-2 A.9.2.1
Access Restrictions A.12.1.2, (Organizational
CM-5
for Change A.12.1.4, Users)
A.12.5.1 Device Identification Confidentiality,
IA-3 None
Configuration and Authentication Integrity
CM-6 None Integrity
Settings Identifier
IA-4 A.9.2.1
CM-7 Least Functionality A.12.5.1* Management
System Component Authenticator A.9.2.1, A.9.2.4,
CM-8 A.8.1.1, A.8.1.2 IA-5
Inventory Management A.9.3.1, A.9.4.3
Configuration Authentication
CM-9 A.6.1.1* IA-6 A.9.4.2
Management Plan Feedback
CM- Software Usage Cryptographic
A.18.1.2
10 Restrictions IA-7 Module A.18.1.5
CM- User-Installed A.12.5.1, Authentication
11 Software A.12.6.2 Identification and
CM- Confidentiality, IA-8 Authentication (Non- A.9.2.1
Information Location None Organizational Users)
12 Integrity, Availability
CM- Confidentiality, Service Identification Confidentiality,
Data Action Mapping None IA-9 None
13 Integrity, Availability and Authentication Integrity
CM- Adaptive
Signed Components None Integrity Confidentiality,
14 IA-10 Identification and None
Integrity
Authentication
5.2, 5.3, 7.5.1,
7.5.2, 7.5.3, Confidentiality,
IA-11 Re-authentication None
Contingency Planning A.5.1.1, A.5.1.2, Integrity
CP-1 Policy and A.6.1.1, Confidentiality,
IA-12 Identity Proofing None
Procedures A.12.1.1, Integrity
A.18.1.1, 5.2, 5.3, 7.5.1,
A.18.2.2 7.5.2, 7.5.3,
Incident Response
7.5.1, 7.5.2, A.5.1.1, A.5.1.2,
IR-1 Policy and
7.5.3, A.6.1.1, A.6.1.1, A.12.1.1
CP-2 Contingency Plan Procedures
A.17.1.1, A.18.1.1,
A.17.2.1 A.18.2.2
CP-3 Contingency Training A.7.2.2* Incident Response
IR-2 A.7.2.2*
Contingency Plan Training
CP-4 A.17.1.3
Testing Incident Response
IR-3 None Availability
CP-5 Withdrawn --- Testing
A.11.1.4, A.16.1.4,
Alternate Storage IR-4 Incident Handling A.16.1.5,
CP-6 A.17.1.2,
Site A.16.1.6
A.17.2.1
A.11.1.4, Confidentiality,
Alternate Processing IR-5 Incident Monitoring None
CP-7 A.17.1.2, Integrity, Availability
Site
A.17.2.1 IR-6 Incident Reporting A.6.1.3, A.16.1.2
Telecommunications A.11.2.2, Incident Response Confidentiality,
CP-8 IR-7 None
Services A.17.1.2 Assistance Integrity, Availability
A.12.3.1, Incident Response 7.5.1, 7.5.2,
IR-8
CP-9 System Backup A.17.1.2, Plan 7.5.3, A.16.1.1
A.18.1.3 Information Spillage Confidentiality,
IR-9 None
System Recovery and Response Integrity, Availability
CP-10 A.17.1.2
Reconstitution IR-10 Withdrawn ---
25
5.2, 5.3, 7.5.1, PE-11 Emergency Power A.11.2.2
7.5.2, 7.5.3, PE-12 Emergency Lighting A.11.2.2*
System Maintenance A.5.1.1, A.5.1.2,
MA-1 Policy and A.6.1.1, A.11.1.4,
PE-13 Fire Protection
Procedures A.12.1.1, A.11.2.1
A.18.1.1, A.11.1.4,
Environmental
A.18.2.2 PE-14 A.11.2.1,
Controls
Controlled A.11.2.4*, A.11.2.2
MA-2
Maintenance A.11.2.5* A.11.1.4,
Water Damage
MA-3 Maintenance Tools None Integrity, Availability PE-15 A.11.2.1,
Protection
A.11.2.2
Nonlocal
MA-4 None Integrity, Availability A.8.2.3,
Maintenance
PE-16 Delivery and Removal A.11.1.6,
Maintenance A.11.2.5
MA-5 None Integrity, Availability
Personnel
A.6.2.2,
MA-6 Timely Maintenance A.11.2.4 PE-17 Alternate Work Site A.11.2.6,
MA-7 Field Maintenance None Integrity, Availability A.13.2.1
5.2, 5.3, 7.5.1, A.8.2.3,
Location of System
7.5.2, 7.5.3, PE-18 A.11.1.4,
Components
Media Protection A.5.1.1, A.5.1.2, A.11.2.1
MP-1 Policy and A.6.1.1, A.11.1.4,
Procedures A.12.1.1, PE-19 Information Leakage
A.11.2.1
A.18.1.1,
A.18.2.2 Asset Monitoring and
PE-20 A.8.2.3*
Tracking
A.8.2.3, A.8.3.1,
MP-2 Media Access Electromagnetic
A.11.2.9 PE-21 None Availability
Pulse Protection
MP-3 Media Marking A.8.2.2
PE-22 Component Marking A.8.2.2
A.8.2.3, A.8.3.1,
MP-4 Media Storage A.11.1.4,
A.11.2.9 PE-23 Facility Location
A.11.2.1
A.8.2.3, A.8.3.1,
A.8.3.3, 5.2, 5.3, 7.5.1,
MP-5 Media Transport 7.5.2, 7.5.3,
A.11.2.5,
A.11.2.6 A.5.1.1, A.5.1.2,
Planning Policy and
PL-1 A.6.1.1,
A.8.2.3, A.8.3.1, Procedures
MP-6 Media Sanitization A.12.1.1,
A.8.3.2, A.11.2.7 A.18.1.1,
MP-7 Media Use A.8.2.3, A.8.3.1 A.18.2.2
MP-8 Media Downgrading None Confidentiality 7.5.1, 7.5.2,
System Security and
5.2, 5.3, 7.5.1, PL-2 7.5.3, 10.1,
Privacy Plans
7.5.2, 7.5.3, A.14.1.1
Physical and
A.5.1.1, A.5.1.2, PL-3 Withdrawn ---
Environmental
PE-1 A.6.1.1, A.7.1.2, A.7.2.1,
Protection Policy and PL-4 Rules of Behavior
A.12.1.1, A.8.1.3
Procedures
A.18.1.1,
A.18.2.2 PL-5 Withdrawn ---
Physical Access PL-6 Withdrawn ---
PE-2 A.11.1.2*
Authorizations Concept of
PL-7 8.1, A.14.1.1
A.11.1.1, Operations
Physical Access
PE-3 A.11.1.2, Security and Privacy
Control PL-8 A.14.1.1*
A.11.1.3 Architectures
Access Control for Confidentiality,
A.11.1.2, PL-9 Central Management None
PE-4 Transmission Integrity, Availability
A.11.2.3
Medium Confidentiality,
PL-10 Baseline Selection None
Access Control for A.11.1.2, Integrity, Availability
PE-5
Output Devices A.11.1.3 Confidentiality,
PL-11 Baseline Tailoring None
Monitoring Physical Integrity, Availability
PE-6 None Confidentiality
Access 4.1, 4.2, 4.3, 4.4,
PE-7 Withdrawn --- 5.2, 5.3, 6.1.1,
Visitor Access 6.2, 7.4, 7.5.1,
PE-8 None Confidentiality 7.5.2, 7.5.3, 8.1,
Records Information Security
PM-1 9.3, 10.2,
A.11.1.4, Program Plan
A.5.1.1, A.5.1.2,
Power Equipment A.11.2.1, A.6.1.1,
PE-9
and Cabling A.11.2.2, A.18.1.1,
A.11.2.3 A.18.2.2
PE-10 Emergency Shutoff A.11.2.2*
26
Information Security PM- Complaint Confidentiality,
None
PM-2 Program Leadership 5.1, 5.3, A.6.1.1 26 Management Integrity, Availability
Role PM- Confidentiality,
Privacy Reporting None
Information Security 27 Integrity, Availability
PM-3 and Privacy 5.1, 6.2, 7.1 4.3, 6.1.2, 6.2,
Resources PM-
Risk Framing 7.4, 7.5.1, 7.5.2,
28
6.1.1, 6.2, 7.5.1, 7.5.3
Plan of Action and
PM-4 7.5.2, 7.5.3, 8.3, Risk Management
Milestones Process PM- 5.1, 5.3, 9.2,
9.2, 9.3, 10.1 Program Leadership
29 A.6.1.1
PM-5 System Inventory None Integrity, Availability Roles
Measures of 5.3, 6.1.1, 6.2, Supply Chain Risk 4.4, 6.2, 7.5.1,
PM-6 PM-
Performance 9.1, Management 7.5.2, 7.5.3,
30
Enterprise Confidentiality, Strategy 10.2*
PM-7 None
Architecture Integrity, Availability 4.4, 6.2, 7.4,
Critical Infrastructure PM- Continuous 7.5.1, 7.5.2,
PM-8 None Availability 31 Monitoring Strategy 7.5.3, 9.1, 10.1,
Plan
10.2
4.3, 4.4, 6.1.1,
Risk Management 6.1.2, 6.2, 7.5.1, PM- Confidentiality,
PM-9 Purposing None
Strategy 7.5.2, 7.5.3, 9.3, 32 Integrity, Availability
10.2 5.2, 5.3, 7.5.1,
PM- Authorization 7.5.2, 7.5.3,
9.3, A.6.1.1* Personnel Security A.5.1.1, A.5.1.2,
10 Process
PS-1 Policy and A.6.1.1,
PM- Mission and Business Procedures A.12.1.1,
4.1
11 Process Definition A.18.1.1,
PM- Insider Threat Confidentiality, A.18.2.2
None
12 Program Integrity Position Risk Confidentiality,
PS-2 None
PM- Security and Privacy Designation Integrity
7.2, A.7.2.2*
13 Workforce PS-3 Personnel Screening A.7.1.1
PM- Testing, Training, and Personnel
6.2* PS-4 A.7.3.1, A.8.1.4
14 Monitoring Termination
Security and Privacy PS-5 Personnel Transfer A.7.3.1, A.8.1.4
PM-
Groups and 7.4, A.6.1.4
15 A.7.1.2, A.7.2.1,
Associations PS-6 Access Agreements
A.13.2.4
PM- Threat Awareness Confidentiality,
None External Personnel
16 Program Integrity PS-7 A.6.1.1, A.7.2.1*
Security
Protecting Controlled
PM- Unclassified PS-8 Personnel Sanctions 7.3, A.7.2.3
None Confidentiality
17 Information on PS-9 Position Descriptions A.6.1.1
External Systems Personally
PM- Confidentiality, Identifiable
Privacy Program Plan None
18 Integrity Information Confidentiality,
PT-1 None
PM- Privacy Program Confidentiality, Processing and Integrity, Availability
None Transparency Policy
19 Leadership Role Integrity
and Procedures
Dissemination of
PM- Confidentiality, Authority to Process
Privacy Program None
20 Integrity Personally Confidentiality,
Information PT-2 None
Identifiable Integrity, Availability
PM- Accounting of Confidentiality, Information
None
21 Disclosures Integrity
Personally
Personally Identifiable Confidentiality,
PM- Identifiable Confidentiality, PT-3 None
None Information Integrity
22 Information Quality Integrity, Availability Processing Purposes
Management
PT-4 Consent None Integrity
PM- Data Governance Confidentiality,
None PT-5 Privacy Notice None Integrity
23 Body Integrity, Availability
PM- Confidentiality, System of Records
Data Integrity Board None PT-6 None Integrity
24 Integrity Notice
Minimization of Specific Categories of
Personally Personally
PT-7 None Integrity
PM- Identifiable Confidentiality, Identifiable
None Information
25 Information Used in Integrity
Testing, Training, and Computer Matching
PT-8 None Integrity
Research Requirements
27
5.2, 5.3, 7.5.1, Development
7.5.2, 7.5.3, SA-15 Process, Standards, A.6.1.5, A.14.2.1
Risk Assessment A.5.1.1, A.5.1.2, and Tools
RA-1 Policy and A.6.1.1, Developer-Provided Confidentiality,
Procedures A.12.1.1, SA-16 None
Training Integrity, Availability
A.18.1.1,
A.18.2.2 Developer Security
and Privacy A.14.2.1,
Security SA-17
RA-2 A.8.2.1 Architecture and A.14.2.5
Categorization Design
6.1.2, 8.2, SA-18 Withdrawn ---
RA-3 Risk Assessment
A.12.6.1*
SA-19 Withdrawn ---
RA-4 Withdrawn ---
Customized
Vulnerability Confidentiality,
SA-20 Development of None
RA-5 Monitoring and A.12.6.1* Integrity, Availability
Critical Components
Scanning
SA-21 Developer Screening A.7.1.1
Technical
Surveillance Confidentiality, Unsupported System
RA-6 None SA-22 None Integrity, Availability
Countermeasures Integrity, Availability Components
Survey SA-23 Specialization None Availability
RA-7 Risk Response 6.1.3, 8.3, 10.1 5.2, 5.3, 7.5.1,
Privacy Impact Confidentiality, 7.5.2, 7.5.3,
RA-8 None System and
Assessments Integrity A.5.1.1, A.5.1.2,
Communications
SC-1 A.6.1.1,
RA-9 Criticality Analysis A.15.2.2* Protection Policy and
A.12.1.1,
Procedures
Confidentiality, A.18.1.1,
RA-10 Threat Hunting None
Integrity, Availability A.18.2.2
5.2, 5.3, 7.5.1, Separation of System
Confidentiality,
7.5.2, 7.5.3, 8.1, SC-2 and User None
Integrity
System and Services A.5.1.1, A.5.1.2, Functionality
SA-1 Acquisition Policy A.6.1.1, Security Function Confidentiality,
and Procedures A.12.1.1, SC-3 None
Isolation Integrity
A.18.1.1,
A.18.2.2 Information In
Confidentiality,
SC-4 Shared System None
Allocation of Integrity
SA-2 None Availability Resources
Resources
Denial-of Service-
A.6.1.1, A.6.1.5, SC-5 None Availability
Protection
System Development A.14.1.1,
SA-3 SC-6 Resource Availability None Availability
Life Cycle A.14.2.1,
A.14.2.6 A.13.1.1,
8.1, A.14.1.1, A.13.1.3,
SC-7 Boundary Protection
A.14.2.7, A.13.2.1,
SA-4 Acquisition Process A.14.1.3
A.14.2.9,
A.15.1.2 A.8.2.3,
System 7.5.1, 7.5.2, A.13.1.1,
SA-5 Transmission
Documentation 7.5.3, A.12.1.1* A.13.2.1,
SC-8 Confidentiality and
A.13.2.3,
SA-6 Withdrawn --- Integrity
A.14.1.2,
SA-7 Withdrawn --- A.14.1.3
Security Engineering SC-9 Withdrawn ---
SA-8 A.14.2.5
Principles SC-10 Network Disconnect A.13.1.1
A.6.1.1, A.6.1.5, Confidentiality,
A.7.2.1, SC-11 Trusted Path None
Integrity
External System A.13.1.2,
SA-9 Cryptographic Key
Services A.13.2.2,
A.15.2.1, SC-12 Establishment and A.10.1.2
A.15.2.2 Management
A.12.1.2, A.10.1.1,
Developer Cryptographic A.14.1.2,
A.14.2.2, SC-13
SA-10 Configuration Protection A.14.1.3,
A.14.2.4,
Management A.18.1.5
A.14.2.7
Developer Testing A.14.2.7, SC-14 Withdrawn ---
SA-11
and Evaluation A.14.2.8 Collaborative
SA-12 Withdrawn --- SC-15 Computing Devices A.13.2.1*
and Applications
SA-13 Withdrawn ---
SA-14 Withdrawn ---
28
Transmission of Confidentiality,
Confidentiality, SC-43 Usage Restrictions None
SC-16 Security and Privacy None Integrity
Integrity
Attributes Detonation Confidentiality,
SC-44 None
Public Key Chambers Integrity, Availability
SC-17 Infrastructure A.10.1.2 System Time
Certificates SC-45 None Integrity
Synchronization
Confidentiality, Cross Domain Policy Confidentiality,
SC-18 Mobile Code None SC-46 None
Integrity Enforcement Integrity, Availability
SC-19 Withdrawn Alternate
Secure SC-47 Communications None Availability
Name/Address Paths
SC-20 Resolution Service None Integrity Confidentiality,
(Authoritative SC-48 Sensor Relocation None
Integrity
Source)
Hardware-Enforced
Secure Confidentiality,
SC-49 Separation and Policy None
Name/Address Integrity, Availability
Enforcement
SC-21 Resolution Service None Integrity
(Recursive or Caching Software-Enforced
Confidentiality,
Resolver) SC-50 Separation and Policy None
Integrity, Availability
Enforcement
Architecture and
Provisioning for Hardware-Based Confidentiality,
SC-22 None Integrity SC-51 None
Name/Address Protection Integrity, Availability
Resolution Service 5.2, 5.3, 7.5.1,
Confidentiality, 7.5.2, 7.5.3,
SC-23 Session Authenticity None System and
Integrity A.5.1.1, A.5.1.2,
Information Integrity
SI-1 A.6.1.1,
Confidentiality, Policy and
SC-24 Fail in Known State None A.12.1.1,
Integrity Procedures
A.18.1.1,
Confidentiality, A.18.2.2
SC-25 Thin Nodes None
Integrity, Availability A.12.6.1,
Confidentiality, A.14.2.2,
SC-26 Decoys None SI-2 Flaw Remediation
Integrity, Availability A.14.2.3,
Platform- A.16.1.3
SC-27 Independent None Availability Malicious Code
SI-3 A.12.2.1
Applications Protection
Protection of Confidentiality,
SC-28 A.8.2.3* SI-4 System Monitoring None
Information at Rest Integrity, Availability
SC-29 Heterogeneity None Availability Security Alerts,
Concealment and Confidentiality, SI-5 Advisories, and A.6.1.4*
SC-30 None Directives
Misdirection Integrity, Availability
Covert Channel Security and Privacy Confidentiality,
SC-31 None Confidentiality SI-6 None
Analysis Function Verification Integrity
Confidentiality, Software, Firmware,
SC-32 System Partitioning None SI-7 and Information None Integrity
Availability
Integrity
SC-33 Withdrawn ---
SI-8 Spam Protection None Integrity, Availability
Non-Modifiable
SC-34 None Integrity, SI-9 Withdrawn ---
Executable Programs
External Malicious Confidentiality, Information Input
SC-35 None SI-10 None Integrity
Code Identification Integrity, Availability Validation
Distributed Confidentiality,
SI-11 Error Handling None
SC-36 Processing and None Availability Integrity, Availability
Storage Information
Confidentiality,
Out-of-Band Confidentiality, SI-12 Management and None
SC-37 None Integrity, Availability
Channels Integrity, Availability Retention
SC-38 Operations Security A.12.x Predictable Failure
SI-13 None Integrity, Availability
Prevention
Process
Confidentiality, Confidentiality,
SC-39 Isolation None SI-14 Non-Persistence None
Integrity, Availability Integrity, Availability
Wireless Link Confidentiality, Information Output Confidentiality,
SC-40 None SI-15 None
Protection Integrity Filtering Integrity, Availability
Port and I/O Device Confidentiality, Confidentiality,
SC-41 None SI-16 Memory Protection None
Access Integrity Integrity, Availability
Sensor Capability and Confidentiality,
SC-42 A.11.1.5* SI-17 Fail-Safe Procedures None
Data Integrity, Availability
29
Personally [AT-4 Training Records], [AT-6 Training
Identifiable Confidentiality, Feedback]. These two controls require the
SI-18 None
Information Quality Integrity, Availability
Operations organization to document and monitor
Confidentiality, information security and privacy training
SI-19 De-identification None activities, including security and privacy
Integrity
Confidentiality, awareness training and specific role-based
SI-20 Tainting None
Integrity security and privacy training, retain individual
SI-21 Information Refresh None Confidentiality training records, and gather feedback on
SI-22 Information Diversity None Integrity organizational training results [10]. These could
Information Confidentiality, be important indicators of the awareness process
SI-23 None
Fragmentation Integrity
effectiveness in the organization. These controls
5.2, 5.3, 7.5.1,
very often are audited by auditors during the ISO
7.5.2, 7.5.3,
A.5.1.1, A.5.1.2, 27001 certification process; however, they are not
Supply Chain Risk
SR-1 Management Policy
A.6.1.1, explicitly mentioned in ISO 27001.
A.12.1.1, [CM-2 Baseline Configuration], [CM-6
and Procedures
A.15.1.1,
A.18.1.1, Configuration Settings]. These controls force
A.18.2.2 organizations to develop, document, and maintain
Supply Chain Risk under configuration control, a current baseline
SR-2 A.14.2.7*
Management Plan configuration of the system, and configuration
Supply Chain settings for components. Baseline configurations
A.15.1.2,
SR-3 Controls and
Processes
A.15.1.3* for systems and system components include
SR-4 Provenance A.14.2.7*
connectivity, operational, and communications
Acquisition
aspects of systems. Baseline configurations are
SR-5 Strategies, Tools, and A.15.1.3 documented, formally reviewed, and agreed-upon
Methods specifications for systems or configuration items
SR-6
Supplier Assessments
A.15.2.1
within those systems. Baseline configurations
and Reviews serve as a basis for future builds, releases, or
Supply Chain changes to systems and include security and
SR-7 A.15.2.2*
Operations Security
privacy control implementations, operational
Notification Confidentiality,
SR-8
Agreements
None
Integrity procedures, information about system
Tamper Resistance components, network topology, and logical
SR-9 None Integrity placement of components in the system
and Detection
Inspection of Systems architecture [10]. These controls are important for
SR-10 None Integrity
or Components maintaining the integrity of the security
Component configurations for the systems and components
SR-11 None Integrity
Authenticity
and ensuring the standard configuration for the
SR-12 Component Disposal None Confidentiality
infrastructure systems and components. Again,
these aspects are not explicitly highlighted in the
As may be seen from the table there is an ISO 27001 but commonly are checked during the
overlapping between the controls from ISO and ISO certification process.
NIST frameworks. But the most important [PE-6 Monitoring Physical Access], [PE-8
specifics of these frameworks is that NIST 800-53 Visitor Access Records]. NIST 800-53 requires
can be considered a super-set of ISO 27001. In from organizations to monitor physical access to
particular, all the controls from ISO 27001 can be the facility where the system resides to detect and
covered by NIST 800-53. However, ISO 27001 respond to physical security incidents and to
does not cover all of the areas of NIST 800-53. maintain and periodically review visitor access
From the coverage perspective, NIST 800-53 is records to the facility where the system resides
more comprehensive and contains much more [10]. These are other examples of controls that are
areas and controls than ISO 27001. While the extremely relevant for the protection of the
detailed analysis of the missing controls is out of organization’s assets. They are especially
the scope of this investigation let’s take a look at a important for small representative offices that
few examples which would show in which areas often are lacking baseline security controls
NIST, in contrast to ISO, provide more established within headquarters and are also quite
comprehensive coverage of the security-related often emphasized during the ISO certification
areas. audits. Nevertheless, they have been overlooked
30
for a quite long time until the issue of the revised be tightened to the organization’s context and
version of the ISO 27002 earlier this year (so they needs and expectations of interested parties.
should appear in the new version of the ISO 27001 A common misunderstanding is that
as well). companies have to pick one or the other
[RA-10 Threat Hunting]. Threat hunting is an framework and stick with it, or that one is better
active means of cyber defense in contrast to than the other. In fact, both frameworks can be
traditional protection measures, such as firewalls, applied to a single organization due to their
intrusion detection and prevention systems, synergy and can greatly increase its information
quarantining malicious code in sandboxes, and security, risk management, and security program.
Security Information and Event Management It is not always necessary to choose between
technologies and systems. Cyber threat hunting NIST 800-53 and ISO 27001. In fact, the two are
involves proactively searching organizational complementary and can be used in the same
systems, networks, and infrastructure for organization. However, if certification is your
advanced threats. The objective is to track and goal, you should definitely look closer at ISO
disrupt cyber adversaries as early as possible in the 27001. Being externally audited and achieving
attack sequence and to measurably improve the accredited certification against ISO 27001’s
speed and accuracy of organizational responses. requirements would likely provide a higher level
[10]. Likewise the previous controls, this one has of confidence among clients and stakeholders and
been also overlooked by the ISO 27001 would be a prerequisite for securing certain
publications, despite its extreme importance and contracts. Accredited certification to ISO 27001
relevance for the organizations. This demonstrates that your organization follows
inconsistency should be partially eliminated with information security best practices, and delivers
the new version of the ISO 27001 standard - this an independent, expert assessment of whether
year's revised version of ISO 27002 already your valuable information and information assets
contains a new control defining requirements for are adequately protected. At the same time, while
threat intelligence which is an integral part of the implementing the ISO 27001 requirements you
threat hunting process. still can leverage NIST 800-53 to strengthen the
[PM-18 Privacy Program Plan], [PT-1 areas that are missing or not sufficiently covered
Personally Identifiable Information Processing in the ISO.
and Transparency Policy and Procedures],
[PT-2 Authority to Process Personally 4. References
Identifiable Information], [PT-4 Consent], [PT-
5 Privacy Notice] and other controls related to the
protection of personally identifiable information [1] H. Taherdoost, Understanding Cybersecurity
Frameworks and Information Security
(PII) processing. The defining characteristic of the
Standards—A Review and Comprehensive
NIST 800-53 is that it contains a set of controls to
Overview, 2022. doi: 10.3390/
address privacy requirements for the processing of
PII while ISO 27001 does not specifically address electronics11142181.
privacy beyond the inherent benefits provided by [2] T. Conkle, G. Witte, Improving
maintaining the security of PII, therefore we can Cybersecurity through the Use of the
assume that the ISO 27001 controls do not satisfy Cybersecurity Framework, in 9th
privacy requirements with respect to PII International Topical Meeting on Nuclear
processing [29]. From this perspective, NIST has Plant Instrumentation, Control, and Human-
an advantage over ISO 27001 in regard to the Machine Interface Technologies, NPIC and
protection of the PII processing and may be HMIT, vol. 3, 2015, pp. 2479–2486.
considered a good basis for GDPR compliance. [3] V. Buriachok, V. Sokolov, P. Skladannyi,
Security Rating Metrics for Distributed
Wireless Systems, in 8th International
3. Conclusion Conference on “Mathematics. Information
Technologies. Education:” Modern Machine
Understanding both the differences and Learning Technologies and Data Science
similarities between these two the most known and (MoMLeT and DS), vol. 2386, 2019, pp.
adopted security frameworks—ISO 27001 and 222–233.
NIST 800-53 is crucial for implementing an [4] F. Kipchuk, et al., Assessing Approaches of
effective information security program that would IT Infrastructure Audit, in IEEE 8th
31
International Conference on Problems of [18] Regulation (EU) 2016/679 of the European
Infocommunications, Science and Parliament and of the Council on the
Technology, PICST, 2021. doi: Protection of Natural Persons with Regard to
10.1109/picst54195.2021.9772181. the Processing of Personal Data and on the
[5] I. Kuzminykh, et al., Investigation of the IoT Free Movement of Such Data, 2018, pp. 1–
Device Lifetime with Secure Data 88.
Transmission, Internet of Things, Smart [19] ISO/IEC 27701:2019, Security Techniques
Spaces, and Next Generation Networks and — Extension to ISO/IEC 27001 and ISO/IEC
Systems, 2019, pp. 16–27. doi: 10.1007/978- 27002 for Privacy Information Management
3-030-30859-9_2. — Requirements and Guidelines, 2019,
[6] NIST Cybersecurity Framework vs ISO https://www.iso.org/standard/71670.html
27001/27002 vs NIST 800-53 vs Secure [20] Trust Services Criteria Issued by the AICPA
Controls Framework. URL: Assurance Services Executive Committee,
https://www.complianceforge.com/faq/nist- 2017, https://www.aicpa.org/content/dam/
800-53-vs-iso-27002-vs-nist-csf-vs-scf aicpa/interestareas/frc/assuranceadvisoryser
[7] A. Zahoor, et al., Information Security vices/downloadabledocuments/trust-
Management Needs More Holistic Approach: services-criteria.pdf
A Literature Review, 2016. doi: [21] COBIT 5, A Framework for the Governance
10.1016/j.ijinfomgt.2015.11.009 and Management of Enterprise IT, 2012.
[8] ISO/IEC 27001: Information Technology— [22] D. Sulistyowati, F. Handayani, Y. Suryanto,
Security Techniques—Information Security Comparative Analysis and Design of
Management Systems—Requirements, 2013, Cybersecurity Maturity Assessment
https://www.iso.org/standard/54534.html. Methodology Using NIST CSF COBIT
[9] ISO/IEC 27002: Information Technology— ISO/IEC 27002 and PCI DSS, International
Security Techniques—Code of Practice for Journal on Informatics Visualization, vol. 4,
Information Security Controls, 2013, no. 4, 2020, pp. 225–230.
https://www.iso.org/standard/54533.html. [23] M. Siponen, R. Willison, Information
[10] (2020) Security and Privacy Controls for Security Management Standards: Problems
Information Systems and Organizations and Solutions, J. Information &
Special Publication (SP) 800-53 Rev 5, U.S. Management, vol. 46, 2009, pp. 267–270.
Department of Commerce, 2020, [24] S. Yevseiev, et al. Synergy of Building
https://csrc.nist.gov/publications/detail/sp/8 Cybersecurity Systems: Monograph, PC
00-53/rev-5/final. Technology Center, 2021.
[11] Overview of the NIST Cybersecurity [25] Computer Security Resource Center - SP
Framework, 2018, https://1path2020b. 800-53 Rev. 5. https://csrc.nist.gov/
websitetotalcare.com/blog/overviewof- publications/detail/sp/800-53/rev-5/final
thenist-cybersecurity-framework. [26] V. Susukailo, I. Opirsky, O. Yaremko,
[12] PCI DSS Quick Reference Guide, Methodology of ISMS Establishment
Understanding the Payment Card Industry Against Modern Cybersecurity Threats, in
Data Security Standard, ver. 3.2.1, 2018, Future Intent-Based Networking. Lecture
https://www.pcisecuritystandards.org/docu Notes in Electrical Engineering, vol. 831,
ments/PCI_DSS-QRG-v3_2_1.pdf 2022. doi: 10.1007/978-3-030-92435-5_15.
[13] CIS Controls v8, Center for Internet Security, [27] ISO Official website—ISO/IEC 27001
2021, https://www.cisecurity.org/controls/ Information security management,
v8/. https://www.iso.org/isoiec-27001-
[14] CIS Controls v8 Mapping to NIST SP 800- information-security.html
53 Rev 5, Center for Internet Security, 2021. [28] Best Practice ISO 27001 Required
[15] HITRUST CSF Framework, HITRUST Documentation. https://www.riskmanage
Alliance, 2021, https://hitrustalliance.net/ mentstudio.com/best-practice-iso-27001-
product-tool/hitrust-csf/ required-documentation/
[16] HIPAA; Pub. L. 104-191, 110 Stat. 1936, [29] NIST SP 800-53, Revision 5 Control
enacted August 21, 1996 Mappings to ISO/IEC 27001 URL:
[17] Cloud Controls Matrix, Cloud Security https://csrc.nist.gov/CSRC/media/Publicatio
Alliance, 2021, https://cloudsecurityalliance. ns/sp/800-53/rev-5/final/documents/sp800-
org/artifacts/cloud-controls-matrix-v4/ 53r5-to-iso-27001-mapping.docx
32