NIST CSF, ISO 27001, COBIT, CIS Controls: which cybersecurity framework?

NIST CSF 2.0, ISO 27001, COBIT 2019 and CIS Controls v8.1: what each framework does, where they overlap and how to combine them for your context.

· 11 min read
Illustration: four overlapping glass frames, their shared area in orange

A cybersecurity framework gives you a shared structure to organise security and measure where you stand. The four most cited, NIST CSF, ISO 27001, COBIT and the CIS Controls, do not answer the same question: the first describes outcomes, the second a certifiable management system, the third the governance of enterprise IT, and the last prioritised technical safeguards.

So "which one should we choose?" is a slightly misleading question. For most organisations the right answer is one anchor framework complemented by one or two others. This comparison presents each framework in its current version, shows where they overlap and suggests combinations by context.

01

What is a cybersecurity framework?

A framework is a structured set of requirements, good practices or expected outcomes published by a recognised body. It serves three purposes: not forgetting anything, speaking the same language as auditors, customers and regulators, and measuring progress over time.

Frameworks differ in nature. A standard such as ISO 27001 contains auditable requirements and can be certified. A framework such as NIST CSF sets objectives without prescribing means. A catalogue such as the CIS Controls details technical safeguards. A governance framework such as COBIT looks at how the enterprise decides and controls. None of them replaces a risk analysis: they tell you what to cover, not which risk matters most to you.

02

NIST CSF 2.0: six functions to describe your posture

The Cybersecurity Framework (CSF) is published by NIST, the US National Institute of Standards and Technology. Version 2.0, released on 26 February 2024, extended a framework originally designed for critical infrastructure to all organisations, whatever their sector or size.

Its core is organised into six functions: govern, identify, protect, detect, respond and recover. Govern is the main addition in 2.0: it treats cybersecurity as an enterprise risk, alongside financial and reputational risks. The functions break down into 22 categories and then subcategories, each describing an outcome.

The CSF is used with profiles: a current profile describes the outcomes achieved, a target profile those the organisation aims for, and the gap becomes the roadmap. Tiers (from "partial" to "adaptive") describe how rigorous risk management is. The document is free and, as NIST points out, it does not prescribe outcomes nor how to achieve them: there is no NIST CSF certification.

03

ISO 27001: the certifiable management system

ISO/IEC 27001:2022 sets the requirements for an information security management system (ISMS). Clauses 4 to 10 describe the management loop: context, leadership, risk assessment, support, operation, performance evaluation and improvement. Annex A lists 93 controls grouped into four themes (organisational, people, physical and technological).

Its strength is that it is certifiable by an accredited body and recognised worldwide. It is risk-based, often using ISO 27005 or EBIOS Risk Manager: you do not adopt all 93 controls by default, you justify each choice in the statement of applicability. On the other hand, the standard is paid for and requires real documentation effort, starting with an information security policy approved by management.

04

COBIT 2019: governance of enterprise IT

COBIT is published by ISACA, the international association of IT audit and governance professionals. The 2019 version has 40 governance and management objectives in five domains: Evaluate, Direct and Monitor (EDM, the only governance domain), then Align, Plan and Organise (APO), Build, Acquire and Implement (BAI), Deliver, Service and Support (DSS), and Monitor, Evaluate and Assess (MEA). Design factors let each enterprise tailor its governance system (ISACA overview).

COBIT is not a cybersecurity framework in the strict sense: security is covered by a few objectives, including Managed Security (APO13) and Managed Security Services (DSS05), next to risk, project and supplier management. Its value lies elsewhere: linking IT and cyber decisions to business objectives, which makes it popular with internal auditors, finance departments and regulated sectors.

05

CIS Controls v8.1: prioritised technical safeguards

The CIS Controls are published by the Center for Internet Security, a US non-profit. There are 18 controls, from asset inventory to penetration testing, broken down into 153 safeguards. Version 8.1, released on 25 June 2024, added a governance function aligned with NIST CSF 2.0 and clarified asset classes.

Their strength is prioritisation. Safeguards are split into three implementation groups: IG1 contains 56 safeguards described as essential cyber hygiene for every organisation, IG2 adds to it for more exposed organisations, and IG3 covers everything. In France, the closest equivalent is ANSSI's IT hygiene guide and its 42 measures.

06

Cybersecurity framework comparison table

Comparison of NIST CSF 2.0, ISO 27001, COBIT 2019 and CIS Controls v8.1
CriterionNIST CSF 2.0ISO 27001COBIT 2019CIS Controls v8.1
PublisherNIST (United States)ISO and IECISACACenter for Internet Security
Current version2.0, February 2024202220198.1, June 2024
NatureOutcome frameworkManagement system requirementsEnterprise IT governance frameworkCatalogue of technical safeguards
Structure6 functions, 22 categoriesClauses 4 to 10 and 93 controls (Annex A)40 objectives in 5 domains18 controls, 153 safeguards, 3 groups
CertificationNoYes, by an accredited bodyNot for the enterprise (individual certifications)No
AccessFreePaid standardISACA publicationsFree download
StrengthCommon language, board reportingRecognised proof, risk-basedLink to strategy and auditConcrete priorities, quick wins
LimitDoes not say howDocumentation effort, costBroad, light on technical detailLittle governance or organisation
07

How the frameworks overlap

The simplest way to compare them is to use the six NIST CSF functions as a common grid, which is what CIS has done since version 8.1. The grid below shows which functions each framework covers in depth and which only in part. Pick a framework to see its angle, or overlay them all.

Overlaps Four frameworks on one grid

Overlaid, the four frameworks complement each other: COBIT and ISO 27001 carry governance, CIS Controls brings technical detail, and NIST CSF is the common language for comparison.

NIST CSF 2.0The grid itself: six functions and outcomes to achieve, without prescribing how. Use it to position the others.

ISO 27001A management system (clauses 4 to 10) plus the 93 Annex A controls: very strong on governance, risk and protection, lighter on detection and recovery.

COBIT 2019Governance of all enterprise IT. Security takes up only a few of the forty objectives, but this is the framework that links cyber to board decisions.

CIS Controls v8.1Prioritised technical safeguards, very concrete on inventory, protection, detection and response; governance only arrived with version 8.1.

Indicative coverage of the six NIST CSF 2.0 functions by each framework
Framework GovernIdentifyProtectDetectRespondRecover
NIST CSF 2.0 Strong Strong Strong Strong Strong Strong
ISO 27001 Strong Strong Strong Partial Partial Partial
COBIT 2019 Strong Partial Partial Partial Partial Partial
CIS Controls v8.1 Partial Strong Strong Strong Strong Partial
Phinasoft's indicative reading, based on the published structure of each framework.

Two lessons stand out. First, no framework covers both ends of the chain on its own: COBIT and ISO 27001 carry governance and decisions, the CIS Controls the technical detail. Second, the overlap between ISO 27001, NIST CSF and the CIS Controls is massive. Assessing each separately means asking the same teams the same question three times. The publishers know this: NIST publishes mappings between the CSF and other documents, and CIS maps its safeguards to the CSF functions.

08

Which cybersecurity framework fits your context?

Four situations come up often.

Customers or tenders ask for proof

ISO 27001 is the natural anchor: it is the only one of the four that leads to a certification recognised everywhere. NIST CSF can be used to present your posture to management, and the CIS Controls to detail the technical side of Annex A.

You are in scope of NIS 2

The NIS 2 Directive does not mandate a framework, but its risk management measures overlap widely with ISO 27001. ENISA's technical guidance, published in June 2025, maps the implementing regulation's requirements to existing standards. For France, see our article on the resilience bill that transposes the directive.

You are starting out with a small team

Start with the concrete: CIS Controls IG1 or ANSSI's hygiene guide. Once the basics are in place, structure the approach with ISO 27001, even if certification is not an immediate goal.

Your board and internal audit think in terms of governance

COBIT provides the frame to link cyber to business objectives and enterprise risk management. It combines well with ISO 27001 for the security part, which the CISO continues to lead.

In every case, the key is to keep a single base of interlinked requirements rather than one spreadsheet per framework: our guide to compliance management explains how to build these mappings. That is what a structured governance, risk and compliance approach makes possible, including for the requirements you set for your suppliers.

Going further: Phinasoft's policies editor lets you manage standards and regulations, link them together and calculate indicators by framework or scope.

Summary

01

Four different kinds of framework

NIST CSF describes outcomes, ISO 27001 a certifiable management system, COBIT the governance of enterprise IT, and CIS Controls prioritised technical safeguards.

02

Complementary rather than competing

The overlaps are large: pick one anchor framework, borrow what is missing from the others, and avoid assessing everything twice.

03

Context decides

Certification demands, regulators, team size and maturity matter far more than a framework's reputation.

Frequently asked questions about cybersecurity frameworks

What is a cybersecurity framework?

A structured set of requirements, good practices or expected outcomes, published by a recognised body, used to organise security and measure progress. Some are certifiable standards (ISO 27001), others voluntary frameworks (NIST CSF, CIS Controls, COBIT).

What is the difference between ISO 27001 and NIST CSF?

ISO 27001 sets the requirements for an information security management system and can be certified by an accredited body. NIST CSF 2.0 describes cybersecurity outcomes in six functions, with no certification and no prescribed means. The latter is often used to present and compare, the former to structure and prove.

Is COBIT a cybersecurity framework?

Not only. COBIT 2019, published by ISACA, is a framework for the governance and management of enterprise information and technology as a whole. Security is covered by some of its 40 objectives, but its main value is linking IT and cyber decisions to business objectives and the board.

What are the CIS Controls?

Eighteen security controls published by the Center for Internet Security, broken down into 153 safeguards and prioritised into three implementation groups. The first, IG1, contains 56 safeguards described as essential cyber hygiene for every organisation. The current version is 8.1, released in June 2024.

Can you follow several frameworks at once?

Yes, and most organisations do. Good practice is to pick an anchor framework, often ISO 27001, then map the other requirements (NIST CSF, CIS Controls, NIS 2) to it so that a control assessed once counts for several frameworks.

Which framework helps prepare for NIS 2?

The NIS 2 Directive does not mandate any framework. Its risk management measures overlap widely with ISO 27001, which remains the most common starting point in Europe. ENISA's technical guidance, published in June 2025, maps the implementing regulation's requirements to existing standards.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.