Skip to content

    ISO/IEC 27001:2022 (ISMS clauses) to NIST CSF 2.0 control mapping

    ISO/IEC 27001:2022 (ISMS clauses) and NIST CSF 2.0 both map to 47 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    47
    ISO/IEC 27001:2022 (ISMS clauses) controls involved
    24
    NIST CSF 2.0 controls involved
    72
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored ISO/IEC 27001:2022 (ISMS clauses) to NIST CSF 2.0 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both ISO/IEC 27001:2022 (ISMS clauses) and NIST CSF 2.0, with the controls on each side that map to them.
    NIST 800-53 controlFamilyISO/IEC 27001:2022 (ISMS clauses) controlsNIST CSF 2.0 controls
    AC-1Policy and ProceduresACAccess Control5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-05
    AT-1Policy and ProceduresATAwareness and Training5.1, 5.2, 7.4, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03
    AT-2Literacy Training and AwarenessATAwareness and Training7.4PR.AT-01
    AU-1Policy and ProceduresAUAudit and Accountability5.1, 5.2, 7.5.1, 7.5.2, 7.5.3DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-04
    CA-1Policy and ProceduresCAAssessment, Authorization, and Monitoring5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.RA-01
    CA-2Control AssessmentsCAAssessment, Authorization, and Monitoring8.1, 9.1ID.IM-01, ID.IM-02, ID.RA-01
    CA-7Continuous MonitoringCAAssessment, Authorization, and Monitoring10.1, 8.1GV.OC-03
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and Monitoring10.1, 8.1GV.OC-03
    CM-1Policy and ProceduresCMConfiguration Management5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-01, PR.PS-05
    CM-3Configuration Change ControlCMConfiguration Management6.3ID.RA-07
    CP-1Policy and ProceduresCPContingency Planning5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05
    IA-1Policy and ProceduresIAIdentification and Authentication5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-05
    IR-1Policy and ProceduresIRIncident Response5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-08, ID.IM-02, ID.IM-03, ID.IM-04, RS.AN-03
    MA-1Policy and ProceduresMAMaintenance5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-02, PR.PS-03
    PE-1Policy and ProceduresPEPhysical and Environmental Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3DE.CM-02, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-06, PR.IR-02
    PE-22Component MarkingPEPhysical and Environmental Protection4.3ID.AM-05
    PL-1Policy and ProceduresPLPlanning4.1, 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, 9.1, 9.2.1, 9.2.2GV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RR-03, GV.SC-01, GV.SC-03, GV.SC-05, ID.RA-09, PR.PS-06
    PL-9Central ManagementPLPlanning5.1, 5.3GV.RM-05, GV.RR-01, GV.RR-02
    RA-1Policy and ProceduresRARisk Assessment5.1, 5.2, 6.1.1, 6.1.2, 7.5.1, 7.5.2, 7.5.3, 8.2GV.OV-01, GV.OV-02, GV.OV-03, GV.PO-01, GV.PO-02, GV.RM-01, GV.RM-03, GV.RM-04, GV.RM-06, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09
    RA-2Security CategorizationRARisk Assessment6.1.2ID.RA-04
    RA-3Risk AssessmentRARisk Assessment6.1.2, 8.2GV.RM-06, ID.IM-01, ID.IM-02, ID.RA-01, ID.RA-04, ID.RA-05
    RA-7Risk ResponseRARisk Assessment6.1.3, 8.3GV.RM-04, ID.RA-05, ID.RA-06
    SA-1Policy and ProceduresSASystem and Services Acquisition5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.RA-09, PR.PS-06
    SA-5System DocumentationSASystem and Services Acquisition4.3ID.AM-05
    SA-9(3)Establish and Maintain Trust Relationship with ProvidersSASystem and Services Acquisition4.3GV.OC-02, GV.OC-04, GV.OC-05, GV.RM-05, GV.RR-02, GV.SC-01, GV.SC-02, GV.SC-03, GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-09, GV.SC-10, ID.AM-05, ID.RA-10
    SC-1Policy and ProceduresSCSystem and Communications Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SI-1Policy and ProceduresSISystem and Information Integrity5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information Integrity7.4DE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    SI-5(1)Automated Alerts and AdvisoriesSISystem and Information Integrity7.4DE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    MP-1Policy and ProceduresMPMedia Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.AM-08, PR.DS-01, PR.DS-02, PR.DS-10
    PS-1Policy and ProceduresPSPersonnel Security5.1, 5.2, 7.2, 7.3, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RR-04, GV.SC-01, GV.SC-03
    PS-2Position Risk DesignationPSPersonnel Security7.2GV.RR-02, PR.AA-05
    PS-9Position DescriptionsPSPersonnel Security5.3, 7.3GV.RM-05, GV.RR-02
    PM-1Information Security Program PlanPMProgram Management10.1, 4.4, 5.1, 5.2, 6.1.1, 7.5.1, 7.5.2, 7.5.3, 8.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RM-01, GV.RM-03, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-09
    PM-2Information Security Program Leadership RolePMProgram Management5.1, 5.3GV.RM-05, GV.RR-01, GV.RR-02
    PM-3Information Security and Privacy ResourcesPMProgram Management5.1, 7.1GV.RR-03
    PM-6Measures of PerformancePMProgram Management5.1, 5.3, 9.1GV.OV-01, GV.OV-03, GV.RM-05, GV.RR-01, GV.RR-02, GV.SC-09, ID.IM-03
    PM-8Critical Infrastructure PlanPMProgram Management4.1, 9.1, 9.2.1, 9.2.2GV.OC-03, GV.SC-05, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05
    PM-9Risk Management StrategyPMProgram Management6.1.1, 6.1.2, 8.2GV.OV-02, GV.OV-03, GV.RM-01, GV.RM-02, GV.RM-03, GV.RM-04, GV.RM-06, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, ID.RA-04
    PM-13Security and Privacy WorkforcePMProgram Management5.3, 7.3, 7.4GV.RM-05, GV.RR-02
    PM-14Testing, Training, and MonitoringPMProgram Management10.1, 8.1GV.OC-03
    PM-16(1)Automated Means for Sharing Threat IntelligencePMProgram Management7.4DE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    PM-28Risk FramingPMProgram Management6.1.2GV.OC-01, GV.RM-04, GV.RM-06, GV.RM-07, ID.RA-05, ID.RA-06
    PM-29Risk Management Program Leadership RolesPMProgram Management5.1, 5.3, 6.1.1, 6.1.2, 8.2GV.OV-02, GV.OV-03, GV.RM-01, GV.RM-03, GV.RM-04, GV.RM-05, GV.RM-06, GV.RR-01, GV.RR-02, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10
    PT-1Policy and ProceduresPTPII Processing and Transparency5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SR-1Policy and ProceduresSRSupply Chain Risk Management5.1, 5.2, 7.5.1, 7.5.2, 7.5.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-10
    SR-7Supply Chain Operations SecuritySRSupply Chain Risk Management8.1GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.