Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
Cyber Security Framework and Standards: NIST and ISO 27001
Updated 11 October 2026 · Fact-checked
A cyber security framework is a structured set of practices for managing security risk. A standard sets requirements you can be audited against. NIST CSF groups work into functions: Govern, Identify, Protect, Detect, Respond, Recover. ISO/IEC 27001 specifies an information security management system. In answers, define, list components, compare and apply to the facts.
Understand Cyber Security Framework and Standards
Every organisation faces cyber risk, but it cannot fix everything at once. A framework gives a common structure to decide what to protect, how, and in what order. A standard goes further: it lists requirements, and an independent auditor can check you against them.
The NIST Cybersecurity Framework (CSF) is published by the US National Institute of Standards and Technology. It is voluntary and not certifiable. Version 1.1 had five functions: Identify, Protect, Detect, Respond, Recover. Version 2.0 (2024) added a sixth, Govern, covering strategy, roles, policy and oversight. Students often search for the five functions, so write both: the five core functions, plus Govern in the current version. The framework also uses implementation tiers and profiles (current and target) to show where you are and where you want to be.
ISO/IEC 27001 is an international standard for an Information Security Management System (ISMS). An ISMS is the set of policies, processes, people and controls used to protect the confidentiality, integrity and availability of information (the CIA triad). It follows a risk-based, continual improvement approach. A company can be certified by an accredited body. The main clauses cover context of the organisation, leadership, planning (risk assessment and treatment), support, operation, performance evaluation and improvement.
ISO/IEC 27001 has an Annex A list of controls. In the 2022 edition there are 93 controls in four themes: organisational, people, physical and technological. The company chooses controls based on its risk assessment and records the choice in a Statement of Applicability. ISO/IEC 27002 gives guidance on implementing these controls.
In India, no single framework is compulsory for all companies. But the law expects security that is reasonable. The 2011 Sensitive Personal Data Rules under the IT Act name ISO/IEC 27001 as one example of a recognised standard. CERT-In directions and sector regulators add specific duties. So frameworks help you show reasonable care and demonstrate compliance.
Key rules to remember
- CIA triad
- Information security = Confidentiality + Integrity + Availability
- The three goals every framework and ISMS control aims to protect.
- NIST CSF functions
- Govern → Identify → Protect → Detect → Respond → Recover
- Five functions in version 1.1 (without Govern); six in version 2.0. Govern sits across all the others.
- ISO/IEC 27001 cycle
- Plan → Do → Check → Act (continual improvement)
- The ISMS is a continuing process, not a one-time project.
- Annex A structure (2022 edition)
- 93 controls = 4 themes: organisational, people, physical, technological
- Controls are selected on risk; exclusions must be justified in the Statement of Applicability.
- Certification rule
- ISO/IEC 27001: certifiable. NIST CSF: not certifiable.
- This is the sharpest point of difference in comparison questions.
- Risk
- Risk = Likelihood × Impact
- Used in risk assessment under both ISO 27001 and the NIST Identify function.
How to solve Cyber Security Framework and Standards questions
Use this method for definition, comparison and case questions on frameworks and standards.
- 1Read the question and mark the task word: explain, compare, advise or apply.
- 2Define the framework or standard in one or two lines, with its issuer and whether it is voluntary or certifiable.
- 3List the core components: functions for NIST CSF; clauses, ISMS and Annex A controls for ISO 27001.
- 4For a case question, map each fact in the problem to a function or clause (for example, a data breach found late points to Detect).
- 5Link to Indian law where relevant: reasonable security practices, CERT-In reporting duties, the IT Act and board responsibility.
- 6Give a clear recommendation: which framework or standard, which gaps to close first, who is accountable.
- 7Close with a one-line conclusion that answers the exact question asked.
Quickest way: Define, list, map, conclude
When to use it: Use when you have under ten minutes for a 5 to 8 mark question.
- Write one definition line with the framework name and nature (voluntary or certifiable).
- List the functions or clauses in order as short bullets.
- Add one line each on what each item means in practice.
- If comparing, draw a quick two-column list: purpose, certification, structure, focus.
- End with the Indian law link and a conclusion.
Common mistakes in Cyber Security Framework and Standards
Writing only five NIST functions and leaving out Govern, or writing six without mentioning version 1.1.
Older notes and search results still say five.
Fix: Write: five core functions in version 1.1, and Govern added in version 2.0. This covers both.
Saying a company is 'NIST certified'.
Students assume every framework has certification like ISO.
Fix: State that NIST CSF is voluntary guidance and cannot be certified. Only ISO/IEC 27001 offers certification by an accredited body.
Treating ISO 27001 as a list of technical tools.
Students focus on Annex A and forget the management system.
Fix: Say first that it is an ISMS: leadership, risk assessment, policies, audit and improvement. Annex A controls come after the risk assessment.
Confusing ISO/IEC 27001 with ISO/IEC 27002.
The numbers look alike.
Fix: 27001 holds the requirements and is certifiable. 27002 is guidance on implementing controls.
Mixing up Respond and Recover.
Both come after an incident.
Fix: Respond means containing and handling the incident (analysis, communication, mitigation). Recover means restoring systems and operations and learning from the event.
Giving a generic theory answer to a case question.
Students recall notes instead of reading the facts.
Fix: Quote the facts, name the matching function or clause, then recommend an action.
Worked examples
Example 1
Distinguish between the NIST Cybersecurity Framework and ISO/IEC 27001. (6 marks)
Show the solution
- Nature: NIST CSF is a voluntary framework of outcomes and practices. ISO/IEC 27001 is an international standard with auditable requirements.
- Structure: NIST CSF is organised into functions (Identify, Protect, Detect, Respond, Recover, and Govern in version 2.0). ISO/IEC 27001 is organised into management system clauses plus Annex A controls.
- Certification: NIST CSF cannot be certified. An organisation can be certified against ISO/IEC 27001 by an accredited certification body.
- Approach: NIST CSF is flexible and uses profiles and tiers to set targets. ISO/IEC 27001 requires a documented risk assessment, a Statement of Applicability and periodic audits.
- Use together: a company can use NIST CSF to organise its security programme and ISO/IEC 27001 to build and certify its ISMS.
Answer: NIST CSF is voluntary, function-based and not certifiable. ISO/IEC 27001 is a certifiable standard for an ISMS built on risk assessment and controls. They complement each other.
Example 2
Sahyadri Pay Ltd, a Pune payments company, found that a ransomware attack had encrypted its servers. The attack ran for two days before anyone noticed. It has no tested restore plan and no board-level security policy. Advise the board using the NIST CSF and suggest a standard to adopt. (8 marks)
Show the solution
- Govern: the company has no board-level policy. The board should approve a security policy, assign a responsible officer and review risk regularly.
- Identify: list critical assets, such as payment servers and customer data, and run a risk assessment of likelihood and impact.
- Protect: apply access control, patching, backups, staff training and network safeguards.
- Detect: the attack ran for two days unnoticed. Add continuous monitoring and alerting to spot unusual activity early.
- Respond: prepare an incident response plan with contain, investigate and communicate steps, including reporting to CERT-In as required under its directions.
- Recover: keep offline backups, test restoration regularly and set recovery time targets.
- Standard: adopt ISO/IEC 27001 to build an ISMS with leadership commitment, a risk treatment plan and a Statement of Applicability, and seek certification. This also helps show reasonable security practices under the IT Act framework.
Answer: Use NIST CSF to fix gaps across Govern, Identify, Protect, Detect, Respond and Recover. The main gaps are Govern, Detect and Recover. Adopt ISO/IEC 27001 to build a certifiable ISMS.
Exam tips
- Always write the NIST functions in order and add one line of meaning for each. Marks go for explanation, not just the list.
- In comparison questions, include certification, nature and structure as separate points.
- In case questions, tie every recommendation to a fact given in the problem.
- Add the Indian law link (reasonable security practices, CERT-In duties, board oversight) to lift a theory answer to a compliance answer.
- Because papers are descriptive, use short headed bullets so the examiner sees your structure quickly.
Practice questions from Cyber Security
- Under the Information Technology Act, 2000, which authority serves as the national agency for performing functions in the area of cyber secu…
- Sahyadri Pharma Ltd wants a certifiable management system for protecting the confidentiality, integrity and availability of its information …
- The website of a Chennai online ticketing company becomes unreachable on a sale day because thousands of compromised devices spread across m…
- Which provision of the Information Technology Act, 2000 designates CERT-In as the national agency for cyber security functions such as colle…
- A company secretary is asked to preserve a suspect laptop for a possible internal fraud investigation. Which first step best protects the ev…
Cyber Security Framework and Standards in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Security Framework and Standards: frequently asked questions
What are the five functions of the NIST Cybersecurity Framework?
They are Identify, Protect, Detect, Respond and Recover. These were the five core functions in version 1.1. Version 2.0 added Govern as a sixth function, so mention both in your answer.
What is ISO 27001 in simple words?
It is an international standard for setting up an information security management system. The company assesses its risks, picks controls to treat them, and keeps improving. An accredited body can audit and certify it.
What is the difference between ISO 27001 and the NIST framework?
ISO/IEC 27001 is a certifiable standard with auditable requirements for an ISMS. NIST CSF is voluntary guidance organised into functions and cannot be certified. Many organisations use both.
Is any cyber security framework mandatory in India?
No single framework is compulsory for every company. But the law expects reasonable security practices, and CERT-In and sector regulators set specific duties. Standards such as ISO/IEC 27001 help you show compliance.