0Pricing
Cloud & IT Cert Prep · Lesson

NIST RMF, ISO 27001, and CIS Controls

Survey the most widely adopted security frameworks and understand how they complement each other to build a comprehensive information security management system.

NIST RMF, ISO 27001, and CIS Controls is a free Cloud & IT Cert Prep lesson on CoddyKit — lesson 4 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cloud & IT Cert Prep learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Why Frameworks Matter

Security frameworks are structured sets of guidelines, best practices, and controls that help organizations build and maintain effective security programs. Rather than starting from scratch, frameworks provide a proven methodology that can be tailored to organizational size, industry, and risk profile. The Security+ exam focuses on three widely adopted frameworks: NIST RMF, ISO 27001, and the CIS Controls — each approaching security from a different angle.

NIST Risk Management Framework (RMF)

The NIST Risk Management Framework (NIST SP 800-37) is a six-step lifecycle for managing security and privacy risk in federal information systems, though it is widely adopted in the private sector too. The six steps are: Categorize (system and data sensitivity), Select (appropriate controls from SP 800-53), Implement (deploy controls), Assess (test effectiveness), Authorize (ATO decision by authorizing official), and Monitor (continuous monitoring). The RMF emphasizes ongoing authorization rather than point-in-time certifications.

# NIST RMF 6 Steps (SP 800-37 Rev. 2)
1. CATEGORIZE  - Classify system impact (Low/Mod/High)
2. SELECT      - Choose controls from SP 800-53
3. IMPLEMENT   - Deploy and document controls
4. ASSESS      - Test control effectiveness (CA-2)
5. AUTHORIZE   - ATO signed by Authorizing Official
6. MONITOR     - Continuous monitoring (ISCM)

NIST SP 800-53 Control Catalog

NIST SP 800-53 is the control catalog that feeds the RMF Select phase. It organizes hundreds of security and privacy controls into 20 families such as Access Control (AC), Audit and Accountability (AU), Incident Response (IR), and System and Communications Protection (SC). Controls are tagged with baseline assignments (Low, Moderate, High) that match the system's FIPS-199 impact level, so organizations select the right control set for their risk category.

# SP 800-53 control families (abbreviated)
AC  Access Control
AT  Awareness and Training
AU  Audit and Accountability
CA  Assessment, Authorization, and Monitoring
CM  Configuration Management
CP  Contingency Planning
IA  Identification and Authentication
IR  Incident Response
MA  Maintenance
MP  Media Protection
PS  Personnel Security
RA  Risk Assessment
SA  System and Services Acquisition
SC  System and Communications Protection
SI  System and Information Integrity

ISO/IEC 27001 Overview

ISO/IEC 27001 is an international standard for Information Security Management Systems (ISMS). Unlike NIST (which is US-focused), ISO 27001 is globally recognized and organizations can achieve formal third-party certification — which is valuable for customer trust and international contracts. The standard follows the Plan-Do-Check-Act (PDCA) cycle and focuses on building a management system around information security rather than specifying individual technical controls.

# ISO 27001 PDCA Cycle
PLAN  : Establish ISMS scope, risk assessment,
        risk treatment plan, control selection
DO    : Implement controls, training, procedures
CHECK : Internal audits, management review,
        measure control effectiveness
ACT   : Corrective actions, continual improvement

# Certification process
1. Gap analysis
2. Implement controls (Annex A)
3. Stage 1 audit (documentation review)
4. Stage 2 audit (on-site assessment)
5. Certificate issued (valid 3 years, annual surveillance)

ISO 27001 Annex A Controls

Annex A of ISO 27001:2022 contains 93 controls organized into four themes: Organizational (37 controls — policies, roles, supplier relationships), People (8 controls — hiring, training, termination), Physical (14 controls — premises, equipment), and Technological (34 controls — access control, malware, encryption, logging). Not every control must be implemented — organizations select applicable controls based on their Statement of Applicability (SoA), justifying any controls that are excluded.

CIS Controls Overview

The CIS Critical Security Controls (formerly SANS Top 20) are a prioritized set of 18 control groups developed by the Center for Internet Security. They are highly practical and action-oriented, designed for immediate implementation rather than long-term program management. CIS Controls are organized into three Implementation Groups (IGs): IG1 (essential cyber hygiene, 56 safeguards), IG2 (adds 74 safeguards for more complex environments), and IG3 (all 153 safeguards for mature organizations facing sophisticated threats).

# CIS Controls 18 groups
01 Inventory of Enterprise Assets
02 Inventory and Control of Software Assets
03 Data Protection
04 Secure Configuration of Enterprise Assets
05 Account Management
06 Access Control Management
07 Continuous Vulnerability Management
08 Audit Log Management
09 Email and Web Browser Protections
10 Malware Defenses
11 Data Recovery
12 Network Infrastructure Management
13 Network Monitoring and Defense
14 Security Awareness and Skills Training
15 Service Provider Management
16 Application Software Security
17 Incident Response Management
18 Penetration Testing

CIS Benchmarks vs CIS Controls

The CIS Controls define what to do at a high level; CIS Benchmarks define how to do it for specific platforms. CIS Benchmarks provide prescriptive, step-by-step hardening guidance for operating systems (Windows, Linux), cloud platforms (AWS, Azure, GCP), network devices, browsers, and databases. They are freely downloadable and widely used as the technical specification for CIS Control 4 (Secure Configuration). Automation tools like Chef, Ansible, and InSpec can apply CIS Benchmarks at scale.

Comparing NIST, ISO 27001, and CIS

Each framework serves a different primary need. NIST RMF is best for US government and defense contractors requiring formal authorization processes. ISO 27001 is best for organizations that want internationally recognized certification to demonstrate security to customers. CIS Controls are best for organizations seeking prioritized, actionable steps to improve defenses quickly. Many mature organizations use all three: CIS Controls for daily operations, NIST RMF for risk governance, and ISO 27001 for customer-facing certification.

# Framework comparison
Framework    Origin  Certification  Focus
NIST RMF     USA     No (ATO)       Risk lifecycle + authorization
ISO 27001    Intl    YES            ISMS management system
CIS Controls USA     No             Prioritized technical actions

# Common combinations:
# Government : NIST RMF + SP 800-53
# Enterprise : ISO 27001 + CIS Controls
# SMB        : CIS IG1 (56 safeguards minimum)

Other Frameworks and Standards

Additional frameworks appear on the Security+ exam. COBIT (Control Objectives for Information Technologies) focuses on IT governance and aligning security with business objectives. SOC 2 is an auditing standard for service providers that evaluates security, availability, confidentiality, processing integrity, and privacy. PCI-DSS is a prescriptive compliance standard for payment card environments. Understanding these frameworks positions you to speak the language of different industries and regulatory environments.

Framework Selection Criteria

When choosing a framework, consider: regulatory mandate (HIPAA requires addressable safeguards; FedRAMP requires NIST), customer requirements (enterprise customers may require ISO 27001 certification), organizational maturity (CIS IG1 is appropriate for small organizations just starting), and industry sector (financial services may require NIST CSF or SOC 2). Starting with one framework and expanding is better than attempting to implement all frameworks simultaneously, which overwhelms smaller teams.

Frameworks and Continuous Improvement

All three frameworks share a commitment to continuous improvement. The NIST RMF Monitor step drives ongoing control testing. ISO 27001's Act phase requires corrective actions and improvement plans. CIS Controls are versioned and updated as the threat landscape evolves (currently version 8.1). Security programs that treat frameworks as a one-time compliance exercise quickly fall behind — the frameworks are designed as living programs that mature over time alongside organizational capabilities and emerging threats.

Quick Check

Test your understanding of CompTIA Security+ (SY0-701) concepts from this lesson.

Lesson Recap

In this lesson you learned: NIST RMF provides a six-step risk lifecycle (Categorize, Select, Implement, Assess, Authorize, Monitor) with SP 800-53 controls, ISO 27001 is a globally certifiable ISMS standard based on PDCA with Annex A controls, and CIS Controls offer 18 prioritized control groups in three implementation groups for practical, actionable security improvements. Next up we explore data classification schemes and privacy requirements.

Frequently asked questions

Is the “NIST RMF, ISO 27001, and CIS Controls” lesson free?

Yes — the full text of “NIST RMF, ISO 27001, and CIS Controls” is free to read here on the web, and the Cloud & IT Cert Prep course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cloud & IT Cert Prep course, upgrade to CoddyKit PRO.

What will I learn in “NIST RMF, ISO 27001, and CIS Controls”?

Survey the most widely adopted security frameworks and understand how they complement each other to build a comprehensive information security management system. You practise Cloud & IT Cert Prep with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Cloud & IT Cert Prep?

No prior experience is required. Cloud & IT Cert Prep on CoddyKit is structured for beginners through advanced learners; this is — lesson 4 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “NIST RMF, ISO 27001, and CIS Controls” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Cloud & IT Cert Prep lesson?

Yes. Every Cloud & IT Cert Prep lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Risk Identification and Risk Register
  2. Qualitative vs Quantitative Risk Analysis
  3. Risk Treatment: Accept, Transfer, Mitigate, Avoid
  4. NIST RMF, ISO 27001, and CIS Controls
← Back to Cloud & IT Cert Prep