Chapter 3

Audit Frameworks & Standards

Dive deep into the major cybersecurity frameworks and standards used in audit engagements, including NIST CSF, ISO 27001/27002, COBIT, and CIS Controls. Learn how to select the right framework for any organization.

NIST Cybersecurity Framework

Overview of the NIST CSF

The NIST Cybersecurity Framework (CSF) was developed by the National Institute of Standards and Technology in response to Executive Order 13636. Originally designed for critical infrastructure sectors, it has become one of the most widely adopted cybersecurity frameworks globally due to its flexible, risk-based approach. The framework provides a common language for understanding, managing, and expressing cybersecurity risk to both internal and external stakeholders.

The Five Core Functions

  • Identify: Develop an organizational understanding of cybersecurity risk to systems, people, assets, data, and capabilities. This includes asset management, business environment analysis, governance, risk assessment, and risk management strategy.
  • Protect: Develop and implement appropriate safeguards to ensure delivery of critical services. This covers access control, awareness training, data security, information protection processes, maintenance, and protective technology.
  • Detect: Develop and implement appropriate activities to identify the occurrence of a cybersecurity event. This includes anomaly and event detection, security continuous monitoring, and detection processes.
  • Respond: Develop and implement appropriate activities to take action regarding a detected cybersecurity incident. This covers response planning, communications, analysis, mitigation, and improvements.
  • Recover: Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services impaired due to a cybersecurity incident. This includes recovery planning, improvements, and communications.
The NIST CSF is not a prescriptive checklist. It is a risk-based framework that allows organizations to customize their implementation based on their unique risk profile, business requirements, and available resources. This flexibility is both its greatest strength and its biggest challenge for auditors.

Implementation Tiers and Profiles

The framework includes Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) that describe the degree to which an organization's cybersecurity risk management practices exhibit the characteristics defined in the framework. Profiles represent the alignment of the framework core with the organization's specific requirements, risk tolerance, and resources. A 'Current Profile' captures the current state and a 'Target Profile' defines the desired state, with the gap between them driving a prioritized action plan.

ISO 27001 & ISO 27002

ISO 27001: The Information Security Management System Standard

ISO 27001 is an internationally recognized standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Unlike frameworks that provide guidance, ISO 27001 is a certifiable standard, meaning organizations can undergo a formal audit by an accredited certification body to demonstrate compliance. Certification is valid for three years with annual surveillance audits.

  • Context of the Organization: Understanding internal and external issues, interested parties, and the scope of the ISMS.
  • Leadership: Top management commitment, security policy, and organizational roles and responsibilities.
  • Planning: Risk assessment and risk treatment processes, information security objectives, and plans to achieve them.
  • Support: Resources, competence, awareness, communication, and documented information requirements.
  • Operation: Operational planning and control, risk assessment execution, and risk treatment implementation.
  • Performance Evaluation: Monitoring, measurement, analysis, evaluation, internal audit, and management review.
  • Improvement: Nonconformity handling, corrective action, and continual improvement.

ISO 27002: Code of Practice for Information Security Controls

ISO 27002 complements ISO 27001 by providing detailed guidance on implementing the security controls referenced in Annex A of ISO 27001. While ISO 27001 specifies what must be done, ISO 27002 provides practical guidance on how to implement each control. The 2022 revision reorganized controls into four themes: Organizational, People, Physical, and Technological, with a total of 93 controls down from 114 in the previous version.

When auditing against ISO 27001, the Statement of Applicability (SoA) is a critical document. It lists all Annex A controls, states whether each is applicable, provides justification for exclusions, and describes the implementation status. Auditors should review the SoA early in the engagement to understand the organization's control scope.

COBIT & CIS Controls

COBIT: Governance of Enterprise IT

COBIT (Control Objectives for Information and Related Technologies) is a framework developed by ISACA for IT governance and management. While broader than just cybersecurity, COBIT provides a comprehensive structure for aligning IT activities with business objectives. COBIT 2019, the latest version, introduces a governance system with 40 governance and management objectives organized into five domains: Evaluate, Direct and Monitor (EDM); Align, Plan and Organize (APO); Build, Acquire and Implement (BAI); Deliver, Service and Support (DSS); and Monitor, Evaluate and Assess (MEA).

COBIT is particularly valuable for auditors working in environments where IT governance is a primary concern, such as SOX compliance engagements. Its structured approach to linking business goals with IT processes makes it ideal for demonstrating that IT controls support financial reporting integrity.

CIS Controls: Prioritized Security Actions

The Center for Internet Security (CIS) Controls are a set of 18 prioritized cybersecurity best practices designed to mitigate the most common cyber attacks. Unlike broad frameworks, CIS Controls provide specific, actionable recommendations organized into three Implementation Groups (IGs) based on organizational size and resources. IG1 defines essential cyber hygiene for all organizations, IG2 adds controls for organizations managing more complex environments, and IG3 covers the full set for organizations with mature security programs.

  • Inventory and Control of Enterprise Assets: Actively manage all hardware devices so only authorized devices have access.
  • Inventory and Control of Software Assets: Actively manage all software so only authorized and supported software can execute.
  • Data Protection: Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.
  • Secure Configuration of Enterprise Assets and Software: Establish and maintain secure configurations for hardware, software, and network infrastructure.
  • Account Management: Use processes and tools to assign and manage authorization to credentials for user accounts.
  • Access Control Management: Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts.

CIS Controls are often used as a practical complement to broader frameworks. For example, an organization may adopt ISO 27001 as its overarching ISMS standard but use CIS Controls to guide the specific technical implementation of security measures.

Choosing the Right Framework

Factors in Framework Selection

Selecting the right cybersecurity framework is a strategic decision that depends on multiple factors unique to each organization. There is no universally correct choice. The best framework is one that aligns with the organization's regulatory environment, business objectives, risk tolerance, industry, and maturity level. As an auditor, you may be asked to recommend a framework or to evaluate the appropriateness of the framework an organization has already adopted.

  • Regulatory Requirements: Some frameworks map directly to specific regulatory obligations. For example, NIST CSF maps well to many US federal requirements, while ISO 27001 is preferred for international organizations seeking formal certification.
  • Industry Standards: Certain industries have established preferences. Financial services often use COBIT for IT governance, healthcare aligns with NIST due to HIPAA security rule mappings, and technology companies may prefer ISO 27001 for customer trust.
  • Organizational Maturity: Less mature organizations benefit from the prescriptive nature of CIS Controls, while mature organizations may prefer the flexibility of NIST CSF or the comprehensive governance structure of COBIT.
  • Certification Needs: If the organization needs formal certification for customer or partner requirements, ISO 27001 is the primary choice as it offers third-party certification. NIST CSF and CIS Controls do not have formal certification programs.
  • Resource Availability: Smaller organizations with limited security teams may find CIS Controls IG1 more practical than implementing the full scope of ISO 27001 or COBIT.
Organizations are not limited to a single framework. Many adopt a primary framework for overall governance and supplement it with specific controls from other frameworks. For example, using NIST CSF for strategic alignment, ISO 27001 for ISMS certification, and CIS Controls for tactical implementation guidance.
FrameworkBest ForCertifiable?Complexity
NIST CSFRisk-based strategy; US organizations; critical infrastructureNoModerate
ISO 27001International organizations; formal certification needsYesHigh
COBITIT governance; SOX compliance; large enterprisesNo (process-level assessments available)High
CIS ControlsPractical technical implementation; small-to-mid-size organizationsNoLow to Moderate

Chapter quiz

Audit Frameworks & Standards Quiz

7 questions · passing score 70%

Practice scenario

Framework Selection for a Fintech Startup

You are a cybersecurity consultant hired by PayStream, a fintech startup with 120 employees. PayStream operates a mobile payment platform that processes transactions for small businesses across the United States and Canada. They are preparing for Series B funding and their potential investors have asked about their security posture. PayStream currently has no formal cybersecurity framework in place but has implemented some basic security controls. The CTO, Maria Zhang, has asked you to recommend a framework and help them understand what implementation will involve.