Exam objective 4.1 asks you to identify and apply information security control frameworks and standards to manage risk. Before you can protect a company's digital assets, you need a structured, proven recipe for doing so; frameworks and standards are that recipe. Without them, securing an organisation is like trying to build a house with no blueprint and no building code—everyone would do it differently, most would do it badly, and nobody could prove it was safe.
Jump to a section
A simple way to picture Information Security Control Frameworks and Standards
A building inspector's rulebook and renovation blueprint is a perfect analogy for information security control frameworks and standards. This rulebook is a comprehensive guide that lists all the safety requirements a building must meet: fire exits must be a certain width, wiring must be a specific gauge, load-bearing walls cannot be moved. It doesn't tell the contractor how to mix concrete or which brand of nails to buy; it sets the goal. The blueprint, on the other hand, is the detailed plan for a specific house, showing where every outlet and stud will go, and it explicitly references the rulebook to show how the design complies.
Every builder in the town follows this rulebook. The bank will not lend money for a renovation unless the plans show compliance. The inspector visits during construction to check that the work matches the blueprint and meets the rulebook's minimum standards. If the builder deviates, the inspector issues a violation. This system works because everyone—architects, electricians, plumbers, and the bank—is working from the same agreed-upon rulebook. The rulebook represents the standard (like ISO 27001 or NIST), and the blueprint represents the control framework (how you apply the standard to your specific organisation). The inspector is the auditor, and the certificate of occupancy is the certification. Without the rulebook, one builder might think one fire exit is fine, while another insists on two; the rulebook removes the guesswork and ensures a consistent, safe outcome for everyone who uses the building.
Information security control frameworks and standards are the organised tools and benchmarks that organisations use to manage cyber risk systematically. Think of them as the 'instruction manuals' and 'rulebooks' for security. They exist to solve a fundamental problem: without a standardised approach, every company would invent its own way to secure data, making it impossible to compare security postures, meet regulatory requirements, or prove to customers that their information is safe.
First, let's define the key terms. An 'information security control' is a safeguard or countermeasure designed to protect the confidentiality, integrity, and availability of information. Confidentiality means keeping data secret from unauthorised people. Integrity means ensuring data hasn't been tampered with. Availability means that authorised users can access the data when they need it. These three goals are often called the 'CIA triad'.
A 'framework' is a structured set of guidelines, best practices, and controls. It tells you what security areas you need to think about (like access control, incident response, and physical security) and gives you a structure for organising your efforts. It is a toolbox, not a specific set of rules. The most common frameworks you need to know for CRISC are COBIT and the NIST Cybersecurity Framework (CSF).
A 'standard' is a more prescriptive set of requirements. Standards are often certifiable, meaning a third-party auditor can check if you meet the standard and issue a certificate. The most important standard for CRISC is ISO 27001, which specifies the requirements for an Information Security Management System (ISMS). An ISMS is a systematic approach to managing sensitive company information so that it remains secure. It includes people, processes, and IT systems.
Now, let's look at the three main frameworks and standards you will be tested on:
COBIT (Control Objectives for Information and Related Technologies): Developed by ISACA (the same organisation that runs the CRISC exam), COBIT is a framework for governing and managing enterprise IT. It links IT goals to business goals. For security, COBIT provides a set of control objectives and processes (like 'Manage Security' and 'Manage Risk'). It is comprehensive and designed for senior management and auditors. It does not tell you the exact technical controls to use; it tells you what processes you need and how to measure them.
NIST (National Institute of Standards and Technology) Cybersecurity Framework: This is a voluntary framework from the US government. It has three main parts: the Core, Implementation Tiers, and Profiles. The Core consists of five functions: Identify, Protect, Detect, Respond, and Recover. These are high-level categories. Each function has categories and subcategories of security outcomes. For example, under 'Protect', there is 'Access Control' and 'Data Security'. NIST CSF is very popular because it is flexible and uses business-friendly language. It doesn't prescribe specific technologies; it describes desired outcomes.
ISO 27001: This is a certifiable international standard. You either meet its requirements or you do not. It specifies a set of controls (listed in Annex A) that an organisation must implement. There are 93 controls grouped into 14 domains, such as 'Information Security Policies', 'Human Resource Security', and 'Communications Security'. To become ISO 27001 certified, a company must go through a formal audit by an accredited certification body.
Why do these exist? Before widespread frameworks, every company 'did its own thing', leading to huge variation in security quality. Regulators and customers demanded proof of security. Insurance companies wanted to know if a company was safe to insure. Frameworks and standards provided a common language and a benchmark. They replaced ad-hoc, reactive security practices with structured, proactive risk management.
For the CRISC exam, you must understand the differences between these three. COBIT is about governance and aligning IT with business strategy. NIST CSF is about improving cybersecurity posture through a risk-based approach. ISO 27001 is about establishing a management system and meeting a specific set of requirements for certification. A common mistake is confusing 'framework' with 'standard'. Remember: frameworks are flexible guides; standards are mandatory requirements (if you want certification). Another key point: you can use a framework (like NIST) to build your security programme, and then get certified against a standard (like ISO 27001) to prove your programme works.
Select a Framework or Standard
Identify the business need: are we aiming for certification (ISO 27001), improving cybersecurity (NIST CSF), or aligning IT with business strategy (COBIT)? This choice determines all subsequent steps. An audit or client requirement often drives this choice.
Perform a Gap Analysis
Compare your organisation's existing security controls against the chosen framework's requirements. List what you already have (e.g., a firewall) and what you are missing (e.g., a formal incident response plan). This creates a 'gap list' that becomes your project plan.
Develop and Implement Controls
For each gap, design and deploy a control. This could be a policy (e.g., password policy), a process (e.g., quarterly risk assessments), or a technology (e.g., encryption software). Document every control for audit evidence.
Conduct an Internal Audit
Before an external audit, perform an internal review to verify that all controls are in place and operating effectively. This is often done by someone independent of the implementation team. Fix any deficiencies found.
Undergo External Audit (for Standards)
If pursuing certification (e.g., ISO 27001), an accredited external auditor reviews your documentation, interviews staff, and tests controls. If you pass, you receive certification, which is valid for a fixed period (usually three years) with annual surveillance audits.
Maintain and Continuously Improve
Frameworks and standards are not 'set and forget'. You monitor controls, update them as threats change, and re-assess risk annually. For ISO 27001, you must show continuous improvement through management reviews and corrective actions.
Imagine you are the new information security manager at a mid-sized logistics company called 'ShipFast Ltd.' ShipFast stores customer addresses, payment details, and shipment logs. Currently, there is no formal security programme. The CEO says they want to 'get serious about security' because a major client is demanding proof of 'good security practices' before signing a contract. What do you do?
Your first step is to choose a framework to guide your work. You do not invent your own security controls; you adopt an existing, proven framework. You choose the NIST Cybersecurity Framework because you know the client is a US-based firm that understands it, and it is flexible enough for a medium-sized company. You present the five NIST functions to the CEO as your roadmap: Identify, Protect, Detect, Respond, Recover.
Here is the step-by-step process:
You start by 'Identify' (Identify what is important). You create an asset inventory: what data do we have, where is it stored, who has access? You identify risks, like the risk of a data breach from a phishing email. You document the current security controls (firewalls, password policies) and find gaps.
Next, 'Protect' (implement safeguards). Based on the gaps from the Identify phase, you implement controls. You use the NIST CSF subcategories as your checklist. For example, under 'Access Control' (PR.AC), you ensure that only the sales team can access the customer database. You implement multi-factor authentication (MFA) for system administrators. You train all staff on phishing awareness. These are controls.
Then, 'Detect' (find security incidents quickly). You deploy antivirus and intrusion detection systems. You set up a log monitoring process. You create a baseline of 'normal' network traffic so you can spot anomalies.
After that, 'Respond' (have a plan for when things go wrong). You write an incident response plan that specifies who calls whom, when to shut down a server, and how to preserve evidence. You test the plan with a tabletop exercise.
Finally, 'Recover' (get back to normal after an incident). You create backup procedures and practice restoring data from backups. You document lessons learned to improve next time.
After completing this, the CEO asks for a certificate to show the client. NIST CSF is not certifiable (it is a framework, not a standard). So, you decide to pursue ISO 27001 certification. You now map your NIST-based controls to the ISO 27001 Annex A controls. This is a very common real-world combination: use NIST to build the programme, then use ISO 27001 to certify it. A gap analysis shows you are missing a formal 'Information Security Policy' document and a 'Supplier Security' process. You create these and then undergo an external audit. After passing the audit, ShipFast becomes ISO 27001 certified. The client is satisfied, and the contract is signed.
What does an IT professional do with all of this? They:
Select a framework (often NIST or COBIT) based on their organisation's size, industry, and regulatory requirements.
Perform a 'gap analysis' comparing current controls against the framework's recommendations.
Develop a project plan to implement missing controls.
If certification is desired, they map controls to a standard (like ISO 27001).
They prepare for audits by gathering evidence that controls are operating effectively.
They continuously monitor and update the framework as the business and threat landscape change.
The key takeaway is that frameworks and standards are not just theory; they are the daily tools used to build, measure, and prove security.
CRISC tests your ability to identify, apply, and differentiate between information security control frameworks and standards. This is a high-value area because it forms the basis for the entire 'Response and Recovery' domain (Domain 4). Expect approximately 5-10 questions on this topic.
The exam loves to test the following specific concepts:
The difference between a framework and a standard: This is the most common trap. A question will describe a flexible guideline that helps you organise your security programme and ask 'what is this?'. Answer: framework (NIST CSF). Another question will describe a set of mandatory requirements that result in a certificate after an audit. Answer: standard (ISO 27001). Be careful: COBIT is a framework, not a standard (it is not certifiable in the same way ISO 27001 is).
The purpose of each framework/standard: You must know that COBIT is about governance and control objectives for IT as a whole, not just security. NIST CSF is specifically for improving cybersecurity posture. ISO 27001 is for establishing an ISMS and achieving certification.
The structure of NIST CSF (the five functions: Identify, Protect, Detect, Respond, Recover). The exam may ask you to place a given control into the correct function. For example, 'training employees' belongs to 'Protect'. 'Creating a risk register' belongs to 'Identify'.
The concept of 'mapping' between frameworks: CRISC often tests that you can use one framework to meet another standard's requirements. For instance, you can use NIST CSF controls to satisfy ISO 27001 requirements.
Control objectives vs. controls: COBIT provides 'control objectives' (what you should achieve), while ISO 27001 provides specific controls (how to achieve it). The exam will test that you understand this distinction.
Common trap patterns:
Trap: They describe a process that is part of a different framework (e.g., they describe COBIT's 'EDM' (Evaluate, Direct, Monitor) process but ask you to identify it as part of NIST. Don't fall for it.
Trap: They ask which framework is 'most suitable' for a given scenario. Remember: NIST CSF is for cybersecurity risk, COBIT is for IT governance, ISO 27001 is for certification.
Trap: They use the term 'standard' loosely. Always remember that ISO 27001 is a standard, but NIST CSF and COBIT are frameworks.
Trap: They ask about the 'Implementing' tier in COBIT. COBIT does not have implementation tiers; that is a NIST CSF concept.
Key definitions to memorise:
ISMS (Information Security Management System): A systematic approach to managing sensitive information.
Annex A: The list of controls in ISO 27001 (93 controls, 14 domains).
COBIT's five domains: Evaluate, Direct, Monitor, Align, Plan, Organise (EDM, APO, BAI, DSS, MEA).
NIST CSF's five functions: ID, PR, DE, RS, RC.
The exam will test your ability to 'apply' the framework, not just recite it. For example, a scenario question might describe a company that has just suffered a ransomware attack. The question will ask: 'Which NIST CSF function should the organisation focus on to ensure it can restore operations?' The answer is 'Recover'.
Finally, do not memorise every single control in ISO Annex A. Instead, understand the categories and know that a full list exists in the document. The exam will ask about the purpose of Annex A, not its exact contents.
Frameworks (like NIST CSF and COBIT) are flexible guides for organising security efforts; standards (like ISO 27001) are prescriptive, certifiable requirements.
The NIST Cybersecurity Framework's five core functions are Identify, Protect, Detect, Respond, and Recover.
ISO 27001 certification requires an external audit to verify compliance with its 93 controls in Annex A.
COBIT links IT goals to business goals and is designed for enterprise governance, not just security.
Organisations often use a combination of frameworks and standards, such as building a programme with NIST CSF and then certifying it against ISO 27001.
An Information Security Management System (ISMS) is the systematic approach required by ISO 27001 to manage sensitive information.
Mapping controls from one framework to another (e.g., NIST to ISO) is a common real-world activity to demonstrate compliance without duplication of effort.
These come up on the exam all the time. Here's how to tell them apart.
NIST CSF
Voluntary framework, not certifiable
Focuses on cybersecurity outcomes (Identify, Protect, Detect, Respond, Recover)
Flexible, uses business-friendly language
ISO 27001
Certifiable international standard
Focuses on an ISMS and specific control requirements (Annex A)
Prescriptive, requires formal documentation and external audit
COBIT
Broad IT governance framework covering strategy, finance, and operations
Designed for senior management and auditors
Uses process areas like EDM, APO, BAI, DSS, MEA
NIST CSF
Specifically for cybersecurity risk management
Designed for operational security teams
Uses five core functions: ID, PR, DE, RS, RC
Framework
Flexible guideline or structure
Not certifiable (cannot get 'framework certificate')
Examples: NIST CSF, COBIT
Standard
Mandatory set of requirements
Certifiable through external audit
Examples: ISO 27001, PCI DSS
Mistake
ISO 27001 and NIST CSF are the same thing; you only need one.
Correct
They serve different purposes. NIST CSF is a flexible framework for improving cybersecurity posture. ISO 27001 is a certifiable standard. Organisations often use both: NIST to build the programme and ISO 27001 to certify it.
Both documents list controls and are called 'standards' in casual conversation, leading beginners to think they are interchangeable.
Mistake
A framework tells you exactly which software or firewall to buy.
Correct
Frameworks describe outcomes and processes (e.g., 'implement access control'), not specific technologies. You choose the technology that achieves the outcome.
Beginners hear 'security controls' and think of specific tools like antivirus, so they assume the framework will pick the tool for them.
Mistake
If you follow NIST CSF, you are automatically compliant with ISO 27001.
Correct
NIST CSF is not ISO 27001. While there is significant overlap, ISO 27001 has additional requirements (like a formal risk assessment methodology, an ISMS, and specific documentation). You must intentionally map and address gaps.
Because many controls look similar on the surface, beginners assume compliance with one means compliance with the other.
Mistake
COBIT is just another security framework like NIST.
Correct
COBIT is a broader IT governance framework that covers all of IT (including financial systems, operations, and strategy), not just security. Security is just one part of COBIT's scope.
Because COBIT includes security controls, people assume it is a 'security-only' framework.
Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.
NIST CSF is a voluntary, flexible framework for improving cybersecurity. ISO 27001 is a certifiable standard that requires an external audit. NIST tells you 'what to think about'; ISO tells you 'exactly what to do'. Many companies use NIST to build their programme and ISO to prove it.
No. You need to know that there are 93 controls grouped into 14 domains, and that Annex A is the list. The exam tests your understanding of the purpose and structure, not the specific details of every control.
Yes, but they have different purposes. COBIT is for overall IT governance, while NIST is specifically for cybersecurity. Many large organisations use both: COBIT for top-level IT governance and NIST for operational security.
No, COBIT is a framework, not a standard. You cannot get 'COBIT certified' for your organisation. However, individuals can get COBIT-based certifications like COBIT 2019 Foundation.
It means taking a control from one framework (e.g., 'access control' from NIST) and showing which requirement it satisfies in another standard (e.g., ISO 27001 A.9.1.1). This avoids duplicating effort when an organisation uses multiple frameworks.
NIST CSF is often the best starting point because it is flexible and scalable. You can implement only the controls that are relevant to your size and risk. ISO 27001 can be expensive and heavy for a small business unless a client or regulation demands it.
You've finished Information Security Control Frameworks and Standards. Continue through the CRISC study guide to build a complete picture of the exam.
Done with this chapter?