Cybersecurity work draws on several kinds of references: voluntary guidance, management-system standards, laws and regulations, sector requirements and contractual obligations. Their purposes differ, so identify the nature, edition and applicability of each before using it as an assessment baseline.
Organisation-wide direction
The NIST Cybersecurity Framework organises cybersecurity outcomes, while ISO/IEC 27001 specifies requirements for an information security management system. They can support related programmes without being interchangeable. NIST CSF, ISO/IEC 27001.
Use an organisation-wide reference to connect security objectives, responsibilities and reviews. Decide how it relates to the obligations and risks of your actual business scope.
Legal, regulatory and contractual obligations
Record legal obligations separately from voluntary guidance. GDPR is an EU regulation, and HIPAA includes US requirements applying to covered entities and business associates; the Security Rule concerns electronic protected health information. Applicability depends on the activities, entities and jurisdiction involved. GDPR text, HHS Security Rule.
For US federal information systems, the Federal Information Security Modernization Act of 2014 (FISMA) and the associated NIST implementation guidance provide another distinct legal and operational context. Establish whether that context applies before adopting its requirements as your baseline. NIST FISMA background.
PCI DSS addresses payment account data security within its defined scope. Requirements may arise through the payment ecosystem and contractual arrangements. Determine the relevant obligations and assessment scope rather than treating every security reference as a law. PCI Security Standards Council.
Topic-specific guidance
Select additional references for the systems and risks being examined. Operational technology, cloud services, software supply chains and incident response each need context-specific analysis.
For operational technology, the ISA/IEC 62443 series addresses the cybersecurity of industrial automation and control systems throughout their lifecycle. For cloud services, the Cloud Security Alliance Cloud Controls Matrix (CCM) supports the assessment of cloud security controls and allocation of responsibilities between providers and customers. These are concrete starting points for the OT and cloud examples; neither replaces an assessment of your actual architecture and responsibilities. ISA/IEC 62443, CSA Cloud Controls Matrix.
For supply-chain work, NIST SP 800-161 Rev. 1, Update 1 addresses cybersecurity risks across suppliers, products and services. For incident response, NIST SP 800-61 Rev. 3, published in April 2025, integrates response considerations with CSF 2.0. Supply-chain guidance, Incident-response guidance.
Apply the reference in CSFaaS
Check the edition actually available in the framework library and the version selected in the workspace. Record applicability, connect requirements to policies and controls, and retain supporting evidence. If the desired publication is unavailable, document that gap instead of assuming another entry is equivalent.
Framework mappings can help organize review, but they do not establish compliance automatically. Keep the source obligation, implemented control, assessment scope and evidence distinguishable so the result can be reviewed on its merits.