23.3 Foundational Industry GRC Frameworks
ISO/IEC 27001: A Certified Management System
ISO 27001 specifies an Information Security Management System, a repeatable machine for running security rather than a checklist of products. Its mandatory clauses follow a Plan-Do-Check-Act rhythm: understanding the organization and its interested parties, leadership commitment and policy, planning that covers risk assessment, risk treatment, and the Statement of Applicability listing every control selected or excluded with justification, then support (resources, competence, awareness), operation, performance evaluation through internal audit, metrics, and management review, and finally nonconformity handling with corrective action and continual improvement. Controls themselves live in the annex control set, elaborated by ISO 27002 guidance. Certification audits the management system, so a company with weak risk analysis fails even with strong tooling.
NIST CSF 2.0: Six Functions, Two Profiles
The Cybersecurity Framework organizes outcomes under Govern, Identify, Protect, Detect, Respond, and Recover. Govern, added in version 2.0, elevates policy, roles, risk appetite, and supply-chain oversight to a first-class function instead of an afterthought. Organizations describe a current profile and a target profile, and the delta between them becomes the roadmap, which is why CSF is popular with teams that want outcome language rather than clause numbering.
SOC 2 and GDPR: Proof and Law
SOC 2 is an attestation for service organizations against the Trust Services Criteria categories: Security, the common criteria required in every report, plus optional Availability, Processing Integrity, Confidentiality, and Privacy. A Type I report evaluates design at a point in time; a Type II evaluates operating effectiveness across a window, typically six to twelve months, with sampled evidence. GDPR is law, not a voluntary framework. It requires a lawful basis, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, plus accountability for all of it, and grants data subjects rights of access, rectification, erasure, restriction, portability, and objection, with breach notification duties on tight clocks.
Converging on One Control Library
Serious teams stop mapping framework by framework. They maintain one internal library of controls, each with an owner, a test, and an evidence source, then cross-reference it to every framework, so an access review satisfies ISO annex controls, CSF Protect outcomes, SOC 2 common criteria, and accountability evidence for privacy obligations in a single operating routine.
Architecture Diagram
Key Takeaways
- ISO 27001 certifies a Plan-Do-Check-Act management system; the Statement of Applicability justifies every control choice.
- NIST CSF 2.0 adds Govern to Identify, Protect, Detect, Respond, and Recover, and drives roadmaps from current versus target profiles.
- SOC 2 requires Security common criteria and may add Availability, Processing Integrity, Confidentiality, or Privacy; Type II covers a period.
- GDPR mandates lawful basis, purpose limitation, minimization, and accountability, plus data-subject rights and breach clocks.
- Map once into a single control library so one operating routine satisfies every framework at once.