Topic 23 · Deep Dive

23.3 Foundational Industry GRC Frameworks

ISO/IEC 27001: A Certified Management System

ISO 27001 specifies an Information Security Management System, a repeatable machine for running security rather than a checklist of products. Its mandatory clauses follow a Plan-Do-Check-Act rhythm: understanding the organization and its interested parties, leadership commitment and policy, planning that covers risk assessment, risk treatment, and the Statement of Applicability listing every control selected or excluded with justification, then support (resources, competence, awareness), operation, performance evaluation through internal audit, metrics, and management review, and finally nonconformity handling with corrective action and continual improvement. Controls themselves live in the annex control set, elaborated by ISO 27002 guidance. Certification audits the management system, so a company with weak risk analysis fails even with strong tooling.

NIST CSF 2.0: Six Functions, Two Profiles

The Cybersecurity Framework organizes outcomes under Govern, Identify, Protect, Detect, Respond, and Recover. Govern, added in version 2.0, elevates policy, roles, risk appetite, and supply-chain oversight to a first-class function instead of an afterthought. Organizations describe a current profile and a target profile, and the delta between them becomes the roadmap, which is why CSF is popular with teams that want outcome language rather than clause numbering.

SOC 2 and GDPR: Proof and Law

SOC 2 is an attestation for service organizations against the Trust Services Criteria categories: Security, the common criteria required in every report, plus optional Availability, Processing Integrity, Confidentiality, and Privacy. A Type I report evaluates design at a point in time; a Type II evaluates operating effectiveness across a window, typically six to twelve months, with sampled evidence. GDPR is law, not a voluntary framework. It requires a lawful basis, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, plus accountability for all of it, and grants data subjects rights of access, rectification, erasure, restriction, portability, and objection, with breach notification duties on tight clocks.

Converging on One Control Library

Serious teams stop mapping framework by framework. They maintain one internal library of controls, each with an owner, a test, and an evidence source, then cross-reference it to every framework, so an access review satisfies ISO annex controls, CSF Protect outcomes, SOC 2 common criteria, and accountability evidence for privacy obligations in a single operating routine.

Architecture Diagram

frameworks converge on one control library Govern Identify Protect Detect Respond Recover ISO 27001 ISMS clauses, PDCA SOC 2 5 TSC categories GDPR principles, rights Control library one control, mapped to many Gap analysis current vs target
Learn one control library and cross-reference it: CSF functions, ISO clauses, SOC 2 criteria, and GDPR duties share the same evidence.

Key Takeaways

« Back to Topic 23« 23.2 / 23.4 »