This table shows the 28 compliance areas where ISO 27001 and NIST CSF controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaISO 27001NIST CSF
EncryptionA.8.24PR.DS-01, PR.DS-02
Key ManagementA.8.24PR.DS-01
Access ControlA.5.15PR.AA-01
Identity ManagementA.5.16PR.AA-01, PR.AA-03
Authentication & MFAA.5.17, A.8.5PR.AA-03
Access Rights ReviewA.5.18PR.AA-05
Privileged Access ManagementA.8.2PR.AA-05
Network SecurityA.8.20, A.8.21, A.8.22PR.IR-01
Vulnerability ManagementA.8.8ID.RA-01, PR.PS-01
Logging & MonitoringA.8.15, A.8.16DE.CM-01, DE.AE-02
Incident ManagementA.5.24, A.5.25, A.5.26RS.MA-01, RS.AN-03
Post-Incident ReviewA.5.27RS.AN-08
Business ContinuityA.5.29, A.5.30RC.RP-01, RC.RP-03
Backup & RestorationA.8.13RC.RP-03
Third-Party Risk ManagementA.5.19, A.5.20GV.SC-03
Supplier Due DiligenceA.5.21GV.SC-06
Supplier ContractsA.5.20GV.SC-05
Supplier MonitoringA.5.22GV.SC-09
Risk AssessmentA.5.7ID.RA-03, ID.RA-05
Information Security PolicyA.5.1GV.PO-01
Security Awareness & TrainingA.6.3PR.AT-01
Data ClassificationA.5.12, A.8.10, A.8.12PR.DS-10
Change ManagementA.8.32PR.PS-01
Secure DevelopmentA.8.25, A.8.28PR.PS-06
Security TestingA.5.35ID.IM-02
Record KeepingA.8.15DE.CM-01
Configuration ManagementA.8.9PR.PS-01
Malware ProtectionA.8.7DE.CM-09
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.