Back to glossaryLaw & regulation

ISO 27001 / NIST CSF

Two leading cybersecurity frameworks: ISO 27001, a certifiable standard for information security management, and the NIST CSF, a non-certifying American framework for structuring a cyber posture.

Definition

ISO/IEC 27001 is the international reference standard for information security management systems (ISMS). Published by the International Organization for Standardization and revised in 2022, it defines the requirements an organization must meet to establish, implement, maintain and improve a structured set of policies, procedures and technical controls designed to protect the confidentiality, integrity and availability of information. The standard adopts a risk-based approach: the organization identifies its information assets, assesses associated threats and vulnerabilities, then selects controls from an annex of 93 measures organized into four themes (organizational, people, physical and technological). ISO 27001 certification, issued by an accredited third-party body after audit, is today a criterion used in cyber underwriting to assess the insured's maturity, and can justify a premium reduction or access to higher limits. The NIST Cybersecurity Framework (CSF), developed by the US National Institute of Standards and Technology and revised in version 2.0 in 2024, is a non-certifying but very widely adopted framework that organizes cybersecurity capabilities into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is particularly valued for structuring communication between management and technical teams, and serves as a reference in many underwriting questionnaires. The two frameworks are complementary: ISO 27001 structures management and enables certification, while the NIST CSF offers an operational vocabulary and a maturity assessment framework.

Example

A cyber underwriter asks a prospect whether it is ISO 27001 certified. The absence of certification does not disqualify the insured, but the underwriter will deepen the audit to verify existing controls, whereas a valid certification would give a presumption of maturity and could reduce the premium by 10 to 20 percent.

Related terms
Also known as

ISO/IEC 27001, NIST Cybersecurity Framework, SMSI, ISMS, ISO 27001, NIST CSF