Skip to main content

Command Palette

Search for a command to run...

CISSP Frameworks & Standards — The Ultimate Exam Cheat Sheet

Updated
28 min readView as Markdown
S
I like breaking things that are supposed to be secure. When I’m not hunting vulnerabilities, I’m exploring systems, architectures, and the assumptions behind them.

What You Really Need to Know for the CISSP Exam

If you're preparing for the CISSP exam, frameworks and standards can become one of the most confusing parts of your study plan.

You encounter names such as:

  • ISO/IEC 27001

  • ISO/IEC 27002

  • ISO/IEC 27034

  • ISO/IEC 27701

  • ISO 31000

  • NIST Cybersecurity Framework

  • NIST SP 800-53

  • NIST Risk Management Framework

  • COBIT

  • SABSA

  • PCI DSS

  • FedRAMP

  • SOC 1

  • SOC 2

  • CIS Controls

  • MITRE ATT&CK

  • OWASP ASVS

  • GDPR

  • HIPAA

  • SOX

  • and many others.

At some point, every CISSP candidate asks:

"Do I really need to memorize all of these?"

The answer is no.

The CISSP exam is not asking you to become an auditor, compliance specialist, or implementation expert for every framework.

The real skill is understanding:

What is this framework? Why does it exist? What problem does it solve? Where does it fit into security governance and risk management? And when would an organization use it?

The current ISC2 CISSP exam outline places Security Control Frameworks under Domain 1 — Security and Risk Management and explicitly gives examples including ISO, NIST, COBIT, SABSA, PCI and FedRAMP. Domain 1 also covers governance, legal and regulatory issues, risk management, control assessment, business continuity and continuous improvement.

This article is therefore not an encyclopedia.

It is a CISSP-focused study guide and revision cheat sheet.

CISSP Instructor Rule: Don't memorize the library. Understand the map.


1. First Understand What Kind of Thing You're Looking At

One reason frameworks become confusing is that candidates often treat all of them as the same thing.

They aren't.

                         SECURITY & RISK
                              |
          +-------------------+-------------------+
          |                   |                   |
      GOVERNANCE             RISK              CONTROLS
          |                   |                   |
        COBIT             ISO 31000           NIST 800-53
        SABSA             ISO 27001           ISO 27002
                              |
          +-------------------+-------------------+
          |                   |                   |
       PRIVACY              CLOUD              APPSEC
          |                   |                   |
       ISO 27701           FedRAMP             ISO 27034
       GDPR               NIST 800-145         OWASP ASVS
       HIPAA

Think about the distinction:

Type What it does Example
Framework Provides a structured approach to a problem NIST CSF
Standard Provides defined requirements or guidance ISO 27001
Control catalog Provides security/privacy controls NIST 800-53
Risk-management guidance Provides principles/processes for managing risk ISO 31000
Governance framework Helps direct and oversee IT/business alignment COBIT
Security architecture framework Connects business requirements to security architecture SABSA
Regulation Creates legal requirements GDPR
Industry standard Defines sector-specific security requirements PCI DSS
Authorization program Standardizes assessment/authorization for a specific environment FedRAMP
Maturity model Measures/improves organizational capability SAMM
Assurance report Provides independent reporting on controls SOC 1 / SOC 2

This classification is much more useful than memorizing names in isolation.


2. How Deeply Should You Study Each One?

Use three study levels.

Priority Meaning
🔴 HIGH Understand well; know relationships and scenario application
🟠 MEDIUM Know purpose, terminology and major concepts
🟡 LOW Recognition-level knowledge; don't spend hours memorizing details

One important distinction:

"Important to understand" does not mean "explicitly listed by name in the exam outline."

For example, the current ISC2 outline explicitly names the ISO family broadly, but it does not separately enumerate every ISO publication such as 27034, 27701 or 31000. Those standards are still valuable because they help you understand the broader ISO ecosystem and can reinforce CISSP concepts.


3. 🔴 High-Priority CISSP Frameworks & Standards

Framework / Standard Full Name Type CISSP Memory Hook What You Should Know
ISO/IEC 27001 Information Security Management Systems — Requirements ISMS Standard ISMS Risk-based security management, ISMS, risk assessment/treatment, controls, continual improvement
ISO/IEC 27002 Information Security Controls Control Guidance Controls Guidance for implementing security controls; relationship to 27001
NIST CSF 2.0 NIST Cybersecurity Framework Cybersecurity Framework Cybersecurity Risk Govern, Identify, Protect, Detect, Respond, Recover; Profiles and Tiers
NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations Control Catalog Controls Control families, baselines, tailoring, security/privacy controls
NIST SP 800-37 RMF Risk Management Framework for Information Systems and Organizations Risk Framework RMF Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor
COBIT Control Objectives for Information and Related Technologies IT Governance Framework IT Governance Governance vs management, business alignment, accountability
PCI DSS Payment Card Industry Data Security Standard Industry Security Standard Payment Cards Cardholder data, CDE, security requirements, compliance
FedRAMP Federal Risk and Authorization Management Program Federal Cloud Authorization Program Federal Cloud Standardized assessment/authorization of cloud services for US federal agencies
SABSA Sherwood Applied Business Security Architecture Security Architecture Framework Business-Aligned Security Business-driven, risk-oriented, top-down security architecture
SOC 1 Service Organization Control 1 Assurance Report Financial Reporting Controls relevant to financial reporting
SOC 2 Service Organization Control 2 Assurance Report Trust Services Security, Availability, Processing Integrity, Confidentiality, Privacy

These are the concepts I would make very comfortable before moving on to obscure standards.


4. The ISO Family — Your Essential CISSP Mental Map

The ISO family becomes much easier when you stop thinking of every number as a separate subject.

                         ISO FAMILY
                             |
       +---------------------+---------------------+
       |                     |                     |
       ▼                     ▼                     ▼
   ISO 27001             ISO 27002             ISO 27034
      ISMS                Controls             AppSec
       |
       +---------------------+
       |                     |
       ▼                     ▼
   ISO 27701             ISO 31000
    Privacy                  Risk
   Management             Management

Memorize these five associations:

ISO 27001 → Information Security Management

ISO 27002 → Security Controls

ISO 27034 → Application Security

ISO 27701 → Privacy Management

ISO 31000 → Risk Management

That single map eliminates a huge amount of confusion.


5. ISO/IEC 27001 — Information Security Management

Think:

ISMS

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System.

For CISSP, know:

  • Information Security Management System (ISMS)

  • Risk assessment

  • Risk treatment

  • Security objectives

  • Security controls

  • Management responsibility

  • Continual improvement

  • Certification concept

A simple mental model:

                    ISO 27001
                        |
                        ▼
                       ISMS
                        |
          +-------------+-------------+
          |             |             |
          ▼             ▼             ▼
        Risk         Controls     Improvement
     Assessment
          |
          ▼
     Risk Treatment

CISSP scenario

An organization wants a formal information-security management system based on risk and wants the ability to pursue certification.

Think:

ISO 27001


6. ISO/IEC 27002 — Security Controls

Think:

Control Guidance

The easiest exam distinction:

27001 = ISMS

27002 = Security-control guidance

ISO/IEC 27002 supports organizations in implementing information-security controls.

For CISSP, understand:

  • Security controls

  • Control guidance

  • Control implementation

  • Relationship to ISO 27001

Don't memorize every control.


7. ISO/IEC 27034 — Application Security

This standard deserves attention from anyone working in application security.

ISO/IEC 27034 provides guidance for integrating security into processes used to manage applications.

Think:

ISO 27001
    |
    ▼
Information Security Management
    |
    ▼
ISO 27034
    |
    ▼
Application Security
    |
    +---- Development
    +---- Acquisition
    +---- Deployment
    +---- Operation

CISSP memory hook

27034 = Application Security

Know the concept of integrating security into application management and the application lifecycle.

Don't spend time memorizing every document in the ISO 27034 series.


8. ISO/IEC 27701 — Privacy Management

This is an important update to understand correctly.

The current published edition is ISO/IEC 27701:2025, which specifies requirements for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). It applies to organizations acting as PII controllers and processors.

Think:

                 ISO 27001
                     |
              Information Security
                     |
                     ▼
                 ISO 27701
                     |
                     ▼
              Privacy Management
                     |
                     ▼
                    PIMS

Know:

  • Privacy Information Management System (PIMS)

  • Personally Identifiable Information (PII)

  • Controllers

  • Processors

  • Privacy risk

  • Accountability

  • Privacy controls

  • Relationship between security and privacy management

CISSP memory hook

27001 = Information Security Management

27701 = Privacy Information Management

Do not describe 27701 simply as "GDPR certification."

It is a privacy management-system standard, not a substitute for privacy law.


9. ISO 31000 — Risk Management

Think:

General Risk Management

ISO 31000 provides principles and guidelines for managing risk.

Conceptually:

Establish Context
       ↓
Identify Risk
       ↓
Analyze Risk
       ↓
Evaluate Risk
       ↓
Treat Risk
       ↓
Monitor & Communicate

Know:

  • Risk identification

  • Risk analysis

  • Risk evaluation

  • Risk treatment

  • Monitoring

  • Communication

  • Risk-based decision-making

Very important distinction

ISO 31000 = General risk management

ISO 27001 = Information-security management system

Don't confuse the two.


10. NIST — The Family You Absolutely Need to Organize

NIST contains a large ecosystem of publications.

For CISSP, build this mental map:

                          NIST
                            |
         +------------------+------------------+
         |                  |                  |
        CSF                RMF              800-53
         |                  |                  |
   Cybersecurity          Risk              Controls
      Risk             Management           Catalog
   Framework             Process               |
                            |                  |
                            |                  ▼
                            |               800-53A
                            |              Assessment

Then memorize:

NIST Publication Think
NIST CSF 2.0 Cybersecurity risk
SP 800-37 Risk Management Framework
SP 800-53 Security/privacy controls
SP 800-53A Control assessment
SP 800-61 Incident response
SP 800-115 Security testing
SP 800-145 Cloud computing
SP 800-171 Controlled Unclassified Information
SP 800-207 Zero Trust

11. NIST Cybersecurity Framework 2.0

⚠️ Important CISSP Update: There Are Now SIX Functions

If you learned the older version, you may remember:

Identify → Protect → Detect → Respond → Recover

That is the CSF 1.1 model.

NIST CSF 2.0 added a sixth function:

Govern

The current CSF 2.0 Functions are:

             GOVERN
                |
        +-------+-------+
        |       |       |
        ▼       ▼       ▼
     IDENTIFY PROTECT DETECT
        |       |       |
        +-------+-------+
                |
             RESPOND
                |
             RECOVER

More accurately, the six functions are concurrent and continuous, not a strict sequential workflow. NIST explicitly describes CSF 2.0 as having six Functions: Govern, Identify, Protect, Detect, Respond and Recover.

What each Function means

Function Think
Govern Establish cybersecurity strategy, policy, risk tolerance, roles and oversight
Identify Understand assets, suppliers and cybersecurity risks
Protect Implement safeguards
Detect Find and analyze possible attacks/events
Respond Take action against cybersecurity incidents
Recover Restore affected assets and operations

CISSP memory hook

CSF 2.0 = GOVERN + IDENTIFY + PROTECT + DETECT + RESPOND + RECOVER

This is one correction I would consider mandatory before publishing because an article published today should not present the five-function CSF 1.1 model as the current NIST CSF.

NIST CSF 2.0 also includes Organizational Profiles and Tiers, which are useful concepts to recognize, although you do not need to memorize their detailed structure for CISSP.


12. NIST SP 800-53 — Security and Privacy Controls

Think:

800-53 = Controls

NIST SP 800-53 is a detailed catalog of security and privacy controls.

Know:

  • Control families

  • Security controls

  • Privacy controls

  • Control baselines

  • Tailoring

  • Control selection

  • Control implementation

  • Control assessment

The relationship:

NIST CSF
    |
    | "How do we manage cybersecurity risk?"
    ▼
NIST 800-53
    |
    | "What security/privacy controls can we use?"
    ▼
Controls

CISSP exam trap

Don't confuse:

NIST CSF → cybersecurity risk framework

with:

NIST SP 800-53 → security/privacy control catalog

That distinction is extremely important.


13. NIST Risk Management Framework — SP 800-37

The classic RMF sequence is:

PREPARE
   ↓
CATEGORIZE
   ↓
SELECT
   ↓
IMPLEMENT
   ↓
ASSESS
   ↓
AUTHORIZE
   ↓
MONITOR

What does each step mean?

Step CISSP Meaning
Prepare Establish organizational/system context and risk considerations
Categorize Determine potential impact
Select Select appropriate controls
Implement Implement controls
Assess Assess controls
Authorize Make a risk-based authorization decision
Monitor Continuously monitor controls and risk

NIST describes the RMF as a disciplined, structured and flexible process incorporating security and privacy risk, control selection/implementation/assessment, authorization and continuous monitoring.

⭐ Critical CISSP concept

Authorization is a risk decision.

The security team provides analysis and evidence.

The authorizing official / appropriate authority makes the risk-based decision.


14. NIST SP 800-53A — Control Assessment

Simple:

800-53 = Controls

800-53A = Assessment

For CISSP, remember the classic assessment methods:

Examine → Interview → Test

The distinction is:

800-53
   ↓
Controls
   ↓
800-53A
   ↓
Assessment
   ↓
Are the controls implemented
correctly and effectively?

15. NIST SP 800-61 — Incident Response

Think:

Incident Response

A common conceptual lifecycle is:

Preparation
     ↓
Detection & Analysis
     ↓
Containment
     ↓
Eradication
     ↓
Recovery
     ↓
Lessons Learned

For CISSP, concentrate on:

  • Preparation

  • Detection

  • Analysis

  • Containment

  • Eradication

  • Recovery

  • Lessons learned

The important exam skill is knowing what should happen next in a scenario.


16. NIST SP 800-145 — Cloud Computing

Think:

Cloud Definition

Five characteristics

  • On-demand self-service

  • Broad network access

  • Resource pooling

  • Rapid elasticity

  • Measured service

Service models

SaaS
PaaS
IaaS

Deployment models

Public
Private
Community
Hybrid

For CISSP, connect cloud models to:

  • Shared responsibility

  • Data ownership

  • Security boundaries

  • Control responsibility

  • Risk


17. NIST SP 800-171 — Controlled Unclassified Information

Think:

CUI

It addresses protection of Controlled Unclassified Information in nonfederal systems and organizations.

For CISSP, recognize:

CUI + nonfederal environment + security requirements

Don't memorize all requirement details.


18. NIST SP 800-207 — Zero Trust

The simplest definition:

Never trust, always verify.

Traditional thinking:

Internet
   ↓
Firewall
   ↓
Trusted Network
   ↓
Users / Systems

Zero Trust:

User / Device
      ↓
Verify
      ↓
Policy Decision
      ↓
Least Privilege
      ↓
Resource
      ↓
Continuous Monitoring

Know:

  • No implicit trust

  • Continuous verification

  • Least privilege

  • Identity-centric security

  • Device/context evaluation

  • Policy enforcement

  • Continuous monitoring

NIST 800-207 is particularly valuable because Zero Trust also appears directly in the current CISSP architecture domain.


19. COBIT — IT Governance

Think:

COBIT = Governance

COBIT focuses on governing and managing enterprise IT in alignment with organizational objectives.

Business Objectives
        ↓
IT Governance
        ↓
COBIT
        ↓
IT Objectives
        ↓
Business Value

⭐ Governance vs Management

This distinction matters more than memorizing COBIT process names.

Governance:

Evaluate → Direct → Monitor

Management:

Plan → Build → Run → Monitor

CISSP scenario

If the question emphasizes:

business strategy + IT alignment + accountability + oversight

Think:

COBIT


20. SABSA — Business-Driven Security Architecture

SABSA stands for:

Sherwood Applied Business Security Architecture

Think:

Business strategy drives security architecture.

Business Strategy
       ↓
Business Requirements
       ↓
Security Requirements
       ↓
Security Architecture
       ↓
Security Services
       ↓
Security Controls

Know:

  • Business-driven architecture

  • Top-down design

  • Risk orientation

  • Business requirements

  • Security requirements

  • Security services

Memory hook

SABSA = Business-Aligned Security Architecture


21. PCI DSS — Payment Card Security

Think:

Payment Cards

Payment Card Data
       ↓
Cardholder Data Environment
       ↓
PCI DSS Requirements
       ↓
Security Controls
       ↓
Assessment / Compliance

Know:

  • Cardholder data

  • Cardholder Data Environment (CDE)

  • Security requirements

  • Compliance

  • Protection of payment information

You don't need to memorize every PCI DSS requirement for CISSP.


22. FedRAMP — Federal Cloud Security Authorization

FedRAMP stands for:

Federal Risk and Authorization Management Program

Think:

Federal Government + Cloud + Assessment + Authorization

Cloud Service Provider
          ↓
       FedRAMP
          ↓
 Security Assessment
          ↓
Security Requirements / Controls
          ↓
      Authorization
          ↓
 Federal Cloud Use

Important wording

Avoid saying:

"FedRAMP is simply a certification."

A better CISSP description is:

FedRAMP is a standardized US federal program for security assessment, authorization and ongoing oversight of cloud services.

Memory hook

FedRAMP = Federal Cloud Authorization


23. SOC 1 vs SOC 2

This is a high-value distinction.

SOC 1 SOC 2
Primary focus Financial reporting Trust Services Criteria
Memory hook Financial Trust
Typical concern Controls relevant to financial reporting Controls relevant to service trust

SOC 2 covers five Trust Services Criteria:

  • Security

  • Availability

  • Processing Integrity

  • Confidentiality

  • Privacy

Memorize:

SOC 1 → Financial Reporting

SOC 2 → Trust Services


24. 🟠 Medium-Priority Standards and Frameworks

These are useful but should receive less study time than the core set.

Framework / Standard Memory Hook CISSP-Level Knowledge
ISO 27034 Application Security Integrate security into application management/lifecycle
ISO 27701 Privacy Management PIMS, PII, controllers/processors, privacy governance
ISO 31000 Risk Management General risk principles/process
NIST 800-53A Assessment Examine, Interview, Test
NIST 800-61 Incident Response IR lifecycle
NIST 800-115 Security Testing Technical security testing
NIST 800-145 Cloud Characteristics and service/deployment models
NIST 800-171 CUI Protect CUI
NIST 800-207 Zero Trust Continuous verification
CIS Controls Prioritized Safeguards Practical prioritized cybersecurity safeguards
MITRE ATT&CK Adversary Behavior Tactic → Technique → Procedure
OWASP ASVS App Verification Application-security requirements
ISO 22301 Business Continuity BCMS, BIA, resilience, recovery

25. CIS Controls

Think:

Prioritized cybersecurity safeguards

Security Weaknesses
       ↓
CIS Controls
       ↓
Prioritized Safeguards
       ↓
Practical Security Improvement

For CISSP, understand:

  • Prioritization

  • Safeguards

  • Implementation groups

  • Practical security improvement

Don't memorize every safeguard.


26. MITRE ATT&CK

MITRE ATT&CK is a knowledge base for understanding adversary behavior.

Remember:

TACTIC
  ↓
Why / Goal

TECHNIQUE
  ↓
How

PROCEDURE
  ↓
Actual Implementation

Example:

Tactic
Credential Access
      ↓
Technique
Credential Dumping
      ↓
Procedure
Specific attacker method/tool

Memory hook

Tactic = Why

Technique = How

Procedure = Actual Example


27. OWASP ASVS vs OWASP Top 10

For application-security professionals, this distinction is worth knowing.

OWASP Top 10

Think:

Application-security risks

OWASP ASVS

Think:

Application-security verification requirements

OWASP Top 10
     ↓
"What are common application risks?"

OWASP ASVS
     ↓
"What security requirements should
the application satisfy?"

For CISSP, understanding the distinction is more important than memorizing every item.


28. Privacy and Regulatory Knowledge

CISSP also expects understanding of legal, regulatory and privacy requirements.

For these, use three questions:

What does it protect?

Who does it apply to?

Why does it exist?

Regulation Memory Hook
GDPR EU personal-data privacy
HIPAA Healthcare / PHI
SOX Financial reporting
GLBA Financial privacy
FISMA US federal information security
CCPA/CPRA California privacy
FERPA Education records
COPPA Children's online privacy
NERC CIP Electric-grid critical infrastructure

Do not try to become a lawyer while preparing for CISSP.


29. ISO 22301 — Business Continuity

Think:

Business Continuity Management System

Business Processes
       ↓
Business Impact Analysis
       ↓
Critical Functions
       ↓
Recovery Requirements
       ↓
Continuity / Resilience

Know:

  • BIA

  • Critical business functions

  • Recovery requirements

  • Business continuity

  • Disaster recovery

  • Resilience

  • Testing


30. 🔥 The Ultimate CISSP "Don't Confuse These" Table

This is the table I would revise repeatedly.

When the question says... Think...
Information Security Management System ISO 27001
Security-control guidance ISO 27002
Application Security ISO 27034
Privacy Information Management System ISO 27701
General risk-management guidelines ISO 31000
Cybersecurity risk framework NIST CSF 2.0
Cybersecurity governance within CSF NIST CSF 2.0 — Govern
Security/privacy control catalog NIST 800-53
Risk Management Framework NIST 800-37
Control assessment NIST 800-53A
Incident response NIST 800-61
Cloud computing definition NIST 800-145
Controlled Unclassified Information NIST 800-171
Zero Trust NIST 800-207
IT governance COBIT
Business-aligned security architecture SABSA
Payment-card security PCI DSS
Federal cloud authorization FedRAMP
Financial reporting controls SOC 1
Trust Services Criteria SOC 2
Prioritized safeguards CIS Controls
Adversary behavior MITRE ATT&CK
Application-security verification OWASP ASVS
Common web-application risks OWASP Top 10
Business continuity management system ISO 22301
EU personal data GDPR
Healthcare / PHI HIPAA
Financial reporting SOX
Financial privacy GLBA
Federal information security FISMA

31. ⭐ The 20 Associations I Would Memorize

For rapid CISSP revision:

ISO 27001       → ISMS
ISO 27002       → Security Controls
ISO 27034       → Application Security
ISO 27701       → Privacy Management
ISO 31000       → Risk Management

NIST CSF 2.0    → Cybersecurity Risk
NIST 800-53     → Security & Privacy Controls
NIST 800-37     → RMF
NIST 800-53A    → Control Assessment
NIST 800-61     → Incident Response
NIST 800-115    → Security Testing
NIST 800-145    → Cloud
NIST 800-171    → CUI
NIST 800-207    → Zero Trust

COBIT           → IT Governance
SABSA           → Business-Aligned Security Architecture

PCI DSS         → Payment Cards
FedRAMP         → Federal Cloud Authorization

SOC 1           → Financial Reporting
SOC 2           → Trust Services

One addition is worth remembering separately:

NIST CSF 2.0 = Govern + Identify + Protect + Detect + Respond + Recover


32. What You DON'T Need to Memorize

This is where many CISSP candidates waste time.

Don't spend your preparation trying to memorize:

❌ Every ISO 27001 clause

❌ Every ISO 27002 control

❌ Every ISO 27034 detail

❌ Every ISO 27701 requirement

❌ Every ISO 31000 principle word-for-word

❌ Every NIST 800-53 control ID

❌ Every FedRAMP control

❌ Every COBIT process

❌ Every SABSA component

❌ Every PCI DSS requirement

❌ Every MITRE ATT&CK technique

❌ Every OWASP ASVS requirement

❌ Every article of GDPR

Instead, learn:

Purpose → Scope → Category → Key Concepts → Relationships → Scenario Application


33. How CISSP Scenario Questions Should Be Approached

The exam may not ask:

"What is ISO 27001?"

It may give you a business scenario.

Use this process.

Step 1 — Identify the problem

Is it primarily:

  • Governance?

  • Risk?

  • Controls?

  • Privacy?

  • Cloud?

  • Application security?

  • Compliance?

  • Business continuity?

  • Assurance?

Step 2 — Identify the type of framework

Is it:

  • Framework?

  • Standard?

  • Control catalog?

  • Regulation?

  • Maturity model?

  • Assurance report?

  • Authorization program?

Step 3 — Select the best fit

Now choose the framework that actually addresses the problem.

This is much more effective than matching keywords mechanically.


34. CISSP Scenario Examples

Example 1 — ISMS

An organization wants to establish a formal information-security management system based on risk and potentially pursue certification.

Think: ISO 27001


Example 2 — Security Controls

An organization requires a detailed catalog of security and privacy controls.

Think: NIST SP 800-53


Example 3 — Control Assessment

An organization needs to determine whether its controls are implemented correctly and operating effectively.

Think: NIST SP 800-53A


Example 4 — Cybersecurity Risk

Management wants a common structure for communicating and managing cybersecurity risk across the organization.

Think: NIST CSF 2.0


Example 5 — Governance

Senior management wants IT activities aligned with business objectives and appropriate governance oversight.

Think: COBIT


Example 6 — Federal Cloud

A US federal organization needs a standardized security assessment and authorization process for a cloud service.

Think: FedRAMP


Example 7 — Payment Cards

An organization processes payment-card information and needs to address industry security requirements.

Think: PCI DSS


Example 8 — Application Security

An organization wants to integrate security into its application-management processes.

Think: ISO 27034


Example 9 — Privacy Management

An organization wants a formal management system for managing personally identifiable information and privacy responsibilities.

Think: ISO 27701


Example 10 — General Risk

An organization wants internationally recognized principles and guidelines for managing enterprise risk.

Think: ISO 31000


35. A Better Way to Think About the ISO Family

This is perhaps the most useful diagram in the entire article:

                    ┌───────────────────┐
                    │     ISO 27001     │
                    │       ISMS        │
                    └─────────┬─────────┘
                              │
                 Information Security
                              │
              ┌───────────────┼───────────────┐
              │               │               │
              ▼               ▼               ▼
         ISO 27002       ISO 27034       ISO 27701
          Controls         AppSec           Privacy
                                             
                             
                    ISO 31000
                         │
                         ▼
                  General Risk
                   Management

Memorize the purpose, not the documents.


36. A Better Way to Think About NIST

                         NIST
                           │
                           ▼
                   CYBER / SECURITY RISK
                           │
         +-----------------+-----------------+
         │                 │                 │
         ▼                 ▼                 ▼
     NIST CSF          NIST 800-37       NIST 800-53
   Cyber Risk             RMF               Controls
         │                                     │
         │                                     ▼
         │                                  800-53A
         │                                 Assessment
         │
         +---- 800-61  → Incident Response
         +---- 800-145 → Cloud
         +---- 800-171 → CUI
         +---- 800-207 → Zero Trust

This is the mental model I recommend carrying into the exam.


37. Framework vs Standard vs Control — The Final Distinction

If you remember only one conceptual section from this article, remember this.

Framework

A structured approach for managing a problem.

Example: NIST CSF

Standard

Defined requirements or guidance.

Example: ISO 27001

Control

A safeguard that reduces risk.

Example: access control

Regulation

A legally enforceable requirement.

Example: GDPR

Maturity Model

A way to assess and improve capability.

Example: SAMM

Assurance Report

Independent reporting about controls.

Example: SOC 1 / SOC 2

Authorization Program

A standardized process for security assessment and authorization.

Example: FedRAMP


38. The Three-Pass CISSP Study Strategy

Pass 1 — Recognition

Learn:

Framework → Purpose

Examples:

ISO 27001 → ISMS

COBIT → Governance

NIST 800-53 → Controls

FedRAMP → Federal Cloud


Pass 2 — Relationships

Understand how they connect.

ISO

ISO 27001
   ↓
ISMS
   ↓
Risk Management
   ↓
Controls
   ↓
ISO 27002

NIST

NIST CSF 2.0
      ↓
Cybersecurity Risk
      ↓
NIST 800-53
      ↓
Controls
      ↓
NIST 800-53A
      ↓
Assessment

Federal Cloud

Security Requirements / Controls
            ↓
      Security Assessment
            ↓
          FedRAMP
            ↓
        Authorization

Pass 3 — Scenario Application

Now ask:

"If I were the security manager, which framework or concept best solves this problem?"

This is where CISSP preparation becomes much more effective.


39. The Final Night-Before-CISSP Revision Sheet

If you have only a few minutes before the exam, remember this:

                   CISSP FRAMEWORK MAP

ISO 27001    → ISMS
ISO 27002    → Security Controls
ISO 27034    → Application Security
ISO 27701    → Privacy Management
ISO 31000    → Risk Management

NIST CSF 2.0 → Govern + Identify + Protect
               + Detect + Respond + Recover

NIST 800-53  → Security & Privacy Controls
NIST 800-37  → Risk Management Framework
NIST 800-53A → Control Assessment
NIST 800-61  → Incident Response
NIST 800-115 → Security Testing
NIST 800-145 → Cloud
NIST 800-171 → CUI
NIST 800-207 → Zero Trust

COBIT        → IT Governance
SABSA        → Business-Aligned Security Architecture

PCI DSS      → Payment Cards
FedRAMP      → Federal Cloud Authorization

SOC 1        → Financial Reporting
SOC 2        → Trust Services

CIS Controls → Prioritized Safeguards
MITRE ATT&CK → Adversary Behavior

OWASP ASVS   → Application Security Requirements
OWASP Top 10 → Application Security Risks

Conclusion — Understand the Decision, Not Just the Definition

The cybersecurity industry has an enormous number of frameworks, standards, regulations and control catalogs.

You do not need to memorize the entire cybersecurity standards universe to pass CISSP.

The current ISC2 exam outline confirms that frameworks are part of the CISSP knowledge base, particularly within Security and Risk Management, alongside governance, risk, compliance, privacy, control assessment and business continuity.

Your objective should therefore be to build a mental map.

Remember:

ISO 27001 manages the ISMS.

ISO 27002 provides security-control guidance.

ISO 27034 focuses on application security.

ISO 27701 focuses on privacy information management.

ISO 31000 provides general risk-management guidance.

NIST CSF 2.0 organizes cybersecurity risk outcomes through Govern, Identify, Protect, Detect, Respond and Recover.

NIST 800-53 provides security and privacy controls.

NIST 800-37 provides the Risk Management Framework.

NIST 800-53A assesses controls.

COBIT focuses on IT governance.

SABSA aligns security architecture with business requirements.

PCI DSS addresses payment-card security.

FedRAMP addresses federal cloud security assessment and authorization.

SOC 1 focuses on financial reporting.

SOC 2 focuses on Trust Services Criteria.

CIS Controls provide prioritized safeguards.

MITRE ATT&CK describes adversary behavior.

And perhaps the most important lesson:

The CISSP exam isn't testing whether you can recite a framework. It is testing whether you can apply security and risk concepts to a business scenario.

So don't study frameworks as isolated definitions.

Study them as tools for making security decisions.

When you see a CISSP scenario, ask:

What is the business problem?

What type of framework or requirement is involved?

What risk is being addressed?

Who has the authority to make the decision?

Which approach best aligns security with business objectives?

That is the CISSP mindset.

Learn the map.

Understand the relationships.

Think about risk.

Choose the answer that best protects the organization while aligning with business objectives.

That's how you turn a huge standards landscape into a manageable CISSP study topic.


Official References

ISC2 — CISSP Certification Exam Outline The current ISC2 outline is the authoritative source for the CISSP exam domains and explicitly lists ISO, NIST, COBIT, SABSA, PCI and FedRAMP among security-control framework examples.

NIST — Cybersecurity Framework 2.0 The current NIST CSF 2.0 uses six Functions: Govern, Identify, Protect, Detect, Respond and Recover.

ISO — ISO/IEC 27001 ISO/IEC 27001 specifies requirements for an Information Security Management System.

ISO — ISO/IEC 27701:2025 The current edition specifies requirements and guidance for a Privacy Information Management System.

NIST — SP 800-37 Risk Management Framework NIST describes the RMF as a structured and flexible process for managing security and privacy risk, including categorization, control selection, implementation, assessment, authorization and continuous monitoring.

ISO — ISO 31000 ISO 31000 provides principles and guidelines for general risk management.


Final CISSP Rule

Don't memorize the standards universe.

Understand what each framework is designed to accomplish.

Understand how it relates to risk, governance, controls and compliance.

Then apply that knowledge to the scenario.

That is the CISSP way.

CISSP

Part 1 of 1

CISSP