NIST CSF 2.0 vs CIS v8

Side-by-side comparison of NIST Cybersecurity Framework 2.0 and CIS Controls v8 across 49 cybersecurity controls.

44
Shared
5
NIST CSF 2.0 Only
0
CIS v8 Only
0
Neither

Covered by Both (44 controls)

Controls recognized by both NIST CSF 2.0 and CIS v8.

Gp Governance Policy
GV.OC-01, GV.PO-01 | CIS 1.1
Aw Awareness & Training
PR.AT-01, PR.AT-02 | CIS 14.1, CIS 14.2
Rm Risk Management
GV.RM-01, GV.RM-02 | CIS 1.2
Rr Roles & Responsibilities
GV.RR-01 | CIS 1.3
Am Asset Management
ID.AM-01, ID.AM-02 | CIS 1.1, CIS 2.1
Ra Risk Assessment
ID.RA-01, ID.RA-02 | CIS 7.1
Da Data Classification
ID.AM-05 | CIS 3.1, CIS 3.7
Vn Vulnerability Mgmt
ID.RA-01 | CIS 7.1, CIS 7.2, CIS 7.4
Ti Threat Intelligence
DE.AE-07 | CIS 13.8
Ac Access Control
PR.AA-01, PR.AA-03 | CIS 5.1, CIS 6.1, CIS 6.2
Mf Multi-Factor Auth
PR.AA-03 | CIS 6.3, CIS 6.4, CIS 6.5
En Encryption
PR.DS-01, PR.DS-02 | CIS 3.6, CIS 3.9, CIS 3.10
Dp Data Protection
PR.DS-01, PR.DS-02, PR.DS-10 | CIS 3.1, CIS 3.10, CIS 3.12
Bk Backup & Recovery
PR.DS-11 | CIS 11.1, CIS 11.2, CIS 11.4
Pa Privileged Access
PR.AA-05 | CIS 5.4, CIS 6.5
Fw Firewall / Net Seg
PR.IR-01 | CIS 9.2, CIS 9.3, CIS 12.2
Ep Endpoint Protection
PR.IR-01 | CIS 10.1, CIS 10.2
Pm Patch Management
PR.PS-01 | CIS 7.3, CIS 7.4
Cf Secure Config
PR.PS-01 | CIS 4.1, CIS 4.2, CIS 4.6
Sd Secure Development
PR.PS-06 | CIS 16.1, CIS 16.2
Ml Email Security
PR.IR-01 | CIS 9.6, CIS 9.7
Ws Web Security
PR.IR-01 | CIS 9.5, CIS 16.4
Zt Zero Trust
PR.AA-01, PR.AA-03, PR.IR-01 | CIS 6.1, CIS 12.2
Mb Mobile Security
PR.PS-01 | CIS 1.4, CIS 1.5
Cl Cloud Security
PR.PS-01, PR.DS-01 | CIS 4.1, CIS 6.1
Ds DNS Security
PR.IR-01 | CIS 9.2
Wf WAF
PR.IR-01 | CIS 13.10
Dl DLP
PR.DS-10 | CIS 3.12
Sm Cont. Monitoring
DE.CM-01, DE.CM-03 | CIS 8.2, CIS 8.5, CIS 8.11
Lg Logging & Audit
DE.AE-02, DE.AE-03 | CIS 8.1, CIS 8.2, CIS 8.9
Id Intrusion Detection
DE.CM-01 | CIS 13.1, CIS 13.3
An Anomaly Detection
DE.AE-01, DE.AE-04 | CIS 8.5, CIS 8.6
Sg SIEM / SOC
DE.AE-02, DE.AE-06 | CIS 8.2, CIS 8.11
Ir Incident Response
RS.MA-01, RS.MA-02 | CIS 17.1, CIS 17.2, CIS 17.3
Fn Forensics
RS.AN-03 | CIS 17.6
Co Communication
RS.CO-02, RS.CO-03 | CIS 17.2
Mt Mitigation
RS.MI-01, RS.MI-02 | CIS 17.4
Rp Reporting
RS.CO-02 | CIS 17.3
Rc Recovery Planning
RC.RP-01, RC.RP-02 | CIS 11.1, CIS 17.7
Bc Business Continuity
RC.RP-03, RC.RP-04 | CIS 11.3, CIS 11.4
Ll Lessons Learned
RC.RP-06 | CIS 17.8
Dr Disaster Recovery
RC.RP-01 | CIS 11.1, CIS 11.5
Ap API Security
PR.IR-01, PR.AA-03 | CIS 16.4
It Insider Threat
DE.CM-03, DE.AE-01 | CIS 6.1, CIS 6.2, CIS 8.6

Only in NIST CSF 2.0 (5 controls)

Controls covered by NIST CSF 2.0 but not CIS v8. Organizations using CIS v8 should consider supplementing with these.

Summary: NIST CSF 2.0 vs CIS v8

NIST Cybersecurity Framework 2.0 and CIS Controls v8 share 44 controls in common out of 49 total. NIST CSF 2.0 uniquely covers 5 controls that CIS v8 does not, including Supply Chain Risk, Compliance, Business Environment. CIS v8 uniquely covers 0 controls that NIST CSF 2.0 does not. Together, these two frameworks cover all tracked controls. For comprehensive cybersecurity coverage, organizations often adopt both frameworks or supplement with other frameworks.

View Interactive Dashboard