| Framework | What you need to know as a GRC Analyst | Key control areas you should learn | Official documentation |
|---|---|---|---|
| NIST CSF 2.0 | High-level cybersecurity framework. Think outcomes, not individual prescriptive controls. | Govern: policies, roles, risk strategy, oversight, supply chain. Identify: assets, risks, improvements. Protect: IAM, awareness, data security, platforms. Detect: monitoring, adverse events. Respond: incident management, reporting, mitigation. Recover: recovery planning, communication, improvements. | NIST CSF 2.0 official documentation (NIST) |
| NIST SP 800-53 Rev. 5 | Actual control catalogue. This is one of the most important frameworks for learning how controls are structured. | AC Access Control; AT Awareness & Training; AU Audit & Accountability; CA Assessment; CM Configuration Management; CP Contingency Planning; IA Identification & Authentication; IR Incident Response; MA Maintenance; MP Media Protection; PE Physical Protection; PL Planning; PM Program Management; PS Personnel Security; RA Risk Assessment; SA System Acquisition; SC System & Communications Protection; SI System & Information Integrity; SR Supply Chain Risk Management; plus PT PII Processing & Transparency. | NIST SP 800-53 controls (NIST Computer Security Resource Center) |
| ISO/IEC 27001:2022 | The ISMS standard. Learn risk assessment, risk treatment, governance, Statement of Applicability (SoA), internal audit, management review and continual improvement. | Annex A: 93 controls across Organizational, People, Physical and Technological themes. Important: Annex A is a reference control set; the organization’s controls are determined through risk treatment and documented in the SoA. | ISO/IEC 27001 official page |
| ISO/IEC 27002:2022 | The implementation guidance for the 93 ISO 27001 Annex A controls. This is where you learn what the controls actually mean and how they can be implemented. | Organizational – 37: policies, roles, segregation, threat intelligence, asset management, access, supplier security, incident management, continuity, compliance. People – 8: screening, terms, awareness, disciplinary process, remote working. Physical – 14: physical security, equipment, media, disposal. Technological – 34: endpoint security, access, authentication, malware, backup, logging, monitoring, network security, cryptography, secure development, vulnerability management. | ISO/IEC 27002 official information (ISO) |
Very important for your studies:
ISO 27001 = ISMS + requirements + Annex A reference controls.
ISO 27002 = detailed guidance for implementing those 93 controls. The 93 controls have the same identifiers/names in both, while 27002 provides the implementation guidance.