Industry Frameworks / Standards

FrameworkWhat you need to know as a GRC AnalystKey control areas you should learnOfficial documentation
NIST CSF 2.0High-level cybersecurity framework. Think outcomes, not individual prescriptive controls.Govern: policies, roles, risk strategy, oversight, supply chain. Identify: assets, risks, improvements. Protect: IAM, awareness, data security, platforms. Detect: monitoring, adverse events. Respond: incident management, reporting, mitigation. Recover: recovery planning, communication, improvements.NIST CSF 2.0 official documentation (NIST)
NIST SP 800-53 Rev. 5Actual control catalogue. This is one of the most important frameworks for learning how controls are structured.AC Access Control; AT Awareness & Training; AU Audit & Accountability; CA Assessment; CM Configuration Management; CP Contingency Planning; IA Identification & Authentication; IR Incident Response; MA Maintenance; MP Media Protection; PE Physical Protection; PL Planning; PM Program Management; PS Personnel Security; RA Risk Assessment; SA System Acquisition; SC System & Communications Protection; SI System & Information Integrity; SR Supply Chain Risk Management; plus PT PII Processing & Transparency.NIST SP 800-53 controls (NIST Computer Security Resource Center)
ISO/IEC 27001:2022The ISMS standard. Learn risk assessment, risk treatment, governance, Statement of Applicability (SoA), internal audit, management review and continual improvement.Annex A: 93 controls across Organizational, People, Physical and Technological themes. Important: Annex A is a reference control set; the organization’s controls are determined through risk treatment and documented in the SoA.ISO/IEC 27001 official page
ISO/IEC 27002:2022The implementation guidance for the 93 ISO 27001 Annex A controls. This is where you learn what the controls actually mean and how they can be implemented.Organizational – 37: policies, roles, segregation, threat intelligence, asset management, access, supplier security, incident management, continuity, compliance. People – 8: screening, terms, awareness, disciplinary process, remote working. Physical – 14: physical security, equipment, media, disposal. Technological – 34: endpoint security, access, authentication, malware, backup, logging, monitoring, network security, cryptography, secure development, vulnerability management.ISO/IEC 27002 official information (ISO)

Very important for your studies:
ISO 27001 = ISMS + requirements + Annex A reference controls.
ISO 27002 = detailed guidance for implementing those 93 controls. The 93 controls have the same identifiers/names in both, while 27002 provides the implementation guidance.