---
title: "Cynergy regulation mapping NIST, ISO 27001, CSA top 11"
canonical: "https://kb.cynergy.app/space/WC/917635080/Cynergy%20regulation%20mapping%20NIST%2C%20ISO%2027001%2C%20CSA%20top%2011"
format: markdown
---
**NIST SP 800-53, Revision 5 Control Mappings to ISO/IEC 27001, CSA top 11 Cynergy Platform Reference and Support**

The following document provides a detailed description of the ways the Cynergy platforms solution and capabilities are directly mapped to ISO 27001 controls, CSA top 11, and NIST SP 800-53.

TABLE 1:  MAPPING NIST SP 800-53 TO ISO/IEC 27001

|  |  |  |
| --- | --- | --- |
| **NIST SP 800-53 CONTROLS** | **ISO/IEC 27001 CONTROLS**<br>*Note: An asterisk (*) indicates that the ISO/IEC control ****does not fully satisfy**** the intent of the NIST control.* | **Cynergy Platform Supported Controls** |
| AC-17 | Remote Access | A.6.2.1, A.6.2.2, A.13.1.1, A.13.2.1, A.14.1.2 | V |
| AC-22 | Publicly Accessible Content | None | V |
| CA-7 | Continuous Monitoring | 9.1, 9.2, A.18.2.2, A.18.2.3* | V |
| CM-4 | Impact Analyses | A.14.2.3 | V |
| PM-17 | Protecting Controlled Unclassified Information on External Systems | None | V |
| PM-28 | Risk Framing | 4.3, 6.1.2, 6.2, 7.4, 7.5.1, 7.5.2, 7.5.3 | V |
| PM-30 | Supply Chain Risk Management Strategy | 4.4, 6.2, 7.5.1, 7.5.2, 7.5.3, 10.2* | V |
| RA-5 | Vulnerability Monitoring and Scanning | A.12.6.1* | V |
| RA-7 | Risk Response | 6.1.3, 8.3, 10.1 | V |
| SR-6 | Supplier Assessments and Reviews | A.15.2.1 | V |

 

TABLE 2:  Mapping Cynergy to CSA top 11

 

|  |  |
| --- | --- |
| **CSA Top 11** | **Cynergy Platform Supported Controls** |
| CSA-1 | Data Breach | V |
| CSA-2 | Misconfiguration and Inadequate Change Control | V |
| CSA-3 | Insufficient Identity, Credential, Access, and Key Management |  |
| CSA-4 | Insufficient Identity and Credential Management | V |
| CSA-5 | Account Hijacking |  |
| CSA-6 | Insider Threat |  |
| CSA-7 | Insecure Interfaces and Application Programming Interfaces | V |
| CSA-8 | Weak Control Plane | V |
| CSA-9 | Metastructure and Applistructure Failures |  |
| CSA-10 | Limited Cloud Usage Visibility |  |
| CSA-11 | Abuse and Nefarious Use of Cloud Services | V |

 

Table 2 provides a mapping from the security requirements and controls in ISO/IEC 27001 to the security controls in Special Publication 800-53. Please review the introductory text provided above before employing the mappings in Table 2.

 

TABLE 3:  MAPPING ISO/IEC 27001 TO NIST SP 800-53

|  |  |  |
| --- | --- | --- |
| **ISO/IEC 27001 REQUIREMENTS AND CONTROLS** | **NIST SP 800-53 CONTROLS**<br>*Note: An asterisk (*) indicates that the ISO/IEC control does not fully satisfy the intent of the NIST control.* | ** **<br>**Cynergy Platform Supported Controls** |
| **ISO/IEC 27001 Requirements** | ** ** |
| 1. Context of the Organization |  |  |
| 4.1 Understanding the organization and its context | PM-1, PM-11 | V |
| 4.4 Information security management system | PM-1, PM-9, PM-30, PM-31 | V |
| **6.1 Actions to address risks and opportunities** |  |  |
| 6.1.1 General | PM-1, PM-4, PM-6, PM-9 |  |
| 6.1.2 Information security risk assessment | PM-9, PM-28, RA-3 | V |
| 6.1.3 Information security risk treatment | RA-7 | V |
| 1. Operation |  |  |
| 8.2 Information security risk assessment | RA-3 | V |
| 8.3 Information security risk treatment | CA-5, PM-4, RA-7 | V |
| 1. Performance evaluation |  |  |
| 9.1 Monitoring, measurement, analysis, and evaluation | CA-1, CA-7, PM-6, PM-31 | V |
| **10. Improvement** |  |  |
| **ISO/IEC 27001 Controls** | ** ** |
| **A.8  Asset Management** |  |  |
| **A.8.1  Responsibility for assets** |  |  |
| A.8.1.1 Inventory of assets | CM-8 | V |
| A.8.1.2 Ownership of assets | CM-8 | V |
| **A.13  Communications security** |  |  |
| **A.13.1  Network security management** |  |  |
| A.13.1.1 Network controls | AC-3, AC-17, AC-18, AC-20, SC-7, SC-8, SC-10 | V |
| A.13.1.2 Security of network services | CA-3, SA-9 | V |
| **A.16.1 Managing of information security incidents and improvements** |  |  |
| A.16.1.3 Reporting information security weaknesses | SI-2 | V |
| A.16.1.7 Collection of evidence | AU-4, AU-9, AU-10(3), AU-11* | V |
| **A.17  Information security aspects of business continuity management** |  |  |
| **A.17.1  Information security continuity** |  |  |
| A.17.1.2 Implementing information security continuity | CP-6, CP-7, CP-8, CP-9, CP-10, CP-11, CP-13 | V |
| **A.18  Compliance** |  |  |
| **A.18.1  Compliance with legal and contractual requirements** |  |  |
| A.18.2.1 Independent review of information security | CA-2(1), SA-11(3) | V |
| A.18.2.3 Technical compliance review | CA-2 | V |

** **