✳ Reference / Frameworks
Same site.
Different maps.
Use this table to see what each framework is for. A row is not a crosswalk, and a relationship is not proof that one control satisfies another.
| Framework | Purpose | Prescriptive vs outcome | Certifiable? | Primary user | Typical misuse |
|---|---|---|---|---|---|
| CSF 2.0 (CSWP 29) | Communicate cybersecurity risk outcomes | Outcome taxonomy; does not prescribe how | No CSF certificate is part of the framework | Leadership and practitioners aligning language | Treating a profile spreadsheet as an audit pass |
| CIS Controls v8.1 | Prioritized safeguards and Implementation Groups | More prescriptive safeguards | Not a formal certification scheme like ISO. A vendor “aligned” claim is not a certificate | Builders and defenders implementing hygiene | Claiming CIS is done, so CSF or ISO is done |
| ISO/IEC 27001:2022 | Requirements for an information security management system | Management-system requirements, plus Annex A references | Yes. Accredited certification of a scoped ISMS | GRC and management-system owners | Using the logo as proof that a product is secure |
| SP 800-53 Rev. 5 (Rel. 5.2.0) | Select and tailor a control catalog | Catalog of controls, with baselines in SP 800-53B | Used inside authorization processes. Not a consumer sticker | Assessors, federal and Fed-adjacent programs, and control engineers | Implementing every control without tailoring |
| MITRE ATT&CK v19.2 | Describe adversary behaviors | Descriptive knowledge base | No | Detection engineering, threat intelligence, and red and blue teams | Treating coverage percentage as a compliance score |
| OWASP Top 10:2025 | Awareness of common application risks | Awareness list. Not ASVS, and not the LLM Top 10 | No | Developers and application-security educators | Treating the list as a complete test standard |
Three second-wave field guides (SP 800-207, SSDF Version 1.1, and AI RMF 1.0) sit beside these six maps and are not rows in this table.Open the field guides.