2026-09-21 · KeXinMaterials Editorial Team

NIST CSF 2.0 + ISO 27005 + ISO 31000 Cybersecurity Risk Management Family Protective Case B2B Guide

NIST Cybersecurity Framework (CSF) 2.0 + ISO 27005 (information security risk management) + ISO 31000 (enterprise risk management, ERM) are the three foundational risk + cybersecurity frameworks. NIST CSF 2.0 (released February 2024) added the Govern function + expanded supply chain. ISO 27005:2022 + ISO 31000:2018 align with ISO 31000 risk principles. Below is the 2026 B2B procurement guide covering Govern function, risk assessment, risk treatment, risk communication, and protective case correlation.

NIST Cybersecurity Framework 2.0 (CSF 2.0)

NIST Cybersecurity Framework 2.0 (February 2024) expands the original CSF 1.1 (2018) with the Govern function + supply chain + small business quick-start guide + mapping to NIST RMF + ISO 27001.

NIST CSF 2.0 release: February 26, 2024. Replaces CSF 1.1 (2018). Adds Govern function + enhances supply chain risk management + adds small business quick-start guide.

CSF 2.0 structure: 6 functions (Govern + Identify + Protect + Detect + Respond + Recover) + 22 categories + 106 subcategories. Previously 5 functions in CSF 1.1.

Govern function (NEW in CSF 2.0): Organizational context + risk management strategy + roles + responsibilities + policies + processes + oversight. Cross-cutting across all other functions.

Identify function: Asset management + business environment + governance + risk assessment + risk management strategy + supply chain risk management.

Protect function: Identity management + authentication + access control + awareness + training + data security + information protection processes + maintenance + protective technology.

Detect function: Anomalies + events + continuous monitoring + detection processes.

Respond function: Response planning + communications + analysis + mitigation + improvements.

Recover function: Recovery planning + improvements + communications.

CSF 2.0 tiers: Partial (Tier 1) + Risk-Informed (Tier 2) + Repeatable (Tier 3) + Adaptive (Tier 4). Organizational risk management maturity.

CSF 2.0 profiles: Customized implementation of CSF based on use case + sector + risk profile. Quick-Start Guide for Small Businesses included.

CSF 2.0 + NIST RMF mapping: CSF subcategories mapped to NIST RMF (SP 800-37 Rev 2) steps. CSF 2.0 implementation can serve as operational layer for RMF.

CSF 2.0 + ISO 27001 mapping: CSF categories/subcategories mapped to ISO 27001:2022 Annex A controls. Cross-walk published by NIST.

Geographic adoption: US federal agencies (mandatory per Executive Order 14028 May 2021). Voluntary globally. US critical infrastructure (16 sectors).

B2B relevance: For B2B protective cases containing IT + OT + IoT + edge computing equipment, NIST CSF 2.0 alignment increasingly required for US federal + critical infrastructure procurement.

ISO 27005 Information Security Risk Management

ISO/IEC 27005:2022 "Information security, cybersecurity and privacy protection - Guidance on managing information security risks". Edition 4 (2022). Aligns with ISO 31000:2018.

ISO/IEC 27005:2022: "Information security, cybersecurity and privacy protection - Guidance on managing information security risks". Edition 4 (2022). Replaces ISO/IEC 27005:2018.

ISO 27005 scope: Information security risk management for organizations. Aligns with ISO 31000 risk principles + ISO/IEC 27001 ISMS.

ISO 27005 process: Context establishment + risk identification + risk analysis + risk evaluation + risk treatment + risk acceptance + risk communication + risk monitoring + review.

Context establishment: Per ISO 27005 clause 6. Define scope + boundaries + risk criteria + impact criteria + risk acceptance criteria. Align with ISO 27001 ISMS scope.

Risk identification: Per ISO 27005 clause 8. Identify information security risks (asset-based + threat-based + event-based + vulnerability-based). Use ISO 27002 controls + ISO 27017 + ISO 27018 + ISO 27701.

Risk analysis: Per ISO 27005 clause 9. Assess likelihood + consequences (impact). Qualitative + quantitative + semi-quantitative methods. Risk = Likelihood x Impact.

Risk evaluation: Per ISO 27005 clause 10. Compare risk estimates against risk criteria. Prioritize risks for treatment.

Risk treatment: Per ISO 27005 clause 11. Options: (1) Modify (apply controls). (2) Avoid (remove risk source). (3) Share (transfer via insurance / outsourcing). (4) Accept (retain with informed decision).

Risk acceptance: Per ISO 27005 clause 12. Formal acceptance by risk owner. Document in Statement of Applicability (SoA) per ISO 27001.

Risk communication: Per ISO 27005 clause 13. Internal + external communication of risk information. Stakeholder engagement.

Risk monitoring + review: Per ISO 27005 clause 14. Continuous monitoring + periodic review. Update risk assessment based on changes.

ISO 27005 + ISO 27001: ISO 27005 risk assessment feeds ISO 27001 ISMS risk treatment plan + Statement of Applicability.

ISO 27005 + ISO 27002: ISO 27002:2022 Annex A controls (93 controls in 4 themes: organizational + people + physical + technological) referenced in ISO 27005 risk treatment.

Geographic adoption: Adopted as ISO/IEC 27005:2022 (international). Required for ISO 27001 certification. Required for EU NIS2 + EU CRA + UK Cyber Essentials + Singapore MAS TRM.

B2B relevance: For B2B protective cases containing sensitive information (financial + medical + defense + IP), ISO 27005 risk assessment + ISO 27001 ISMS aligned procurement required.

ISO 31000 Enterprise Risk Management (ERM)

ISO 31000:2018 "Risk management - Guidelines". Edition 2 (2018). Provides principles + framework + process for enterprise risk management (ERM) at organizational level.

ISO 31000:2018: "Risk management - Guidelines". Edition 2 (2018). Replaces ISO 31000:2009. Aligns with ISO 27005:2022 + ISO 9001:2015 + ISO 14001:2015.

ISO 31000 scope: All organizations regardless of size + sector. Provides risk management principles + framework + process.

ISO 31000 principles: (1) Integrated. (2) Structured + comprehensive. (3) Customized. (4) Inclusive. (5) Dynamic. (6) Best available information. (7) Human + cultural factors. (8) Continual improvement.

ISO 31000 framework: Leadership + commitment (top management + governance + risk culture + accountability). Integration (strategy + decision-making + processes). Implementation (plans + resources + accountability). Evaluation (effectiveness measurement). Improvement (learning + adjustment).

ISO 31000 process: Communication + consultation (internal + external stakeholders). Scope + context + criteria. Risk assessment (identification + analysis + evaluation). Risk treatment (selection + implementation). Monitoring + review. Recording + reporting.

ISO 31000 vs ISO 27005: ISO 31000 is enterprise-wide (all risks). ISO 27005 is information security specific. ISO 27005 conforms to ISO 31000 principles + framework + process.

ISO 31000 vs COSO ERM: COSO ERM 2017 (US) + ISO 31000:2018 (international) are similar. COSO focuses on financial + strategic risks. ISO 31000 broader.

ISO 31000 risk appetite + tolerance: Top management defines risk appetite (overall level) + risk tolerance (acceptable variation around objectives).

ISO 31000 risk culture: Organizational values + behaviors + understanding of risk. Influences how risks identified, treated, communicated.

ISO 31000 + ISO 9001:2015: ISO 9001:2015 quality management uses ISO 31000 risk-based thinking (clause 6.1). Risk + opportunity identification.

ISO 31000 + ISO 14001:2015: ISO 14001:2015 environmental management uses ISO 31000 risk + opportunity identification. Environmental aspects + impacts.

ISO 31000 governance: Board + top management oversight of risk management. Integration with strategic decision-making + operations.

Geographic adoption: Adopted as ISO 31000:2018 (international). Voluntary. Aligned with COSO ERM + Basel III + Solvency II + UK ORSA + AU CPS 220.

B2B relevance: For B2B procurement of complex protective cases (defense + aerospace + nuclear + medical + financial), ISO 31000 ERM framework demonstrates organizational risk maturity.

NIST CSF 2.0 + ISO 27005 + ISO 31000 Combined + Supply Chain

Combined application of NIST CSF 2.0 + ISO 27005 + ISO 31000 + supply chain risk management + B2B procurement workflow.

Combined framework: NIST CSF 2.0 (operational cyber) + ISO 27005 (information security risk) + ISO 31000 (enterprise risk). Each layer provides specific value.

Layer 1 — ISO 31000 enterprise risk: Top management sets risk appetite + tolerance + culture. Strategic risk integration.

Layer 2 — ISO 27005 information security risk: Information security risks identified + analyzed + treated within ISMS. Feeds into ERM.

Layer 3 — NIST CSF 2.0 operational cybersecurity: Operational cybersecurity controls mapped to Govern + Identify + Protect + Detect + Respond + Recover.

Supply chain risk management per NIST CSF 2.0 + ISO 27001 + ISO 28000: Supply chain cybersecurity risks addressed through vendor assessment + SBOM + software supply chain (SLSA) + hardware supply chain (CTID).

NIST CSF 2.0 + ISO 27001:2022 + ISO 27005:2022 mapping: NIST published crosswalk between CSF 2.0 + ISO 27001:2022. ISO 27005 risk assessment aligned with ISO 27001 Annex A controls.

EU NIS2 + ISO 27001: EU NIS2 (effective October 2024) requires essential + important entities implement ISO 27001 + risk assessment per ISO 27005.

EU Cyber Resilience Act (CRA) + ISO 27001: EU CRA (effective 2025 + 2027 phased) requires digital products + connected devices comply with cybersecurity requirements. ISO 27001 + ETSI EN 303 645 + NIST CSF 2.0 alignment.

US SEC Cybersecurity Disclosure + ISO 27005: US SEC Cybersecurity Disclosure Rule (December 2023) requires public companies disclose cybersecurity risk management + governance + material incidents.

Common B2B mistakes: (1) Treating CSF 2.0 + ISO 27005 + ISO 31000 as competing (they are complementary). (2) Skipping Govern function. (3) Missing supply chain risk. (4) Not integrating with ISO 27001 ISMS. (5) Treating cyber as IT-only (it is enterprise risk).

B2B procurement workflow: (1) Identify customer risk management framework preference (CSF 2.0 / ISO 27005 / ISO 31000 / combined). (2) Verify supplier risk assessment + ISMS + ISO 27001 certification. (3) Supply chain risk assessment (SBOM + software supply chain + hardware supply chain). (4) Contract terms: incident reporting + SLAs + liability + cyber insurance. (5) Continuous monitoring + periodic audit.

B2B recommendation: For B2B protective cases for IT + OT + IoT + critical infrastructure, require NIST CSF 2.0 alignment + ISO 27001:2022 + ISO 27005 risk assessment + ISO 31000 ERM + supply chain risk management + cyber insurance + incident response + SBOM + FOB Shenzhen/Ningbo/EXW delivery 30-45 days.

Key Takeaways

  • NIST CSF 2.0 (Feb 2024) adds Govern function + supply chain + small business guide. 6 functions + 22 categories + 106 subcategories.
  • ISO 27005:2022 information security risk management. Aligns with ISO 31000. Required for ISO 27001 + EU NIS2 + EU CRA + UK Cyber Essentials.
  • ISO 31000:2018 enterprise risk management. Principles + framework + process. Aligned with COSO ERM + Basel III + Solvency II.
  • Layered: ISO 31000 (enterprise) > ISO 27005 (info security) > NIST CSF 2.0 (operational cyber). Complementary not competing.
  • Govern function cross-cutting: top management + board oversight + risk culture + accountability.
  • Supply chain risk: SBOM + SLSA + CTID + vendor assessment. EU NIS2 + EU CRA + US SEC Cyber Disclosure alignment.
  • B2B recommendation: Require NIST CSF 2.0 + ISO 27001:2022 + ISO 27005 risk assessment + ISO 31000 ERM + supply chain + cyber insurance, FOB Shenzhen/Ningbo/EXW.

FAQ

q

a

q

a

q

a

q

a

q

a

q

a

Inquiry Now · 30-45 Day Delivery