2026-09-21 · Équipe éditoriale KeXinMaterials

NIST CSF 2.0 + ISO 27005 + ISO 31000 Cybersécurité Gestion Risques Famille Mallette B2B Guide

NIST CSF 2.0 + ISO 27005 + ISO 31000 sont trois frameworks fondamentaux de cybersécurité + gestion risques. Requis pour IT + OT + IoT + infrastructure critique.

NIST Cybersecurity Framework 2.0 (CSF 2.0)

NIST Cybersecurity Framework 2.0 (February 2024) expands the original CSF 1.1 (2018) with the Govern function + supply chain + small business quick-start guide + mapping to NIST RMF + ISO 27001.

NIST CSF 2.0 release: February 26, 2024. Replaces CSF 1.1 (2018). Adds Govern function + enhances supply chain risk management + adds small business quick-start guide.

CSF 2.0 structure: 6 functions (Govern + Identify + Protect + Detect + Respond + Recover) + 22 categories + 106 subcategories. Previously 5 functions in CSF 1.1.

Govern function (NEW in CSF 2.0): Organizational context + risk management strategy + roles + responsibilities + policies + processes + oversight. Cross-cutting across all other functions.

Identify function: Asset management + business environment + governance + risk assessment + risk management strategy + supply chain risk management.

Protect function: Identity management + authentication + access control + awareness + training + data security + information protection processes + maintenance + protective technology.

Detect function: Anomalies + events + continuous monitoring + detection processes.

Respond function: Response planning + communications + analysis + mitigation + improvements.

Recover function: Recovery planning + improvements + communications.

CSF 2.0 tiers: Partial (Tier 1) + Risk-Informed (Tier 2) + Repeatable (Tier 3) + Adaptive (Tier 4). Organizational risk management maturity.

CSF 2.0 profiles: Customized implementation of CSF based on use case + sector + risk profile. Quick-Start Guide for Small Businesses included.

CSF 2.0 + NIST RMF mapping: CSF subcategories mapped to NIST RMF (SP 800-37 Rev 2) steps. CSF 2.0 implementation can serve as operational layer for RMF.

CSF 2.0 + ISO 27001 mapping: CSF categories/subcategories mapped to ISO 27001:2022 Annex A controls. Cross-walk published by NIST.

Geographic adoption: US federal agencies (mandatory per Executive Order 14028 May 2021). Voluntary globally. US critical infrastructure (16 sectors).

B2B relevance: For B2B protective cases containing IT + OT + IoT + edge computing equipment, NIST CSF 2.0 alignment increasingly required for US federal + critical infrastructure procurement.

ISO 27005 Information Security Risk Management

ISO/IEC 27005:2022 "Information security, cybersecurity and privacy protection - Guidance on managing information security risks". Edition 4 (2022). Aligns with ISO 31000:2018.

ISO/IEC 27005:2022: "Information security, cybersecurity and privacy protection - Guidance on managing information security risks". Edition 4 (2022). Replaces ISO/IEC 27005:2018.

ISO 27005 scope: Information security risk management for organizations. Aligns with ISO 31000 risk principles + ISO/IEC 27001 ISMS.

ISO 27005 process: Context establishment + risk identification + risk analysis + risk evaluation + risk treatment + risk acceptance + risk communication + risk monitoring + review.

Context establishment: Per ISO 27005 clause 6. Define scope + boundaries + risk criteria + impact criteria + risk acceptance criteria. Align with ISO 27001 ISMS scope.

Risk identification: Per ISO 27005 clause 8. Identify information security risks (asset-based + threat-based + event-based + vulnerability-based). Use ISO 27002 controls + ISO 27017 + ISO 27018 + ISO 27701.

Risk analysis: Per ISO 27005 clause 9. Assess likelihood + consequences (impact). Qualitative + quantitative + semi-quantitative methods. Risk = Likelihood x Impact.

Risk evaluation: Per ISO 27005 clause 10. Compare risk estimates against risk criteria. Prioritize risks for treatment.

Risk treatment: Per ISO 27005 clause 11. Options: (1) Modify (apply controls). (2) Avoid (remove risk source). (3) Share (transfer via insurance / outsourcing). (4) Accept (retain with informed decision).

Risk acceptance: Per ISO 27005 clause 12. Formal acceptance by risk owner. Document in Statement of Applicability (SoA) per ISO 27001.

Risk communication: Per ISO 27005 clause 13. Internal + external communication of risk information. Stakeholder engagement.

Risk monitoring + review: Per ISO 27005 clause 14. Continuous monitoring + periodic review. Update risk assessment based on changes.

ISO 27005 + ISO 27001: ISO 27005 risk assessment feeds ISO 27001 ISMS risk treatment plan + Statement of Applicability.

ISO 27005 + ISO 27002: ISO 27002:2022 Annex A controls (93 controls in 4 themes: organizational + people + physical + technological) referenced in ISO 27005 risk treatment.

Geographic adoption: Adopted as ISO/IEC 27005:2022 (international). Required for ISO 27001 certification. Required for EU NIS2 + EU CRA + UK Cyber Essentials + Singapore MAS TRM.

B2B relevance: For B2B protective cases containing sensitive information (financial + medical + defense + IP), ISO 27005 risk assessment + ISO 27001 ISMS aligned procurement required.

ISO 31000 Enterprise Risk Management (ERM)

ISO 31000:2018 "Risk management - Guidelines". Edition 2 (2018). Provides principles + framework + process for enterprise risk management (ERM) at organizational level.

ISO 31000:2018: "Risk management - Guidelines". Edition 2 (2018). Replaces ISO 31000:2009. Aligns with ISO 27005:2022 + ISO 9001:2015 + ISO 14001:2015.

ISO 31000 scope: All organizations regardless of size + sector. Provides risk management principles + framework + process.

ISO 31000 principles: (1) Integrated. (2) Structured + comprehensive. (3) Customized. (4) Inclusive. (5) Dynamic. (6) Best available information. (7) Human + cultural factors. (8) Continual improvement.

ISO 31000 framework: Leadership + commitment (top management + governance + risk culture + accountability). Integration (strategy + decision-making + processes). Implementation (plans + resources + accountability). Evaluation (effectiveness measurement). Improvement (learning + adjustment).

ISO 31000 process: Communication + consultation (internal + external stakeholders). Scope + context + criteria. Risk assessment (identification + analysis + evaluation). Risk treatment (selection + implementation). Monitoring + review. Recording + reporting.

ISO 31000 vs ISO 27005: ISO 31000 is enterprise-wide (all risks). ISO 27005 is information security specific. ISO 27005 conforms to ISO 31000 principles + framework + process.

ISO 31000 vs COSO ERM: COSO ERM 2017 (US) + ISO 31000:2018 (international) are similar. COSO focuses on financial + strategic risks. ISO 31000 broader.

ISO 31000 risk appetite + tolerance: Top management defines risk appetite (overall level) + risk tolerance (acceptable variation around objectives).

ISO 31000 risk culture: Organizational values + behaviors + understanding of risk. Influences how risks identified, treated, communicated.

ISO 31000 + ISO 9001:2015: ISO 9001:2015 quality management uses ISO 31000 risk-based thinking (clause 6.1). Risk + opportunity identification.

ISO 31000 + ISO 14001:2015: ISO 14001:2015 environmental management uses ISO 31000 risk + opportunity identification. Environmental aspects + impacts.

ISO 31000 governance: Board + top management oversight of risk management. Integration with strategic decision-making + operations.

Geographic adoption: Adopted as ISO 31000:2018 (international). Voluntary. Aligned with COSO ERM + Basel III + Solvency II + UK ORSA + AU CPS 220.

B2B relevance: For B2B procurement of complex protective cases (defense + aerospace + nuclear + medical + financial), ISO 31000 ERM framework demonstrates organizational risk maturity.

NIST CSF 2.0 + ISO 27005 + ISO 31000 Combined + Supply Chain

Combined application of NIST CSF 2.0 + ISO 27005 + ISO 31000 + supply chain risk management + B2B procurement workflow.

Combined framework: NIST CSF 2.0 (operational cyber) + ISO 27005 (information security risk) + ISO 31000 (enterprise risk). Each layer provides specific value.

Layer 1 — ISO 31000 enterprise risk: Top management sets risk appetite + tolerance + culture. Strategic risk integration.

Layer 2 — ISO 27005 information security risk: Information security risks identified + analyzed + treated within ISMS. Feeds into ERM.

Layer 3 — NIST CSF 2.0 operational cybersecurity: Operational cybersecurity controls mapped to Govern + Identify + Protect + Detect + Respond + Recover.

Supply chain risk management per NIST CSF 2.0 + ISO 27001 + ISO 28000: Supply chain cybersecurity risks addressed through vendor assessment + SBOM + software supply chain (SLSA) + hardware supply chain (CTID).

NIST CSF 2.0 + ISO 27001:2022 + ISO 27005:2022 mapping: NIST published crosswalk between CSF 2.0 + ISO 27001:2022. ISO 27005 risk assessment aligned with ISO 27001 Annex A controls.

EU NIS2 + ISO 27001: EU NIS2 (effective October 2024) requires essential + important entities implement ISO 27001 + risk assessment per ISO 27005.

EU Cyber Resilience Act (CRA) + ISO 27001: EU CRA (effective 2025 + 2027 phased) requires digital products + connected devices comply with cybersecurity requirements. ISO 27001 + ETSI EN 303 645 + NIST CSF 2.0 alignment.

US SEC Cybersecurity Disclosure + ISO 27005: US SEC Cybersecurity Disclosure Rule (December 2023) requires public companies disclose cybersecurity risk management + governance + material incidents.

Common B2B mistakes: (1) Treating CSF 2.0 + ISO 27005 + ISO 31000 as competing (they are complementary). (2) Skipping Govern function. (3) Missing supply chain risk. (4) Not integrating with ISO 27001 ISMS. (5) Treating cyber as IT-only (it is enterprise risk).

B2B procurement workflow: (1) Identify customer risk management framework preference (CSF 2.0 / ISO 27005 / ISO 31000 / combined). (2) Verify supplier risk assessment + ISMS + ISO 27001 certification. (3) Supply chain risk assessment (SBOM + software supply chain + hardware supply chain). (4) Contract terms: incident reporting + SLAs + liability + cyber insurance. (5) Continuous monitoring + periodic audit.

B2B recommendation: For B2B protective cases for IT + OT + IoT + critical infrastructure, require NIST CSF 2.0 alignment + ISO 27001:2022 + ISO 27005 risk assessment + ISO 31000 ERM + supply chain risk management + cyber insurance + incident response + SBOM + FOB Shenzhen/Ningbo/EXW delivery 30-45 days.

Points clés

  • NIST CSF 2.0 (Feb 2024) adds Govern function + supply chain + small business guide. 6 functions + 22 categories + 106 subcategories.
  • ISO 27005:2022 information security risk management. Aligns with ISO 31000. Required for ISO 27001 + EU NIS2 + EU CRA + UK Cyber Essentials.
  • ISO 31000:2018 enterprise risk management. Principles + framework + process. Aligned with COSO ERM + Basel III + Solvency II.
  • Layered: ISO 31000 (enterprise) > ISO 27005 (info security) > NIST CSF 2.0 (operational cyber). Complementary not competing.
  • Govern function cross-cutting: top management + board oversight + risk culture + accountability.
  • Supply chain risk: SBOM + SLSA + CTID + vendor assessment. EU NIS2 + EU CRA + US SEC Cyber Disclosure alignment.
  • B2B recommendation: Require NIST CSF 2.0 + ISO 27001:2022 + ISO 27005 risk assessment + ISO 31000 ERM + supply chain + cyber insurance, FOB Shenzhen/Ningbo/EXW.

FAQ

q

a

q

a

q

a

q

a

q

a

q

a

Demander maintenant · 30-45 Day Delivery