2026-09-21 · KeXinMaterials 編集チーム
NIST CSF 2.0 + ISO 27005 + ISO 31000 Cybersecurity Risk Management Family Protective Case B2B Guide
NIST CSF 2.0 (February 2024) + ISO 27005 (information security risk) + ISO 31000 (enterprise risk management, ERM) are the three foundational risk + cybersecurity frameworks. IT + OT + IoT + critical infrastructure required.
NIST Cybersecurity Framework 2.0 (CSF 2.0)
NIST Cybersecurity Framework 2.0 (February 2024) expands the original CSF 1.1 (2018) with the Govern function + supply chain + small business quick-start guide + mapping to NIST RMF + ISO 27001.
NIST CSF 2.0 release: February 26, 2024. Replaces CSF 1.1 (2018). Adds Govern function + enhances supply chain risk management + adds small business quick-start guide.
CSF 2.0 structure: 6 functions (Govern + Identify + Protect + Detect + Respond + Recover) + 22 categories + 106 subcategories. Previously 5 functions in CSF 1.1.
Govern function (NEW in CSF 2.0): Organizational context + risk management strategy + roles + responsibilities + policies + processes + oversight. Cross-cutting across all other functions.
Identify function: Asset management + business environment + governance + risk assessment + risk management strategy + supply chain risk management.
Protect function: Identity management + authentication + access control + awareness + training + data security + information protection processes + maintenance + protective technology.
Detect function: Anomalies + events + continuous monitoring + detection processes.
Respond function: Response planning + communications + analysis + mitigation + improvements.
Recover function: Recovery planning + improvements + communications.
CSF 2.0 tiers: Partial (Tier 1) + Risk-Informed (Tier 2) + Repeatable (Tier 3) + Adaptive (Tier 4). Organizational risk management maturity.
CSF 2.0 profiles: Customized implementation of CSF based on use case + sector + risk profile. Quick-Start Guide for Small Businesses included.
CSF 2.0 + NIST RMF mapping: CSF subcategories mapped to NIST RMF (SP 800-37 Rev 2) steps. CSF 2.0 implementation can serve as operational layer for RMF.
CSF 2.0 + ISO 27001 mapping: CSF categories/subcategories mapped to ISO 27001:2022 Annex A controls. Cross-walk published by NIST.
Geographic adoption: US federal agencies (mandatory per Executive Order 14028 May 2021). Voluntary globally. US critical infrastructure (16 sectors).
B2B relevance: For B2B protective cases containing IT + OT + IoT + edge computing equipment, NIST CSF 2.0 alignment increasingly required for US federal + critical infrastructure procurement.
ISO 27005 Information Security Risk Management
ISO/IEC 27005:2022 "Information security, cybersecurity and privacy protection - Guidance on managing information security risks". Edition 4 (2022). Aligns with ISO 31000:2018.
ISO/IEC 27005:2022: "Information security, cybersecurity and privacy protection - Guidance on managing information security risks". Edition 4 (2022). Replaces ISO/IEC 27005:2018.
ISO 27005 scope: Information security risk management for organizations. Aligns with ISO 31000 risk principles + ISO/IEC 27001 ISMS.
ISO 27005 process: Context establishment + risk identification + risk analysis + risk evaluation + risk treatment + risk acceptance + risk communication + risk monitoring + review.
Context establishment: Per ISO 27005 clause 6. Define scope + boundaries + risk criteria + impact criteria + risk acceptance criteria. Align with ISO 27001 ISMS scope.
Risk identification: Per ISO 27005 clause 8. Identify information security risks (asset-based + threat-based + event-based + vulnerability-based). Use ISO 27002 controls + ISO 27017 + ISO 27018 + ISO 27701.
Risk analysis: Per ISO 27005 clause 9. Assess likelihood + consequences (impact). Qualitative + quantitative + semi-quantitative methods. Risk = Likelihood x Impact.
Risk evaluation: Per ISO 27005 clause 10. Compare risk estimates against risk criteria. Prioritize risks for treatment.
Risk treatment: Per ISO 27005 clause 11. Options: (1) Modify (apply controls). (2) Avoid (remove risk source). (3) Share (transfer via insurance / outsourcing). (4) Accept (retain with informed decision).
Risk acceptance: Per ISO 27005 clause 12. Formal acceptance by risk owner. Document in Statement of Applicability (SoA) per ISO 27001.
Risk communication: Per ISO 27005 clause 13. Internal + external communication of risk information. Stakeholder engagement.
Risk monitoring + review: Per ISO 27005 clause 14. Continuous monitoring + periodic review. Update risk assessment based on changes.
ISO 27005 + ISO 27001: ISO 27005 risk assessment feeds ISO 27001 ISMS risk treatment plan + Statement of Applicability.
ISO 27005 + ISO 27002: ISO 27002:2022 Annex A controls (93 controls in 4 themes: organizational + people + physical + technological) referenced in ISO 27005 risk treatment.
Geographic adoption: Adopted as ISO/IEC 27005:2022 (international). Required for ISO 27001 certification. Required for EU NIS2 + EU CRA + UK Cyber Essentials + Singapore MAS TRM.
B2B relevance: For B2B protective cases containing sensitive information (financial + medical + defense + IP), ISO 27005 risk assessment + ISO 27001 ISMS aligned procurement required.
ISO 31000 Enterprise Risk Management (ERM)
ISO 31000:2018 "Risk management - Guidelines". Edition 2 (2018). Provides principles + framework + process for enterprise risk management (ERM) at organizational level.
ISO 31000:2018: "Risk management - Guidelines". Edition 2 (2018). Replaces ISO 31000:2009. Aligns with ISO 27005:2022 + ISO 9001:2015 + ISO 14001:2015.
ISO 31000 scope: All organizations regardless of size + sector. Provides risk management principles + framework + process.
ISO 31000 principles: (1) Integrated. (2) Structured + comprehensive. (3) Customized. (4) Inclusive. (5) Dynamic. (6) Best available information. (7) Human + cultural factors. (8) Continual improvement.
ISO 31000 framework: Leadership + commitment (top management + governance + risk culture + accountability). Integration (strategy + decision-making + processes). Implementation (plans + resources + accountability). Evaluation (effectiveness measurement). Improvement (learning + adjustment).
ISO 31000 process: Communication + consultation (internal + external stakeholders). Scope + context + criteria. Risk assessment (identification + analysis + evaluation). Risk treatment (selection + implementation). Monitoring + review. Recording + reporting.
ISO 31000 vs ISO 27005: ISO 31000 is enterprise-wide (all risks). ISO 27005 is information security specific. ISO 27005 conforms to ISO 31000 principles + framework + process.
ISO 31000 vs COSO ERM: COSO ERM 2017 (US) + ISO 31000:2018 (international) are similar. COSO focuses on financial + strategic risks. ISO 31000 broader.
ISO 31000 risk appetite + tolerance: Top management defines risk appetite (overall level) + risk tolerance (acceptable variation around objectives).
ISO 31000 risk culture: Organizational values + behaviors + understanding of risk. Influences how risks identified, treated, communicated.
ISO 31000 + ISO 9001:2015: ISO 9001:2015 quality management uses ISO 31000 risk-based thinking (clause 6.1). Risk + opportunity identification.
ISO 31000 + ISO 14001:2015: ISO 14001:2015 environmental management uses ISO 31000 risk + opportunity identification. Environmental aspects + impacts.
ISO 31000 governance: Board + top management oversight of risk management. Integration with strategic decision-making + operations.
Geographic adoption: Adopted as ISO 31000:2018 (international). Voluntary. Aligned with COSO ERM + Basel III + Solvency II + UK ORSA + AU CPS 220.
B2B relevance: For B2B procurement of complex protective cases (defense + aerospace + nuclear + medical + financial), ISO 31000 ERM framework demonstrates organizational risk maturity.
NIST CSF 2.0 + ISO 27005 + ISO 31000 Combined + Supply Chain
Combined application of NIST CSF 2.0 + ISO 27005 + ISO 31000 + supply chain risk management + B2B procurement workflow.
Combined framework: NIST CSF 2.0 (operational cyber) + ISO 27005 (information security risk) + ISO 31000 (enterprise risk). Each layer provides specific value.
Layer 1 — ISO 31000 enterprise risk: Top management sets risk appetite + tolerance + culture. Strategic risk integration.
Layer 2 — ISO 27005 information security risk: Information security risks identified + analyzed + treated within ISMS. Feeds into ERM.
Layer 3 — NIST CSF 2.0 operational cybersecurity: Operational cybersecurity controls mapped to Govern + Identify + Protect + Detect + Respond + Recover.
Supply chain risk management per NIST CSF 2.0 + ISO 27001 + ISO 28000: Supply chain cybersecurity risks addressed through vendor assessment + SBOM + software supply chain (SLSA) + hardware supply chain (CTID).
NIST CSF 2.0 + ISO 27001:2022 + ISO 27005:2022 mapping: NIST published crosswalk between CSF 2.0 + ISO 27001:2022. ISO 27005 risk assessment aligned with ISO 27001 Annex A controls.
EU NIS2 + ISO 27001: EU NIS2 (effective October 2024) requires essential + important entities implement ISO 27001 + risk assessment per ISO 27005.
EU Cyber Resilience Act (CRA) + ISO 27001: EU CRA (effective 2025 + 2027 phased) requires digital products + connected devices comply with cybersecurity requirements. ISO 27001 + ETSI EN 303 645 + NIST CSF 2.0 alignment.
US SEC Cybersecurity Disclosure + ISO 27005: US SEC Cybersecurity Disclosure Rule (December 2023) requires public companies disclose cybersecurity risk management + governance + material incidents.
Common B2B mistakes: (1) Treating CSF 2.0 + ISO 27005 + ISO 31000 as competing (they are complementary). (2) Skipping Govern function. (3) Missing supply chain risk. (4) Not integrating with ISO 27001 ISMS. (5) Treating cyber as IT-only (it is enterprise risk).
B2B procurement workflow: (1) Identify customer risk management framework preference (CSF 2.0 / ISO 27005 / ISO 31000 / combined). (2) Verify supplier risk assessment + ISMS + ISO 27001 certification. (3) Supply chain risk assessment (SBOM + software supply chain + hardware supply chain). (4) Contract terms: incident reporting + SLAs + liability + cyber insurance. (5) Continuous monitoring + periodic audit.
B2B recommendation: For B2B protective cases for IT + OT + IoT + critical infrastructure, require NIST CSF 2.0 alignment + ISO 27001:2022 + ISO 27005 risk assessment + ISO 31000 ERM + supply chain risk management + cyber insurance + incident response + SBOM + FOB Shenzhen/Ningbo/EXW delivery 30-45 days.
重要なポイント
- NIST CSF 2.0 (Feb 2024) adds Govern function + supply chain + small business guide. 6 functions + 22 categories + 106 subcategories.
- ISO 27005:2022 information security risk management. Aligns with ISO 31000. Required for ISO 27001 + EU NIS2 + EU CRA + UK Cyber Essentials.
- ISO 31000:2018 enterprise risk management. Principles + framework + process. Aligned with COSO ERM + Basel III + Solvency II.
- Layered: ISO 31000 (enterprise) > ISO 27005 (info security) > NIST CSF 2.0 (operational cyber). Complementary not competing.
- Govern function cross-cutting: top management + board oversight + risk culture + accountability.
- Supply chain risk: SBOM + SLSA + CTID + vendor assessment. EU NIS2 + EU CRA + US SEC Cyber Disclosure alignment.
- B2B recommendation: Require NIST CSF 2.0 + ISO 27001:2022 + ISO 27005 risk assessment + ISO 31000 ERM + supply chain + cyber insurance, FOB Shenzhen/Ningbo/EXW.
よくある質問
q
a
q
a
q
a
q
a
q
a
q
a
関連記事
- IEC 62443 NIS2 EU CRA Industrial Cybersecurity + Protective Case B2B Guide
- ISO 42001 AI Management System + NIST AI RMF + Protective Case B2B Guide
- ISO 20243 + SOC 2 + HIPAA Supply Chain Privacy Data Family + Protective Case B2B Guide
- NIST CSF 2.0 + ISO 27005 + ISO 31000 Cybersecurity Risk Management + Protective Case B2B Guide