NIST CSF 2.0ISO/IEC 27001:2022

CSF 2.0 ID.AM-04 → ISO/IEC 27001:2022

1 mapped control · identifier-only informative reference · Identify function · one implementation can answer several obligations at once.

ISO/IEC 27001:2022RelationshipSource tier
A.5.22relatedTier A2

What evidence answers both

Assessors working from either framework ask for the same thing against ID.AM-04: inventory and assessment artifacts - asset and data registers with owners and dates, risk assessment output, vendor and dependency lists, and the criticality ratings that justify scope decisions. An ISO/IEC 27001 auditor works outward from your Statement of Applicability, so the artifact has to be traceable to the Annex A control you claimed - the mapping tells you which claim your evidence already serves. Keeping one dated evidence register per control means a single artifact answers both frameworks instead of being produced twice.

AxiomLensStop redoing this mapping by hand.
AxiomLens is a GRC command deck you own outright. One-time license, per user — activate once, then it runs fully offline on your machine: your own database, 106 CSF 2.0 subcategories, computed coverage, evidence tied to controls, and board reports generated locally. It supports compliance documentation and audit-preparation workflows — it is a tool, not a certification or an assessment.

See AxiomLens →  ·  2-minute demo
Bayou Bytes
One email each Tuesday: the week’s threats that matter, one copy-paste hardening step, and the script to explain it to a non-technical stakeholder. Free, no pitch.
The Security Gator
© The Security Gator LLC · These mappings are informative references and a practical starting point — not a compliance determination, audit opinion, or legal advice. Mapping strength varies by environment; review and adapt every mapping to your organization and obligations with a qualified professional. · Source: NIST CSF 2.0 Informative References (CPRT/OLIR). Identifiers only — no copyrighted standard text is reproduced. Framework names and control identifiers are the property of their respective owners. · thesecuritygator.com