ISM / NIST CSF cheat sheet
Not a formal mapping. A way to keep one program, two dialects.
| CSF 2.0 | ISM / AU language | What to actually do |
|---|---|---|
| Govern | Governance, risk, PSPF / ISM applicability | Name owners. Record exceptions. Accept risk in writing. |
| Identify | Asset and identity inventory, system categorisation | Know what you have and what it is worth. |
| Protect | Essential Eight, hardening, IAM, encryption | MFA, patch, admin restriction, backups, least privilege. |
| Detect | Logging, monitoring, threat intel (ACSC alerts, KEV) | Detections with an owner. Queue that is read. |
| Respond | IR plan, ACSC assist, OAIC NDB clock | First hour list. Privacy and legal in the room. |
| Recover | Backups, reconstitution, lessons | Restore test. Then change what failed. |
ISO 27001 Annex A can sit beside Protect/Detect. It does not replace Essential Eight for Australian government work.
