Tools / mapping

ISM / NIST CSF cheat sheet

Not a formal mapping. A way to keep one program, two dialects.

CSF 2.0ISM / AU languageWhat to actually do
GovernGovernance, risk, PSPF / ISM applicabilityName owners. Record exceptions. Accept risk in writing.
IdentifyAsset and identity inventory, system categorisationKnow what you have and what it is worth.
ProtectEssential Eight, hardening, IAM, encryptionMFA, patch, admin restriction, backups, least privilege.
DetectLogging, monitoring, threat intel (ACSC alerts, KEV)Detections with an owner. Queue that is read.
RespondIR plan, ACSC assist, OAIC NDB clockFirst hour list. Privacy and legal in the room.
RecoverBackups, reconstitution, lessonsRestore test. Then change what failed.

ISO 27001 Annex A can sit beside Protect/Detect. It does not replace Essential Eight for Australian government work.