Leanpub Header

Skip to main content

Dual Compliance

Cybersecurity under NIST CSF 2.0 and ISO/IEC 27001

Dual Compliance

Excerpt 1 — Chapter 1, "Introduction": why cybersecurity management is not about technology

The simplest way to manage an organization's cybersecurity is to draw up a list of technical measures ("install antivirus software," "enable multi-factor authentication," "encrypt disks") and carry them out one by one. This approach has an obvious advantage — simplicity — but also a systemic flaw: it does not answer the question of which measures this particular organization actually needs, to what extent, and what to do when there are not enough resources for "the whole list." It also creates a false sense of completeness: "we implemented everything on the list — so we are secure," even though the real level of risk depends not on the length of the list but on how well the measures match the specific threats and the value of the organization's assets.

Excerpt 2 — Chapter 1: cyber risk within enterprise risk management

If cybersecurity is about managing risk rather than a checklist of technical measures, the logical continuation of this idea is as follows: cyber risk is not a separate, isolated category discussed only by the IT department in its own language. It is one of the types of risk that any enterprise faces — alongside financial, reputational, operational, and supply chain risk. It should be managed within the same frame of reference as other enterprise risks.

Excerpt 3 — Chapter 14, applying the Chapter 10 mapping methodology: where a mapping gap becomes a technical project

The last row is the central conclusion of this step, and of the whole case study: the mapping table shows honestly that no Annex A control exists for PR.AA-04 that can simply be marked "done" and the gap considered closed. An organization relying only on the SoA, or only on the mapping table, could mistakenly conclude that because A.5.17 partially covers the topic, no further action is needed — which is exactly why the gap analysis, the SoA, and the risk register above all consistently define SSO as a separate, explicit technical project, rather than a derivative action from existing controls.

Excerpt 4 — Chapter 14, closing paragraph of the book

The running case study in this chapter has shown that the fifth step of the Chapter 7 methodology — "the organization can repeat these steps as often as needed" — is not a rhetorical flourish but a real operating cycle: MFA for contractors, backup encryption, and automatic deactivation in the ERP, each opened by a separate cycle in Chapters 6–7 and 13, were already closed and verified by the time this chapter began, and the very fact of their closure — through broadening the profiling scope to identity management across the ERP and CRM together — opened up a new, precisely formulated gap, PR.AA-04, reflected consistently and at once in the updated profile, the action plan, the SoA, the risk register, and the mapping table. It is precisely this consistency among five tools converging on a single decision, not the mere existence of each tool on its own, that is the practical upshot of building an integrated cybersecurity management system.

Minimum price

$19.99

$24.99

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
About

About

About the Book

Overview

Organizations worldwide increasingly face a dual cybersecurity demand: customers and partners require ISO/IEC 27001 certification, while boards of directors and regulators increasingly expect risk to be reported in the language of the NIST Cybersecurity Framework (CSF) 2.0. Leadership teams have to satisfy both requirements at once, and the most common management mistake is to run them as two parallel, poorly aligned projects instead of one coherent program. Dual Compliance answers this problem directly: rather than asking an organization to choose between frameworks, it shows that both describe, in essence, one and the same cyber-risk management program in two complementary languages — NIST CSF in the language of desired outcomes, ISO/IEC 27001 in the language of a formal, certifiable management system — and walks the reader through both in sequence, so that what emerges is one working system rather than two disconnected sets of documents.

The book takes the reader chapter by chapter through a single, consistent build: from risk-based cybersecurity management and the GOVERN function, through all six Core Functions of NIST CSF (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER), Organizational Profiles and Tiers, to the architecture of an ISO/IEC 27001 information security management system and a detailed methodology for mapping the two standards to each other. A running case study — a mid-sized online retailer of consumer electronics, InterShop — accompanies the reader from roughly a third of the way through the book to its final chapter, turning the requirements of both standards into concrete, fully worked working documents for a single organization.

What the Book Covers

The book is organized into five parts and fourteen chapters.

Part I. Foundations of Risk-Based Cybersecurity Management (Chapters 1–3) establishes a shared vocabulary: why cybersecurity management is a management discipline rather than a purely technical one, an overview of the structure of NIST CSF 2.0, and the GOVERN function as the cross-cutting foundation shared by both frameworks.

Part II. The CSF Core in Practice (Chapters 4–7) works sequentially through the IDENTIFY, PROTECT, and DETECT/RESPOND/RECOVER functions, along with Organizational Profiles and Tiers as tools for gap analysis and maturity assessment.

Part III. ISO/IEC 27001 and Risk Management (Chapters 8–10) turns to the formal, certifiable information security management system (ISMS): the standard's harmonized structure, information security risk assessment and treatment, and a detailed methodology for mapping between the two frameworks.

Part IV. Operational Maturity (Chapters 11–13) details an organization's day-to-day practice: supplier and supply chain risk management, policies, documentation and personnel awareness, and internal audit and continual improvement.

Part V. Running Case Study and Synthesis (Chapter 14) brings all preceding chapters together into one integrated cybersecurity management system built around InterShop, and closes the book.

Audience

GRC professionals, managers and implementers of information security management systems (ISMS), security leads and current or aspiring CISOs, IT executives, and compliance consultants. No technical background is required.

What Sets This Book Apart

  • Both frameworks together, not "either/or." Most existing material treats NIST CSF and ISO/IEC 27001 as competing options to choose between. This book consistently shows how to build a single system and describe its results in the language of both standards, including a detailed mapping methodology (Chapter 10) with a mapping table narrowed to a specific worked example (Chapter 10) and then applied to the running case study (Chapter 14).
  • A running case study, not scattered examples. The organization InterShop runs through eight chapters (Chapters 4–14), accumulating a risk register, a Statement of Applicability, a supplier assessment, an access control policy, and an internal audit record — all documents interlinked around a single organization, the way they are in practice.
  • A practical, not a summarizing, treatment of ISO/IEC 27001. The book never reproduces the text of this commercial standard verbatim or in close paraphrase — every clause and Annex A control is explained in the author's own original words, with the author's own examples and illustrative cases, giving readers a practical understanding of the requirements without infringing the standard publisher's copyright.
  • Terminology aligned with the official NIST source text, unified in a single glossary. All NIST CSF terminology is checked against the official English text of NIST CSWP 29, and both frameworks' terms are consolidated into a single alphabetical glossary at the end of the book.

Author

About the Author

Andrii Bogdanovych

Andrii BOGDANOVYCH combines senior public-service management experience with engineering expertise in artificial intelligence — a combination rare in the Ukrainian market, and one that directly shapes this book's approach: discussing AI governance in language equally accessible to public-sector officials, corporate boards, and technical teams.

Deputy Head for Digital Development, Digital Transformation, and Digitalization (CDTO) of the State Energy Supervision Inspectorate of Ukraine (since 2022); he previously held the equivalent position at the State Ecological Inspectorate of Ukraine, and the position of Deputy Head of the Kherson Regional State Administration — in both roles leading digitalization, cybersecurity, and critical-infrastructure protection efforts, respectively at the level of a central executive authority and at the regional level.

He is the author of four training programs: "AI Management and Governance in the Organization: NIST AI RMF 1.0 and ISO/IEC 42001," data governance for executives, data governance for technical practitioners, and building organizational cybersecurity under NIST CSF 2.0 and ISO/IEC 27001.

A practicing Python/AI developer, he designs RAG systems and autonomous agentic solutions built on LLM APIs, publishes and maintains open-source libraries on PyPI, and administers his own server infrastructure. He holds a Master's degree in Public Administration (Taras Shevchenko National University of Kyiv), a Master's degree in Law (Academy of Advocacy of Ukraine), and a Bachelor's degree in Computer Science (Vadym Hetman Kyiv National Economic University).

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub