Genius Multidisciplinary International Journal
ISSN: 2971-7760  |  Vol. 6, No. 3

Comparative Analysis of Cybersecurity Frameworks (NIST, ISO/IEC 27001) in Supporting Enterprise Risk Management Objectives

Sulaiman Sani

Abstract

The increasing frequency and sophistication of cyber threats have elevated cybersecurity from a purely technical function to a strategic organizational priority. Consequently, organizations increasingly integrate cybersecurity governance into Enterprise Risk Management (ERM) frameworks to enhance resilience, ensure regulatory compliance, and achieve organizational objectives. Among the most widely adopted cybersecurity frameworks are the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF 2.0) and the International Organization for Standardization's ISO/IEC 27001:2022 Information Security Management System (ISMS). This study comparatively analyses the extent to which these frameworks support Enterprise Risk Management objectives. Adopting a qualitative comparative research design based on doctrinal and systematic literature analysis, the study examines the governance structures, risk management approaches, implementation mechanisms, regulatory alignment, and organizational applicability of both frameworks. The analysis demonstrates that while NIST CSF 2.0 provides a flexible, risk-based framework emphasizing governance, cyber resilience, and continuous improvement, ISO/IEC 27001:2022 offers a structured and certifiable management system that strengthens information security governance through standardized controls and continual performance evaluation. The study further reveals that neither framework independently addresses all dimensions of enterprise risk management; however, their complementary implementation significantly enhances strategic decision-making, operational resilience, regulatory compliance, and organizational sustainability. The paper concludes that organizations seeking comprehensive cyber risk governance should adopt an integrated implementation strategy that leverages the flexibility of NIST CSF 2.0 alongside the structured management processes of ISO/IEC 27001:2022 to achieve broader Enterprise Risk Management objectives.

DOI: https://doi.org/10.5281/zenodo.21770424

Published: August 3, 2026

Journal: Genius Multidisciplinary International Journal

ISSN: 2971-7760

Volume: 6, Issue 3

Publisher: Genius Academy — Nasarawa State University, Keffi, Nigeria