Comparison of NIST Cybersecurity Framework Patterns and the Requirements of Federal Service For Technical and Export Control (FSTEC) Order No. 31: Compliance Matrices and Integration Methodology
This study focuses on two of the most significant documents in the field of information security: the international standard NIST Cybersecurity Framework version 2.0 and the Russian regulatory act, FSTEC Order No. 31. The subject of the study is the conceptual and structural relationships between the NIST CSF functions and the groups of information security measures established by Order No. 31. The methodological basis consists of a comparative analysis of the original texts of the documents, Positive Technologies comparison tables, and the TOGAF architectural design methodology. The study resulted in the development of a correspondence matrix comparing 17 groups of measures from Order No. 31 with six functions of the NIST CSF 2.0 core. It was found that coverage of CSF functions by the Order's measures varies from 40-60% for class K3 to 95-100% for class K1, while the Govern function has no direct equivalent in the Russian document. A gap analysis methodology is proposed, allowing organizations to identify missing security measures when integrating the two approaches. Practical recommendations for prioritizing protective measures based on a risk-based approach have been developed. The results can be used in designing information security architectures for organizations working with critical information infrastructure and government information systems.
Authors
- Алена Яковлева
Institutions
- Peter the Great St. Petersburg Polytechnic University (RU)
Publication Details
- Journal
- Technoeconomics & Management Research
- Published
- 2026-09-28
- DOI
- https://doi.org/10.57809/2026.5.2.17.4
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00