The broad catalog and the deep one
NIST 800-53 covers each weakness family more completely than ISO 27002, with five times the controls. ISO reaches about as wide with a fifth as many. Breadth and depth, not better. Last updated: 2026-08-22
Two of the most widely adopted control frameworks are built at different grain. NIST 800-53 has 421 controls, more than five thousand counting enhancements. ISO 27002 has 93. On the coverage map that grain shows, and it shows the opposite of what the control count suggests. ISO's 93 broad controls reach about as many weakness families as 800-53 does, with a fifth of the controls. But 800-53 covers each family it touches far more completely. Breadth and depth. Neither is better.
Coverage is our own direct mapping of each framework to the CWE weaknesses, graded for how completely each control addresses each one. Breadth is how many weaknesses a framework reaches at all; depth is how completely it covers them.
Why the smaller catalog reaches wide but shallow
ISO's controls are broad. A single ISO control like "access control" or "information security in supplier relationships" spans a whole area, so a catalog of 93 touches a lot of ground with very little overhead. But a broad control only ever partially addresses any one specific weakness, and the grades bear that out: 73% of ISO's weakness coverage lands at partial. 800-53 splits the same ground into dozens of specific controls, so it can name the exact control for a given weakness and cover it completely. 64% of its coverage is mostly or full. That is the trade the control count hides. It is not 800-53 being weaker; it is 800-53 being able to name the exact control that addresses a specific weakness, which a broad ISO control cannot.
So the choice is not which framework is more complete. It is what you need from it. Adopt ISO when you want a broad baseline you can implement and certify against with a manageable number of controls. Reach for 800-53 when a specific weakness dominates your risk and you need to point at the specific control that addresses it. Graded honestly, this is an observation from our mapping data; the grain difference is a fact about the two catalogs.
By lane
- Lean IT. 93 controls is a program you can actually run. 421 is not, without a security team. ISO first; borrow specific 800-53 controls where a particular weakness matters.
- Security leader. If your risk is concentrated (say, a specific class of software defect), 800-53's depth lets you fund the exact control instead of a broad theme.