Comparison of NIST Cybersecurity Framework Patterns and the Requirements of Federal Service For Technical and Export Control (FSTEC) Order No. 31: Compliance Matrices and Integration Methodology

Authors:
Abstract:

This study focuses on two of the most significant documents in the field of information security: the international standard NIST Cybersecurity Framework version 2.0 and the Russian regulatory act, FSTEC Order No. 31. The subject of the study is the conceptual and structural relationships between the NIST CSF functions and the groups of information security measures established by Order No. 31. The methodological basis consists of a comparative analysis of the original texts of the documents, Positive Technologies comparison tables, and the TOGAF architectural design methodology. The study resulted in the development of a correspondence matrix comparing 17 groups of measures from Order No. 31 with six functions of the NIST CSF 2.0 core. It was found that coverage of CSF functions by the Order's measures varies from 40−60% for class K3 to 95−100% for class K1, while the Govern function has no direct equivalent in the Russian document. A gap analysis methodology is proposed, allowing organizations to identify missing security measures when integrating the two approaches. Practical recommendations for prioritizing protective measures based on a risk-based approach have been developed. The results can be used in designing information security architectures for organizations working with critical information infrastructure and government information systems.

  • References

    ARPP Soft. N.d. A case study on implementing automated process control system protection at Severstal facilities. URL: https://arppsoft.ru/ (accessed: 13.02.2026).
    Australian Signals Directorate. 2024. Essential Eight Maturity Model. URL: https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight (accessed: 13.02.2026).
    Brock J., Brennig K., Lohr B., Bartelheimer C., von Enzberg S. 2024. Improving Process Mining Maturity — From Intentions to Actions. Business & Information Systems Engineering. DOI: 10.1007/s12599-024-00882-7.
    Center for Internet Security. 2024. CIS Controls Version 8.1. URL: https://www.cisecurity.org/controls (accessed: 13.02.2026).
    FSTEC of Russia. 2014. Order No. 31 of March 14, 2014, "On Approval of Requirements for Ensuring Information Security in Automated Control Systems for Production and Technological Processes at Critical Facilities, Potentially Hazardous Facilities, and Facilities Posing an Increased Danger to Human Life and Health and the Environment" (as amended on March 23, 2017, August 9, 2018, and March 15, 2021). URL: https://fstec.ru/dokumenty/vse-dokumenty/prikazy/prikaz-fstek-rossii-ot-14-marta-2014-g-31 (accessed: 13.02.2026).
    Gartner. 2024. Hype Cycle for Security Operations, 2024. URL: https://www.gartner.com (accessed: 13.02.2026).
    Gordon L.A., Loeb M.P., Lucyshyn W., Zhou L. 2023. The impact of information sharing on cybersecurity underinvestment: A real options perspective. Journal of Accounting and Public Policy 42 (3), 107-125. DOI: 10.1016/j.jaccpubpol.2023.107125.
    Henshel D., Sample C., Cains M.G. 2024. A survey of cybersecurity standards for critical infrastructure protection. IEEE Access 12, 33456-33478. DOI: 10.1109/ACCESS.2024.3378921.
    IBM Corporation. 2024. Cost of a Data Breach Report 2024 URL: https://www.ibm.com/reports/data-breach (accessed: 13.02.2026).
    INNER. 2025. Cybersecurity Standards Comparison Chart: IEC 62443 vs NIST CSF 2.0. URL: https://inner.su/articles/tablitsa-standartov-kiberbezopasnosti-iec-62443-vs-nist-csf-2-0-sootvetstvie/ (accessed: 13.02.2026).
    iTPROTECT. N.d. Industrial Vulnerability Management Project. URL: https://itprotect.ru/projects/upravleniye-uyazvimostyami.proj (accessed: 13.02.2026).
    Ivanov D., Sokolov B. 2024. Cyber-physical systems resilience: State-of-the-art and future challenges. International Journal of Production Research 62 (8), 2845-2864. DOI: 10.1080/00207543.2023.2292441.
    Jet CSIRT. 2025. Research into the protection of industrial control systems from targeted attacks. URL: https://jetcsirt.su/upload/2025_Исследование_Защита_АСУ_ТП.pdf (accessed: 13.02.2026).
    Johnson M.E., Goetz E. 2025. Security standards alignment for critical infrastructure protection. IEEE Security & Privacy 23 (1), 56-68. DOI: 10.1109/MSEC.2024.3489217.
    Kitsios F., Chatzidimitriou E., Kamariotou M. 2024. Developing a risk-based strategic cybersecurity framework for digital transformation. International Journal of Information Management 75, 102-118. DOI: 10.1016/j.ijinfomgt.2023.102118.
    Lukatsky A. 2019. What can be borrowed from the NIST CSF for the development of FSTEC orders? URL: https://www.securitylab.ru/blog/personal/Business_without_danger/156177.php (accessed: 13.02.2026).
    NIST. 2020. NIST Special Publication 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations. URL: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final (accessed: 13.02.2026).
    NIST. 2024. NIST Cybersecurity Framework 2.0. URL: https://www.nist.gov/cyberframework (accessed: 13.02.2026).
    Positive Technologies. 2012. Comparison of the requirements of the FSTEC order of March 14, 2014 No. 31 with the requirements of international standards (NERC CIP, ISA/IEC 62443,
    NIST SP 800-82, NIST SP 800-53). URL: https://static.ptsecurity.com/uploads/files/pt_isim_comparison_of_fstec_requirements_with_international_standards_c5a982acfe.pdf (accessed: 13.02.2026).
    Schmitt M., Schafer C., Weber C. 2025. Integration of security standards in enterprise architectures: A systematic literature review. Computers & Security 148, 104-122. DOI: 10.1016/j.cose.2024.104122.
    SECURITM. N.d. Comparison of NIST CSF 2.0 and FSTEC Order No. 31. URL: https://service.securitm.ru/help/compliance (accessed: 13.02.2026).
    Shackelford S.J. 2023. The NIST Cybersecurity Framework and the evolution of cyber risk governance. Berkeley Business Law Journal 20 (1), 45-78. DOI: 10.15779/Z38G737H0B.
    Van Looy A. 2021. Business Process Maturity: A Comparative Study on a Sample of Business Process Maturity Models. Cham: Springer. DOI: 10.1007/978-3-319-04202-2.

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License
Previous articleNext article