Can ISO 27001 and NIST coexist?
Yes, of course. There are many points in common between those frameworks.
As an example of common things between frameworks, here’s a mapping between ISO 27001 and NIST SP 800:
ISO/IEC 27001 (Annex A) CONTROLS |
NIST SP 800-53 controls |
A.5 Security policy |
|
A.5.1 Information security policy |
|
A.5.1.1 Information security policy document |
XX-1 controls |
A.5.1.2 Review of the information security policy |
XX-1 controls |
A.6 Organization of information security |
|
A.6.1 Internal |
|
A.6.1.1 Management commitment to information security |
XX-1 controls, PM-2; SP... |