How do CIS benchmarks map to ISO 27001?
More context
The 2022 revision of ISO/IEC 27001 restructured Annex A into four themes: organizational, people, physical, and technological controls. Configuration benchmarks map most cleanly onto the technological theme (A.8), which covers things like access enforcement, logging, secure configuration, and cryptography. People controls in A.6, such as security awareness and disciplinary process, are inherently procedural and cannot be evidenced by scanning a machine.
For an ISO 27001 certification effort, the useful outcome is knowing which Annex A controls the technical estate already substantiates and which ones still need documented policy or process evidence. A Framework Coverage Report that certification auditors recognize lets an information security manager attach automated configuration evidence directly to the Statement of Applicability instead of assembling screenshots per control.