What is NIST CSF?
The NIST Cybersecurity Framework (CSF) 2.0 provides a comprehensive approach to managing cybersecurity risks. Explore the six core functions that help organizations establish, communicate, and monitor their cybersecurity strategy.
The strategy layer that steers everything else. Covers risk management policy, roles and responsibilities, oversight, and how cybersecurity fits into wider enterprise risk decisions.
Knowing what you have and what could hurt it. Covers your assets, data, suppliers and their risks, so effort goes where it matters most.
The safeguards that stop bad things happening in the first place. Covers identity and access control, staff training, data security, platform hardening and infrastructure resilience.
Spotting attacks and compromises quickly. Covers monitoring for anomalies and indicators of compromise, and analysing them fast enough for response to succeed.
What happens once an incident is found. Covers containment, incident management, analysis, mitigation, and reporting to the people who need to know.
Getting back to normal after an incident. Covers restoring affected systems and operations, and communicating clearly while you do it.
What you need to know
It's created by the National Institute of Standards and Technology (NIST)
NIST (National Institute of Standards and Technology) is a US federal agency that develops technical standards across industries. They're non-regulatory, meaning they don't enforce compliance, but their frameworks become industry benchmarks through collaboration with private sector experts. The Cybersecurity Framework is one of their most widely adopted standards globally.
Designed to Help Organizations Manage Cyber Risk
The CSF helps organizations understand, assess, and communicate about cybersecurity risks in a structured way. It provides a common language that bridges technical teams and business leadership, making security discussions more strategic. Unlike prescriptive checklists, it focuses on outcomes you want to achieve rather than specific technologies or controls you must implement.
Proven Framework in Use Since 2014
Originally released in 2014 following a presidential Executive Order, the CSF was created to help critical infrastructure organizations improve their cybersecurity posture. It quickly gained adoption far beyond its original scope because of its practical, flexible approach. Organizations worldwide now use it across virtually every industry and sector.
Complements SOC 2 and ISO 27001 Standards
While SOC 2 and ISO 27001 are formal certification standards with specific control requirements, the CSF is a voluntary risk management framework focused on outcomes. Think of it as less prescriptive - it doesn't tell you exactly what controls to implement. Many organizations use the CSF alongside these standards, as it provides a strategic overlay that maps well to their specific requirements.
Version 2.0 Released February 2024
NIST released CSF 2.0 in February 2024 after extensive industry consultation. The update adds a sixth "Govern" function emphasizing cybersecurity as a strategic business issue, includes concrete implementation examples, and expands focus on supply chain security. It also broadens the framework's scope to explicitly serve organizations of all sizes, not just critical infrastructure.
Organized Around Six Core Functions
The framework centers on six high-level Functions: Govern, Identify, Protect, Detect, Respond, and Recover. Each Function breaks down into Categories and then detailed Subcategories that describe specific cybersecurity outcomes. Organizations assess their current state against these outcomes, define their target state, and create action plans to close the gaps based on their unique risks and resources.