NIST Cybersecurity Framework (CSF)
Also known as: NIST CSF
A free US framework that sorts security work into six broad goals, from steering it to recovering after an attack.
Draft - this entry has not been reviewed yet.
Formal
A voluntary framework from the US National Institute of Standards and Technology, first published in February 2014 and updated to version 2.0 in February 2024. Version 2.0 groups outcomes into six functions - Govern, Identify, Protect, Detect, Respond and Recover - and lets a firm compare a current profile with a target profile.
In plain English
A map with six regions rather than a checklist - it shows where you are, where you want to be and which roads connect them, but not exactly how to drive.
In practice
The security lead at a Danish software company with US customers scores the firm against the six functions, finds Detect and Recover weak, and uses the gap between current and target profile to argue for next year's budget.
Why it matters
Leaders and technical staff often talk past each other about security; the framework gives them one free, shared language that suits any size of firm and maps onto ISO 27001 and the CIS Controls.
Technical deep dive
The framework originated in Executive Order 13636 (February 2013), which directed NIST to develop a voluntary framework for critical infrastructure; version 1.0 followed on 12 February 2014, the Cybersecurity Enhancement Act of 2014 gave NIST a standing mandate to maintain it, version 1.1 appeared in April 2018, and Executive Order 13800 (2017) required US federal agencies to use it. Version 2.0, published as NIST CSWP 29 on 26 February 2024, dropped the critical-infrastructure framing in its title and addresses organisations of any size or sector.
It has three components. The Core is a hierarchy of Functions, Categories and Subcategories with stable identifiers: in 2.0 there are six functions, 22 categories and 106 subcategories, compared with five functions, 23 categories and 108 subcategories in 1.1. Govern (GV) is new and contains organisational context (GV.OC), risk management strategy (GV.RM), roles, responsibilities and authorities (GV.RR), policy (GV.PO), oversight (GV.OV) and cybersecurity supply chain risk management (GV.SC); the other functions are Identify (ID), Protect (PR, including PR.AA for identity management, authentication and access control), Detect (DE), Respond (RS) and Recover (RC). Profiles describe current or target outcomes selected from the Core, including Community Profiles shared by a sector. Tiers 1-4 (Partial, Risk Informed, Repeatable, Adaptive) characterise the rigour of an organisation's governance and management practices.
Version 2.0 moved informative references and implementation examples out of the PDF into online resources, notably the Cybersecurity and Privacy Reference Tool, where the subcategories are mapped to SP 800-53 Rev. 5, the CIS Controls, ISO/IEC 27001 and other sources through the OLIR programme, and added Quick-Start Guides for small businesses and other audiences. The framework itself contains no controls to implement; it points to catalogues that do.
Two misconceptions are common. Tiers are often read as maturity levels, but NIST presents them as describing the rigour of risk governance and management, and does not require an organisation to aim for Tier 4 across the board. And there is no official certification: "CSF assessments" by consultants are self-defined evaluations. That is the main contrast with ISO/IEC 27001, which requires a management system audited by accredited bodies; in practice many organisations use the CSF functions as a reporting language for boards and the 27001 ISMS as the operating machinery, and ISO/IEC 27002 borrowed the five original function names as attribute values for its controls.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk management
- →NIST Cybersecurity Framework (CSF)
Relationships
- A kind of
- Security framework
- Requires
- Risk management
- Don't confuse with
- ISO 27000 seriesISO 27001
- Used with
- Supplier managementGap analysis
Sources & further reading
Standards & official texts
Official documentation
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…