DefinitionThe NIST CSF (Cybersecurity Framework) is a voluntary framework from NIST, the US standards institute, for organizing and improving cybersecurity risk management. Version 2.0, published in February 2024, structures the expected outcomes into six functions.
The six functions
The CSF describes security outcomes to achieve, without mandating technologies. In version 2.0, they are organized into six functions:
- Govern: strategy, roles, risk appetite, policies and supply chain risk management. This is the function added in 2.0.
- Identify: understand assets, context and risks.
- Protect: safeguards such as access control, awareness and data protection.
- Detect: find and analyze possible attacks and compromises.
- Respond: take action on a detected incident.
- Recover: restore affected assets and operations.
Created in 2014 with a focus on US critical infrastructure, the framework in version 2.0 explicitly addresses organizations of any size and sector.
Profiles and Tiers
Profiles describe the organization's current and target state; the gap between them becomes the action plan. Tiers, from Partial to Adaptive, indicate the rigor of risk management practices and do not need to be the highest for every company.
NIST CSF vs ISO 27001
ISO/IEC 27001 is a certifiable standard that requires a formal management system. The NIST CSF is not certifiable and works as a common language to measure posture, prioritize investments and talk to the board. Many organizations use both: ISO 27001 as the management system and the CSF as a maturity map and communication tool.
Network Secure supports maturity assessments and GRC programs built on frameworks such as the NIST CSF.
Frequently asked questions
Is the NIST CSF certifiable?
No. It is a voluntary reference framework. For information security certification, the usual standard is ISO/IEC 27001.
What changed in NIST CSF 2.0?
Version 2.0, from February 2024, added the Govern function, broadened the audience to organizations of any size and sector and strengthened supply chain risk management.