NIST CSF (Cybersecurity Framework)
acronymsecuritygovernance & risk
The NIST Cybersecurity Framework: a voluntary structure for organising security work around a small set of high-level functions.
Deliberately not a checklist, which is what people most often want it to be. It describes outcomes rather than controls, so it can sit above whatever control set an organisation already uses, and version 2.0 in 2024 added a Govern function alongside the original Identify, Protect, Detect, Respond and Recover. The useful discipline it imposes is proportion: an organisation that can describe its Detect and Respond work in one sentence each, while Protect runs to four pages, has just learned something about itself.
Also known as: cybersecurity framework, csf, nist cybersecurity framework, csf 2.0
Sources
- NIST Cybersecurity Framework, nist.gov/cyberframework
- CSF 2.0, released February 2024