Frameworks

What is the NIST Cybersecurity Framework (CSF)?

The NIST Cybersecurity Framework is a voluntary, risk-based framework for managing cybersecurity. Version 2.0 (2024) is organized around six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

Definition

The NIST Cybersecurity Framework (CSF) is a voluntary framework published by the US National Institute of Standards and Technology. It gives organizations a common language and structure for assessing and improving their management of cybersecurity risk.

Background

CSF is deliberately technology- and sector-neutral. The current edition, CSF 2.0 (2024), is built around six functions: Govern (added in 2.0), Identify, Protect, Detect, Respond, and Recover. Each function breaks into categories and subcategories of outcomes. Organizations use Tiers to describe how mature their risk management is, and Profiles to describe their current and target states. Because it is voluntary and outcome-based, CSF pairs well with prescriptive standards like ISO 27001 or control catalogs like NIST SP 800-53.

Why it matters

CSF is a widely understood way to describe a security program to executives, boards, and customers without drowning them in control IDs. It is especially useful as an organizing backbone that other frameworks map into.

Step by step

  1. Scope the part of the business the profile will cover.
  2. Create a Current Profile: which CSF outcomes you achieve today.
  3. Set a Target Profile based on your risk appetite and obligations.
  4. Identify and prioritize the gaps between current and target.
  5. Build an action plan and track progress against the six functions.
  6. Reassess periodically as the business and threat landscape change.

Examples

  • An SMB uses CSF to give its board a one-page view of security posture across the six functions.
  • A company maps its existing SOC 2 and ISO 27001 controls into CSF functions to report progress in plain language.

Common mistakes

  • Treating CSF as a checklist to “complete” rather than a way to describe and improve outcomes.
  • Ignoring the new Govern function, which anchors the rest of the program.
  • Building a Target Profile disconnected from actual business risk.

FAQ

How many functions does NIST CSF 2.0 have?

Six: Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in the 2.0 release to emphasize governance and risk-management strategy.

Is NIST CSF mandatory?

It is voluntary for most organizations, though some sectors and contracts reference it. Its value is as a flexible, widely understood structure rather than a compliance mandate.

Is CSF the same as NIST 800-53?

No. CSF is a high-level, outcome-based framework; NIST SP 800-53 is a detailed control catalog. Many organizations use CSF to organize and 800-53 (or another catalog) to implement.

Related

NIST CSF in Keel → What is a risk register? → What is ISO 27001? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free