NIST CSF · 5 min read
NIST CSF 2.0 in Plain English
The Cybersecurity Framework's six functions, and why 2.0 added 'Govern' at the center.
What the CSF is
The NIST Cybersecurity Framework (CSF) is a voluntary, risk-based way to organize a security program. It's not a checklist of controls: it's a common language of outcomes that any organization (any size, any sector) can use to assess and improve its posture. CSF 2.0 (2024) is the current version and, notably, broadened the framework beyond critical infrastructure to *everyone*.
The six functions
- Govern (GV): *new in 2.0.* Establish and monitor the organization's cybersecurity risk strategy, roles, policy, and oversight. It sits at the center and informs the other five.
- Identify (ID): understand your assets, data, suppliers, and risks. You can't protect what you don't know you have.
- Protect (PR): safeguards: access control, awareness training, data security, secure configuration.
- Detect (DE): find anomalies and incidents quickly through monitoring.
- Respond (RS): contain, analyze, and communicate during an incident.
- Recover (RC): restore capabilities and learn from what happened.
Tiers and Profiles
Two tools make the CSF practical:
- Profiles: your Current profile (where you are) vs your Target profile (where you want to be). The gap between them is your roadmap.
- Tiers (1–4): how rigorous and integrated your risk practices are, from *Partial* (ad hoc) to *Adaptive* (continuously improving). Tiers describe maturity, not a grade.
