ExploreGalaxyMy PathSettingsGive Feedback

New here?

A quick look at how MySkillGap works. Close it any time.

Security & ComplianceFree tier available

NIST Cybersecurity Framework

The common language security teams use to talk about risk

What it is

About NIST Cybersecurity Framework

The NIST Cybersecurity Framework (CSF) organises cybersecurity activity into core functions — Identify, Protect, Detect, Respond, Recover, with Govern added in the 2024 CSF 2.0 update — giving organisations a structured, outcome-based way to assess and improve their security posture. It's a reference model rather than software, used by cloud architects, security consultants and compliance teams to map controls, audits and risk registers against recognised standards. It's widely adopted beyond the US and underpins many other compliance frameworks.

What you can do with it

Capabilities

1

Assess an organisation's cybersecurity maturity against defined functions

2

Build a target security profile and develop a gap-analysis roadmap

3

Align cloud architecture and controls with a recognised risk framework

4

Communicate security posture to non-technical stakeholders and boards

5

Map internal controls to other standards like ISO 27001 or SOC 2

How to learn it

Learning Resources

Read the official CSF 2.0 documentation and Quick Start Guides on nist.gov

Take SANS and (ISC)² courses covering NIST CSF implementation

Use NIST's free online CSF 2.0 Reference Tool for exploring functions and categories

Practise mapping a fictional organisation's controls against the framework

Pro Tip

Treat CSF 2.0's new Govern function as the one that ties the rest together — assessors increasingly expect to see leadership accountability, not just technical controls.