NIST Cybersecurity Framework
The common language security teams use to talk about risk
What it is
About NIST Cybersecurity Framework
The NIST Cybersecurity Framework (CSF) organises cybersecurity activity into core functions — Identify, Protect, Detect, Respond, Recover, with Govern added in the 2024 CSF 2.0 update — giving organisations a structured, outcome-based way to assess and improve their security posture. It's a reference model rather than software, used by cloud architects, security consultants and compliance teams to map controls, audits and risk registers against recognised standards. It's widely adopted beyond the US and underpins many other compliance frameworks.
What you can do with it
Capabilities
Assess an organisation's cybersecurity maturity against defined functions
Build a target security profile and develop a gap-analysis roadmap
Align cloud architecture and controls with a recognised risk framework
Communicate security posture to non-technical stakeholders and boards
Map internal controls to other standards like ISO 27001 or SOC 2
How to learn it
Learning Resources
Read the official CSF 2.0 documentation and Quick Start Guides on nist.gov
Take SANS and (ISC)² courses covering NIST CSF implementation
Use NIST's free online CSF 2.0 Reference Tool for exploring functions and categories
Practise mapping a fictional organisation's controls against the framework
Pro Tip
Treat CSF 2.0's new Govern function as the one that ties the rest together — assessors increasingly expect to see leadership accountability, not just technical controls.
Skills that use this tool
Roles that use this tool