NIST Cybersecurity Framework 2.0
The NIST Cybersecurity Framework 2.0, released February 2024, is the most widely adopted cybersecurity framework globally. CSF 2.0 introduces the GOVERN function alongside the original five (Identify, Protect, Detect, Respond, Recover), totalling 6 functions, 22 categories, and 106 subcategories. Available in 10+ languages, it applies to organisations of all sizes and sectors.
6
Functions
22
Categories
106
Subcategories
10+
Languages
Organisational context, risk management strategy, roles and responsibilities, policy, oversight, and supply chain risk management.
Asset management, business environment, governance, risk assessment, and supply chain risk management for comprehensive visibility.
Identity management and access control, awareness and training, data security, platform security, and protective technology.
Anomalies and events detection, security continuous monitoring, and detection processes for timely threat identification.
Response planning, communications, analysis, mitigation, and improvements; recovery planning, continuity, and post-incident improvements.
Create a Current Profile documenting existing cybersecurity outcomes across all six CSF functions.
Define desired cybersecurity outcomes aligned with business objectives and risk appetite.
Compare Current vs Target Profile to identify gaps in cybersecurity outcomes.
Prioritise and plan activities to close identified gaps, considering available resources and risk.
Deploy controls and practices mapped to CSF subcategories using Informative References.
Use CSF Tiers (1-4) to measure maturity and drive continuous improvement over time.