The NIST Cybersecurity Framework (CSF) 2.0
32 pages · 11 sections · built in 34 seconds
This is a real study pack, produced by the same pipeline your documents go through — not a mock-up. The source is a public NIST publication, so you can check every claim against the original.
Skippable1 Title and Abstract
p.1–2
- The NIST Cybersecurity Framework (CSF) 2.0 is a taxonomy of high-level cybersecurity outcomes designed to help any organization understand, assess, prioritize, and communicate its cybersecurity efforts.The CSF applies across all organization sizes, sectors, and maturity levels. It does not prescribe specific methods to achieve outcomes but links to online resources for implementation guidance.
- The CSF is intended for individuals leading cybersecurity programs, but is also useful to executives, boards, risk managers, technology professionals, lawyers, auditors, and policymakers making cybersecurity decisions.The framework's broad audience reflects its role in improving both technical cybersecurity efforts and organizational risk governance and communication.
- NIST provides supplemental resources on the CSF website including Quick Start Guides and Community Profiles to support implementation.Organizations can also submit suggestions for additional resources by contacting cyberframework@nist.gov.
Source: Title and Abstract, pages 1-2
Skippable2 Front Matter
p.3–5
- The NIST Cybersecurity Framework 2.0 is designed to help organizations of all sizes, sectors, and maturity levels manage and reduce cybersecurity risks.The CSF applies across industry, government, academia, and nonprofit organizations regardless of their technical sophistication or existing cybersecurity program maturity.
- The CSF does not use a one-size-fits-all approach because each organization has unique risks, risk appetites, missions, and objectives.Organizations must adapt and implement the CSF differently based on their specific circumstances, which is a necessary feature of the framework.
- CSF outcomes are sector-, country-, and technology-neutral to provide flexibility for addressing unique organizational risks and mission considerations.This neutrality allows organizations to apply the framework across different contexts while maintaining alignment with desired cybersecurity goals.
- CSF 2.0 introduces new emphasis on governance and supply chains compared to previous versions.The updated framework gives special attention to these areas and includes features like Quick Start Guides designed to make the CSF accessible to smaller organizations.
- The CSF should ideally be used to address cybersecurity risks alongside other enterprise risks including financial, privacy, supply chain, reputational, technological, and physical risks.Integration with broader risk management programs helps organizations manage cybersecurity in the context of their overall enterprise risk picture.
- Creating current and target state Organizational Profiles allows organizations to compare their present position with their desired state and accelerate control implementation.This comparison capability supports faster assessment and implementation of security controls tailored to organizational needs.
- The CSF is supplemented by an expanding online portfolio of resources including Implementation Examples, Informative References, Quick Start Guides, and automated tools.These supplementary materials provide specific guidance on achieving outcomes and offer various formats to help organizations of different sizes implement the framework.
- Cybersecurity risk management must be a continuous process that evolves as risks expand constantly.The CSF is designed to provide value over a long time period and remains relevant whether an organization is beginning its cybersecurity journey or maintaining a sophisticated program.
Source: Front Matter, pages 3-5
Must-know3 Cybersecurity Framework (CSF) Overview
p.6–7
- The CSF Core is a sector-, country-, and technology-neutral taxonomy of high-level cybersecurity outcomes organized in a hierarchy of Functions, Categories, and Subcategories.The Core is designed to be understood by executives, managers, and practitioners regardless of cybersecurity expertise, and its neutrality provides flexibility for organizations to address unique risks and mission considerations.
- CSF Organizational Profiles describe an organization's current or target cybersecurity posture in terms of CSF Core outcomes.Profiles serve as a mechanism for mapping and characterizing cybersecurity capabilities against the framework's defined outcomes.
- CSF Tiers characterize the rigor of an organization's cybersecurity risk governance and management practices and how the organization views and manages cybersecurity risks.Tiers provide a way to assess the maturity level and sophistication of an organization's approach to managing cybersecurity risks.
- The CSF describes desirable outcomes organizations can aspire to achieve but does not prescribe specific outcomes or mandate how to achieve them.Implementation guidance is provided through supplementary online resources including Informative References, Implementation Examples, and Quick-Start Guides.
- Organizations can use the CSF Core, Profiles, and Tiers together to understand and assess cybersecurity posture, identify gaps, prioritize risk management actions, and communicate about cybersecurity risks internally and externally.This integrated use supports describing current state, determining required improvements, aligning actions with organizational mission and regulatory requirements, and establishing common language for risk communication.
- The CSF is designed for voluntary adoption by organizations of all sizes and sectors and can also be adopted through governmental policies and mandates.The framework is applicable across industry, government, academia, and nonprofit organizations regardless of cybersecurity program maturity, and previous versions have been successfully implemented globally.
- The CSF should be used in conjunction with other frameworks, standards, guidelines, and leading practices to manage cybersecurity risks as part of enterprise-level information and communications technology (ICT) risk management.The CSF is flexible and intended to be tailored to each organization's unique risks, risk tolerances, mission objectives, and requirements.
- Supplementary online resources include Informative References pointing to existing standards and guidance, Implementation Examples showing ways to achieve outcomes, Quick-Start Guides for actionable CSF adoption, and templates for creating Organizational Profiles.These resources help organizations understand, adopt, and implement the CSF and support transition from previous CSF versions to version 2.0.
Source: Section 1 - Cybersecurity Framework (CSF) Overview, pages 6-7
- AOrganizational Profiles describe the organization's current or target cybersecurity posture, while Tiers characterize the rigor of the organization's cybersecurity risk governance and management practices
- BOrganizational Profiles define mandatory cybersecurity outcomes that all organizations must achieve, while Tiers specify the exact controls to implement
- COrganizational Profiles are used only for large enterprises, while Tiers are designed exclusively for government agencies
- DOrganizational Profiles replace the need for the CSF Core, while Tiers provide alternative frameworks for assessing cybersecurity risk
Source: pages 6-7
- AIt allows each organization to address its unique risks, technologies, and mission considerations while maintaining flexibility
- BIt eliminates the need for organizations to comply with their own country's cybersecurity regulations
- CIt guarantees that all organizations will achieve the same level of cybersecurity maturity regardless of their starting point
- DIt removes the requirement for organizations to tailor the framework to their specific circumstances
Source: page 6
- AThe CSF describes desirable outcomes organizations can aspire to achieve but does not prescribe outcomes or how to achieve them; guidance on how to achieve outcomes is provided through supplementary online resources
- BThe CSF prescribes specific cybersecurity controls that organizations must implement and describes the outcomes that will result from those controls
- CThe CSF describes only the governance structures needed for cybersecurity management and prescribes the technology controls required for compliance
- DThe CSF prescribes outcomes for large organizations but only describes aspirational goals for smaller organizations
Source: page 6
Must-know4 Introduction to the CSF Core
p.8–10
- The CSF Core organizes cybersecurity outcomes hierarchically by Function, Category, and Subcategory, but these are not checklists and specific implementation actions vary by organization.The Core's structure provides outcomes to guide organizations, not prescriptive steps. Different organizations will take different actions to achieve the same outcome, and responsibility for those actions may differ across organizations.
- The six CSF Functions are GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, each addressing a distinct phase of cybersecurity risk management.GOVERN establishes strategy and oversight; IDENTIFY assesses current risks; PROTECT implements safeguards; DETECT finds attacks; RESPOND contains incidents; RECOVER restores operations. The order and apparent size of these Functions do not indicate priority or sequence.
- GOVERN is central to the CSF because it informs how an organization implements the other five Functions within its mission and risk management strategy.Governance activities establish cybersecurity strategy, supply chain risk management, roles and responsibilities, policy, and oversight. This function ensures that cybersecurity efforts align with broader enterprise risk management and stakeholder expectations.
- All six Functions must be addressed concurrently, with GOVERN, IDENTIFY, PROTECT, and DETECT happening continuously, while RESPOND and RECOVER remain ready and activate during incidents.The Functions are interdependent and relate to one another as a wheel. GOVERN and IDENTIFY inform PROTECT; planning in these areas supports DETECT; and all Functions contribute to incident prevention, discovery, and management.
- The CSF Core applies to all information and communication technologies used by an organization, including IT, IoT, OT, cloud, mobile, and artificial intelligence systems.The framework is forward-looking and designed to remain relevant as technology environments and systems evolve. Its breadth ensures applicability across diverse organizational technology landscapes.
Source: Section: Introduction to the CSF Core, pages 8-10
- AGOVERN is the most critical Function and must be completed before any other cybersecurity activities can begin
- BGOVERN informs how an organization will implement the other five Functions and provides the cybersecurity risk management strategy that guides them
- CGOVERN is responsible for detecting and responding to incidents, which are the most important cybersecurity concerns
- DGOVERN is listed first alphabetically and the wheel structure simply follows the order of the Functions
Source: page 9-10
- AIDENTIFY and PROTECT are independent Functions that do not interact or depend on each other
- BAn organization categorizes assets and risks under IDENTIFY, and then takes steps to secure those identified assets under PROTECT
- CPROTECT outcomes must be completed before IDENTIFY outcomes can be determined
- DIDENTIFY is only used after PROTECT has failed to prevent a cybersecurity incident
Source: page 9
- AThe order and size should not be interpreted as implying the sequence or importance of achieving them
- BThe order and size should not be interpreted as restricting which Functions apply to cloud and mobile systems
- CThe order and size should not be interpreted as preventing concurrent implementation of all Functions
- DThe order and size should not be interpreted as determining which organization is responsible for each outcome
Source: page 8
Must-know5 Introduction to CSF Profiles and Tiers
p.11–13
- A CSF Organizational Profile describes an organization's current and/or target cybersecurity posture by mapping the Core's outcomes to the organization's mission, stakeholder expectations, threat landscape, and requirements.Profiles enable organizations to understand, tailor, assess, prioritize, and communicate cybersecurity outcomes, allowing them to focus actions and inform stakeholders of progress.
- A Current Profile specifies the Core outcomes an organization is currently achieving and characterizes the extent to which each outcome is being achieved.This baseline representation of existing cybersecurity practices provides the starting point for improvement planning and can be shared with external stakeholders to document capabilities and improvement opportunities.
- A Target Profile specifies the desired outcomes an organization has prioritized for its cybersecurity risk management objectives, considering anticipated changes such as new requirements, technology adoption, and threat trends.Target Profiles guide future state planning and can be communicated to suppliers and partners as expectations for their cybersecurity performance.
- A Community Profile is a baseline of CSF outcomes created and published to address shared interests among multiple organizations, typically developed for a sector, subsector, technology, threat type, or other use case.Organizations can use Community Profiles as a foundation for creating their own Target Profiles rather than building from scratch.
- The five-step Organizational Profile process involves scoping, gathering information, creating the profile, analyzing gaps between Current and Target Profiles, and implementing an action plan while updating the profile iteratively.This structured approach enables continuous improvement as organizations can repeat the steps as often as needed to maintain alignment with changing cybersecurity requirements.
- CSF Tiers characterize the rigor of an organization's cybersecurity risk governance and management practices across four levels: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4).The Tiers represent a progression from informal, ad hoc responses to agile, risk-informed, continuously improving approaches, helping organizations set the overall tone for risk management.
- Tiers should complement rather than replace an organization's existing cybersecurity risk management methodology and can be used as internal benchmarks for organization-wide approaches.Progression to higher Tiers is encouraged when risks or mandates increase or when cost-benefit analysis shows feasible and cost-effective risk reduction.
- An organization can create multiple Organizational Profiles with different scopes, such as profiles addressing the entire organization, specific systems, or particular threat types like ransomware.This flexibility allows organizations to apply the CSF at different levels of granularity to match their governance and risk management structure.
Source: Section 3.1-3.2, pages 11-13
- ATo replace an organization's existing risk management methodology with a standardized NIST approach
- BTo describe an organization's current and/or target cybersecurity posture in terms of the Core's outcomes
- CTo establish legal compliance requirements that all organizations must follow
- DTo provide a fixed benchmark that all organizations in a sector must achieve
Source: pages 11-12
- AA Community Profile is created by an individual organization to express its internal cybersecurity goals, while a Target Profile is shared across multiple organizations in the same sector
- BA Community Profile is a baseline of CSF outcomes created and published to address shared interests among multiple organizations, while a Target Profile specifies an individual organization's desired outcomes
- CA Community Profile must be adopted by all organizations in a sector, while a Target Profile is optional and only used by large enterprises
- DA Community Profile describes an organization's current achievements, while a Target Profile describes future aspirations
Source: pages 11-12
- AImmediately upon implementing the CSF, regardless of the organization's risk environment
- BWhen risks or mandates are greater or when a cost-benefit analysis indicates a feasible and cost-effective reduction of negative cybersecurity risks
- COnly when mandated by external regulators or industry standards
- DWhen the organization has completed all actions in its current Tier's action plan
Source: page 12-13
Useful6 Introduction to Online Resources That Supplement the CSF
p.14–14
- Three types of online resources supplement the CSF: Informative References, Implementation Examples, and Quick Start Guides.These resources are hosted online and can be updated more frequently than the main CSF document, which is updated infrequently for stability. They are also available in machine-readable formats.
- Informative References are mappings that show relationships between the CSF Core and standards, guidelines, regulations, and other content to help organizations achieve Core outcomes.They can be sector- or technology-specific, produced by NIST or other organizations, and may be narrower (like individual controls) or broader (like high-level policy requirements) in scope relative to Subcategories.
- Implementation Examples provide concise, action-oriented steps to help achieve Subcategory outcomes using verbs such as share, document, develop, perform, monitor, analyze, assess, and exercise.These examples are notional and not comprehensive; they do not represent a baseline of required actions or an exhaustive list of all possible actions to address cybersecurity risks.
- Quick-Start Guides are brief documents on specific CSF topics tailored to particular audiences, designed to distill actionable first steps for improving cybersecurity posture.New guides are added as needed and revised on their own time frames independent of the main CSF document updates.
Source: Section 4, page 14
- ABecause the CSF document is intentionally updated infrequently to provide stability to its users, while online resources can be updated more readily and offered in machine-readable formats
- BBecause online resources are required by law to be updated annually, whereas the CSF document has no such requirement
- CBecause online resources are easier to maintain than a printed document and do not require NIST approval
- DBecause the CSF document only applies to certain sectors, while online resources must cover all industries and technologies
Source: page 14
- AInformative References are mappings showing relationships to standards and guidelines, while Implementation Examples provide concrete, action-oriented steps to achieve Subcategory outcomes
- BInformative References are mandatory controls that must be implemented, while Implementation Examples are optional suggestions for consideration
- CInformative References are sector-specific and produced only by NIST, while Implementation Examples are generic and produced by any organization
- DInformative References describe what outcomes to achieve, while Implementation Examples mandate the specific baseline actions required to address cybersecurity risks
Source: page 14
Useful7 Improving Cybersecurity Risk Communication and Integration
p.15–19
- Organizations use the CSF to prioritize cybersecurity activities based on stakeholder expectations and risk appetite, choosing to mitigate, transfer, avoid, or accept risks depending on potential impacts and likelihoods.Understanding organizational mission, risks, and risk tolerance enables informed decision-making about cybersecurity expenditures and actions. The CSF can be used both internally to manage capabilities and externally to communicate with third parties.
- The CSF improves risk management communication through bidirectional information flow between executives, managers, and practitioners across three organizational levels.Executives focus on strategy and priorities, managers translate these into achievable cybersecurity objectives and risk targets, and practitioners implement controls and provide operational insights. This flow enables executives to make informed decisions about cybersecurity posture and adjust strategies accordingly.
- Creating and using Organizational Profiles involves gathering input from executives about priorities and resources, then having managers and practitioners collaborate to identify gaps between Current and Target Profiles and implement actions to close those gaps.Results from control implementation and system-level monitoring are shared through risk registers and progress reports, enabling managers to make ongoing adjustments that reduce harms and increase benefits.
- The GOVERN Function enables executives to establish cybersecurity priorities, integrate cybersecurity risk with enterprise risk management (ERM) programs, and set expectations about risk appetite, accountability, and resources.Executive governance discussions address strategy, risk management approaches including supply chain risk, roles and responsibilities, policies, and oversight mechanisms that cascade down to managers and practitioners.
- Organizations can integrate cybersecurity risk management with ERM to balance a portfolio of risk considerations and translate cybersecurity terminology into general risk management language that executives understand.The CSF helps executives receive and integrate cybersecurity risk data with other types of organizational risk, supporting strategic decision-making at the enterprise level.
- Cybersecurity and privacy are independent disciplines with overlapping objectives - cybersecurity risk management addresses confidentiality, integrity, and availability of data, while privacy risks can arise from data processing activities unrelated to cybersecurity incidents.The NIST Privacy Framework and Cybersecurity Framework can be used together to address different aspects of both risk types. Privacy problems range from dignity-type effects like embarrassment to tangible harms such as discrimination or economic loss.
- Supply chain risk management (SCRM) and cybersecurity SCRM (C-SCRM) are critical because technology products and services depend on complex, globally distributed, interconnected supply chains composed of multiple public and private sector entities.C-SCRM is a systematic process for managing cybersecurity exposure throughout supply chains and developing response strategies. The CSF's C-SCRM Category [GV.SC] connects cybersecurity outcomes with supply chain risk management considerations.
- Organizations should treat emerging technology risks such as artificial intelligence (AI) alongside other enterprise risks to yield integrated outcomes and organizational efficiencies.The NIST Artificial Intelligence Risk Management Framework (AI RMF) uses Functions, Categories, and Subcategories to describe AI outcomes. Cybersecurity and privacy risk management approaches are applicable to the design, development, deployment, evaluation, and use of AI systems.
Source: Section 5, pages 15-19
- ATo ensure that executives maintain direct control over all cybersecurity operational decisions made by practitioners
- BTo enable executives to communicate organizational priorities and strategy while receiving insights from managers and practitioners about cybersecurity risks and their mitigation
- CTo reduce the need for formal governance structures by allowing practitioners to communicate directly with executives about resource allocation
- DTo separate cybersecurity risk management from enterprise risk management so that each discipline can be managed independently
Source: page 15-16
- APrivacy risks can only result from cybersecurity incidents such as data breaches, whereas cybersecurity risks are always caused by external threat actors
- BCybersecurity risk management addresses privacy risks related to loss of data confidentiality, integrity, and availability, but privacy risks can also arise from data processing activities unrelated to cybersecurity incidents
- CPrivacy risks are more difficult to manage than cybersecurity risks because they involve multiple stakeholder groups across the supply chain
- DCybersecurity frameworks are designed primarily for privacy risk management, while privacy frameworks are designed for cybersecurity risk management
Source: page 17-18
Must-know8 CSF Core
p.20–23
- The CSF Core consists of six Functions - Govern, Identify, Protect, Detect, Respond, and Recover - each containing Categories and Subcategories that organize cybersecurity outcomes.The Functions represent the major phases of cybersecurity risk management, from establishing strategy through recovering from incidents. Categories group related outcomes within each Function, and Subcategories specify detailed actions.
- The Govern Function establishes the organization's cybersecurity risk management strategy, expectations, and policy through six Categories covering organizational context, risk management strategy, roles and responsibilities, policy, oversight, and supply chain risk management.Govern is foundational, requiring understanding of mission and stakeholder needs, establishing risk appetite statements, defining clear roles and authorities, communicating policy, monitoring strategy effectiveness, and managing cyber risks from suppliers.
- The Identify Function ensures the organization understands its current cybersecurity risks through three Categories: Asset Management, Risk Assessment, and Improvement.Organizations must maintain inventories of assets, identify vulnerabilities and threats, assess impacts and likelihoods, prioritize risk responses, and continuously identify improvements across all functions.
- The Protect Function implements safeguards to manage cybersecurity risks across five Categories: Identity Management and Access Control, Awareness and Training, Data Security, Platform Security, and Technology Infrastructure Resilience.Protection measures include managing identities and access permissions, providing personnel training, securing data at rest and in transit, maintaining platforms securely, and implementing resilient architectures.
- The Detect Function finds and analyzes possible cybersecurity attacks and compromises through two Categories: Continuous Monitoring and Adverse Event Analysis.Organizations monitor networks, physical environments, personnel activity, and computing systems for anomalies and indicators of compromise, then analyze events to characterize them and declare incidents when criteria are met.
- The Respond Function manages actions taken regarding detected incidents through four Categories: Incident Management, Incident Analysis, Incident Response Reporting and Communication, and Incident Mitigation.Response includes executing incident plans with third parties, triaging and categorizing incidents, investigating root causes, notifying stakeholders as required, and containing and eradicating incidents.
- The Recover Function restores assets and operations affected by incidents through two Categories: Incident Recovery Plan Execution and Incident Recovery Communication.Recovery involves executing recovery plans, verifying backup integrity, restoring systems and services, establishing post-incident operational norms, declaring recovery completion, and communicating progress to stakeholders.
- Subcategory numbering is intentionally non-sequential with gaps indicating CSF 1.1 Subcategories that were relocated in CSF 2.0.The ordering of Functions, Categories, and Subcategories prioritizes operational implementation over alphabetical arrangement, reflecting how organizations structure their risk management activities.
Source: CSF Core, pages 20-23
- ATo follow a sequential numbering pattern that makes them easier to reference
- BTo resonate most with those charged with operationalizing risk management within an organization
- CTo organize them alphabetically for consistency across all NIST guidance documents
- DTo prioritize the Functions based on how frequently organizations experience incidents in each area
Source: page 20
- ARisk Management Strategy must be established before Roles, Responsibilities, and Authorities can be determined
- BRoles, Responsibilities, and Authorities must be in place before Risk Management Strategy can be developed
- CRoles, Responsibilities, and Authorities foster accountability for executing the Risk Management Strategy that has been established
- DRisk Management Strategy and Roles, Responsibilities, and Authorities are independent Functions with no direct relationship
Source: pages 21-22
- ASupply chain risks should only be addressed at Tier 3 and above maturity levels
- BSupply chain risk management is integrated throughout cybersecurity and enterprise risk management processes, with dedicated attention to supplier relationships and third-party dependencies
- CSupply chain risks are managed exclusively through contracts and do not require ongoing monitoring after agreements are established
- DSupply chain risk management is considered a subset of the Identify Function rather than a distinct governance concern
Source: pages 22-23
Must-know9 CSF Tiers
p.24–25
- CSF Tiers characterize the rigor of an organization's cybersecurity risk governance practices (GOVERN function) and cybersecurity risk management practices (IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER functions).The four tiers provide a framework for assessing and communicating the maturity level of an organization's approach to managing cybersecurity risks across both strategic governance and operational management.
- Tier 1 (Partial) represents ad hoc cybersecurity risk management with limited organizational awareness, informal or case-by-case implementation, and minimal supplier risk consideration.Organizations at this level lack formalized processes for sharing cybersecurity information internally and do not prioritize cybersecurity activities based on documented objectives or threat environments.
- Tier 2 (Risk Informed) involves management-approved risk management practices that inform cybersecurity prioritization but lack organization-wide policy and consistent formal response to supplier risks.Cybersecurity awareness exists at the organizational level, and cyber risk assessments occur, but these efforts are not repeatable or consistently applied across all organizational levels.
- Tier 3 (Repeatable) establishes formally approved risk management policies with consistent implementation, regular updates based on changing requirements and threats, and formal supplier risk management mechanisms.Organizations at this level routinely share cybersecurity information, maintain consistent response methods to risk changes, and ensure personnel have the knowledge and skills for their roles, with senior executives regularly communicating about cybersecurity risks.
- Tier 4 (Adaptive) represents organization-wide cybersecurity risk management integrated with organizational objectives, using real-time information and continuous improvement to adapt to evolving threats and technological changes.At this level, cybersecurity risk management is embedded in organizational culture, executives monitor cybersecurity risks alongside financial and other organizational risks, and the organization responds in real-time to supplier and external risks using advanced technologies and predictive indicators.
Source: CSF Tiers, pages 24-25
- ATier 2 uses ad hoc prioritization while Tier 3 uses risk-informed policies and procedures that are formally approved and implemented
- BTier 2 has organization-wide awareness while Tier 3 only considers cybersecurity at some levels
- CTier 2 shares cybersecurity information formally while Tier 3 shares it only informally
- DTier 2 uses real-time information to manage risks while Tier 3 uses historical data
Source: pages 24-25, Table 2
- ATier 4 continuously improves and actively adapts based on lessons learned and predictive indicators, while Tier 3 only updates practices based on application of risk management processes to changes
- BTier 4 relies on informal awareness of threats while Tier 3 requires formal approved policies
- CTier 4 shares cybersecurity information only within the organization while Tier 3 shares it with external parties
- DTier 4 prioritizes cybersecurity based on ad hoc business needs while Tier 3 uses formal organizational objectives
Source: pages 24-25, Table 2
- AOrganizations progress from being unaware of supplier risks at Tier 1 to using real-time information to manage supplier risks at Tier 4
- BAll tiers share supplier risk information equally with external parties to ensure transparency
- CTier 3 organizations completely eliminate supplier risks through written agreements
- DSupplier risk management is not addressed in the NIST Cybersecurity Framework
Source: pages 24-25, Table 2
Must-know10 Glossary
p.26–26
- The CSF Core is a taxonomy of high-level cybersecurity outcomes organized hierarchically into six Functions, 22 Categories, and multiple Subcategories that any organization can use to manage cybersecurity risks.The Functions are the highest level of organization, Categories group related outcomes within Functions, and Subcategories detail more specific technical and management activities that achieve those outcomes.
- A CSF Organizational Profile is a mechanism that describes an organization's current and target cybersecurity posture using CSF Core outcomes, comprising a Current Profile (what is being achieved) and a Target Profile (what is desired).Organizations use profiles to align their cybersecurity posture with business objectives and prioritize which outcomes to achieve.
- CSF Tiers characterize the rigor of an organization's cybersecurity risk governance and management practices on a scale from Partial (Tier 1) to Adaptive (Tier 4).Tiers help organizations understand and communicate the maturity level of their risk management approach.
- A CSF Community Profile is a baseline of CSF outcomes created for a particular sector, subsector, technology, threat type, or use case that organizations can adopt as the foundation for their own Target Profile.Community Profiles address shared interests and goals among multiple organizations in similar contexts.
- CSF Informative References are mappings that show relationships between CSF Core outcomes and existing standards, guidelines, regulations, or other content.These references help organizations understand how the CSF connects to other frameworks and compliance requirements.
- CSF Implementation Examples are concise, action-oriented illustrations of practical ways to achieve specific CSF Core outcomes.These examples provide guidance on how to operationalize the outcomes in organizational practice.
- CSF Quick Start Guides are supplementary resources that provide brief, actionable guidance on specific CSF-related topics.These guides help organizations quickly understand and apply CSF concepts to their particular context.
Source: Appendix C. Glossary, pages 26 and 31-32
- AThe Current Profile describes desired outcomes while the Target Profile describes outcomes being achieved
- BThe Current Profile specifies outcomes currently being achieved while the Target Profile specifies desired outcomes that have been selected and prioritized
- CThe Current Profile is used only for Tier 1 organizations while the Target Profile is used for Tier 2 and above
- DThe Current Profile applies to Community Profiles while the Target Profile applies only to individual organizations
Source: page 26, Glossary
- AA Community Profile is created by individual organizations to replace their Target Profile
- BAn organization can use a Community Profile as the basis for developing its own Target Profile
- CA Community Profile and Target Profile serve identical purposes within an Organizational Profile
- DA Community Profile is only applicable to organizations operating in Tier 3 or Tier 4
Source: page 26, Glossary
- ACSF Functions are the lowest level of organization within the CSF Core's hierarchy
- BCSF Functions are the highest level of organization for cybersecurity outcomes within the CSF Core
- CCSF Functions and the CSF Core are separate frameworks that do not relate to each other
- DCSF Functions are supplementary resources that map the CSF Core to external standards
Source: page 26, Glossary
Skippable11 Back Matter
p.27–32
- Identification of commercial products in the document does not constitute NIST endorsement or recommendation of those products or services.NIST clarifies that mentioning specific equipment, software, or materials is done only to describe procedures adequately and does not imply these are the best available options or that NIST recommends them.
- The proper citation for NIST CSF 2.0 is: National Institute of Standards and Technology (2024) The NIST Cybersecurity Framework (CSF) 2.0 (National Institute of Standards and Technology, Gaithersburg, MD), NIST Cybersecurity White Paper (CSWP) NIST CSWP 29, with DOI 10.6028/NIST.CSWP.29.This standardized citation format should be used when referencing the NIST CSF 2.0 document in other publications or materials.
- Questions and comments about NIST CSF 2.0 can be directed to cyberframework@nist.gov or the Applied Cybersecurity Division at the provided postal address.NIST provides contact information for inquiries about the framework, with both email and mailing address available for the Information Technology Laboratory in Gaithersburg, Maryland.
- All comments submitted to NIST regarding this document are subject to release under the Freedom of Information Act (FOIA).Contributors and commenters should be aware that their submissions may be made publicly available through FOIA requests.
Source: Back Matter, pages 27-32
Get this for your own book
The same thing for your textbook, certification guide or vendor documentation — up to a few hundred pages. StudySift opens shortly, and everyone on the list gets double credit on their first top-up.