Sample

The NIST Cybersecurity Framework (CSF) 2.0

32 pages · 11 sections · built in 34 seconds

This is a real study pack, produced by the same pipeline your documents go through — not a mock-up. The source is a public NIST publication, so you can check every claim against the original.

Tell me when it opens Other sample packs What is StudySift?
This pack 6 must-know 2 useful 3 skippable 22 practice questions
Skippable

1  Title and Abstract

p.1–2
Why skippable
This section is standard front matter containing publication metadata, abstract boilerplate, and administrative information. While the abstract briefly describes what CSF 2.0 is, this content is restated in greater detail in the subsequent 'CSF Overview' and 'Introduction to the CSF Core' sections. The audience list and supplemental content pointers are navigational rather than substantive.
Likely tested: none
  • The NIST Cybersecurity Framework (CSF) 2.0 is a taxonomy of high-level cybersecurity outcomes designed to help any organization understand, assess, prioritize, and communicate its cybersecurity efforts.
    The CSF applies across all organization sizes, sectors, and maturity levels. It does not prescribe specific methods to achieve outcomes but links to online resources for implementation guidance.
  • The CSF is intended for individuals leading cybersecurity programs, but is also useful to executives, boards, risk managers, technology professionals, lawyers, auditors, and policymakers making cybersecurity decisions.
    The framework's broad audience reflects its role in improving both technical cybersecurity efforts and organizational risk governance and communication.
  • NIST provides supplemental resources on the CSF website including Quick Start Guides and Community Profiles to support implementation.
    Organizations can also submit suggestions for additional resources by contacting cyberframework@nist.gov.

Source: Title and Abstract, pages 1-2

Skippable

2  Front Matter

p.3–5
Why skippable
The Front Matter consists primarily of acknowledgments, a table of contents, and a preface that provides context and motivation for the CSF 2.0. While the preface explains the CSF's intended scope and flexibility, these are restatements of material that will be covered in detail in the subsequent sections (Overview, CSF Core, Profiles, Tiers). The acknowledgments and table of contents are standard front matter boilerplate. A learner can proceed directly to the substantive content starting with the CSF Overview section without losing critical knowledge.
Likely tested: none
  • The NIST Cybersecurity Framework 2.0 is designed to help organizations of all sizes, sectors, and maturity levels manage and reduce cybersecurity risks.
    The CSF applies across industry, government, academia, and nonprofit organizations regardless of their technical sophistication or existing cybersecurity program maturity.
  • The CSF does not use a one-size-fits-all approach because each organization has unique risks, risk appetites, missions, and objectives.
    Organizations must adapt and implement the CSF differently based on their specific circumstances, which is a necessary feature of the framework.
  • CSF outcomes are sector-, country-, and technology-neutral to provide flexibility for addressing unique organizational risks and mission considerations.
    This neutrality allows organizations to apply the framework across different contexts while maintaining alignment with desired cybersecurity goals.
  • CSF 2.0 introduces new emphasis on governance and supply chains compared to previous versions.
    The updated framework gives special attention to these areas and includes features like Quick Start Guides designed to make the CSF accessible to smaller organizations.
  • The CSF should ideally be used to address cybersecurity risks alongside other enterprise risks including financial, privacy, supply chain, reputational, technological, and physical risks.
    Integration with broader risk management programs helps organizations manage cybersecurity in the context of their overall enterprise risk picture.
  • Creating current and target state Organizational Profiles allows organizations to compare their present position with their desired state and accelerate control implementation.
    This comparison capability supports faster assessment and implementation of security controls tailored to organizational needs.
  • The CSF is supplemented by an expanding online portfolio of resources including Implementation Examples, Informative References, Quick Start Guides, and automated tools.
    These supplementary materials provide specific guidance on achieving outcomes and offer various formats to help organizations of different sizes implement the framework.
  • Cybersecurity risk management must be a continuous process that evolves as risks expand constantly.
    The CSF is designed to provide value over a long time period and remains relevant whether an organization is beginning its cybersecurity journey or maintaining a sophisticated program.

Source: Front Matter, pages 3-5

Must-know

3  Cybersecurity Framework (CSF) Overview

p.6–7
Why must-know
This section introduces the four foundational components of CSF 2.0 (Core, Organizational Profiles, Tiers, and online resources) and defines their purpose and relationships. It establishes that the CSF is prescriptive about outcomes but not implementation, and clarifies the framework's scope, flexibility, and intended uses (Understand/Assess, Prioritize, Communicate). A learner cannot effectively study CSF 2.0 without understanding these distinctions and the overall structure presented here.
Likely tested: CSF 2.0 components (Core, Profiles, Tiers); the distinction between outcomes and implementation; the four primary uses of the CSF (Understand/Assess, Prioritize, Communicate); applicability across organizations of all sizes and sectors; the role of supplementary online resources.
  • The CSF Core is a sector-, country-, and technology-neutral taxonomy of high-level cybersecurity outcomes organized in a hierarchy of Functions, Categories, and Subcategories.
    The Core is designed to be understood by executives, managers, and practitioners regardless of cybersecurity expertise, and its neutrality provides flexibility for organizations to address unique risks and mission considerations.
  • CSF Organizational Profiles describe an organization's current or target cybersecurity posture in terms of CSF Core outcomes.
    Profiles serve as a mechanism for mapping and characterizing cybersecurity capabilities against the framework's defined outcomes.
  • CSF Tiers characterize the rigor of an organization's cybersecurity risk governance and management practices and how the organization views and manages cybersecurity risks.
    Tiers provide a way to assess the maturity level and sophistication of an organization's approach to managing cybersecurity risks.
  • The CSF describes desirable outcomes organizations can aspire to achieve but does not prescribe specific outcomes or mandate how to achieve them.
    Implementation guidance is provided through supplementary online resources including Informative References, Implementation Examples, and Quick-Start Guides.
  • Organizations can use the CSF Core, Profiles, and Tiers together to understand and assess cybersecurity posture, identify gaps, prioritize risk management actions, and communicate about cybersecurity risks internally and externally.
    This integrated use supports describing current state, determining required improvements, aligning actions with organizational mission and regulatory requirements, and establishing common language for risk communication.
  • The CSF is designed for voluntary adoption by organizations of all sizes and sectors and can also be adopted through governmental policies and mandates.
    The framework is applicable across industry, government, academia, and nonprofit organizations regardless of cybersecurity program maturity, and previous versions have been successfully implemented globally.
  • The CSF should be used in conjunction with other frameworks, standards, guidelines, and leading practices to manage cybersecurity risks as part of enterprise-level information and communications technology (ICT) risk management.
    The CSF is flexible and intended to be tailored to each organization's unique risks, risk tolerances, mission objectives, and requirements.
  • Supplementary online resources include Informative References pointing to existing standards and guidance, Implementation Examples showing ways to achieve outcomes, Quick-Start Guides for actionable CSF adoption, and templates for creating Organizational Profiles.
    These resources help organizations understand, adopt, and implement the CSF and support transition from previous CSF versions to version 2.0.

Source: Section 1 - Cybersecurity Framework (CSF) Overview, pages 6-7

Practice
What is the primary purpose of CSF Organizational Profiles and CSF Tiers as described in the CSF Overview?
  • AOrganizational Profiles describe the organization's current or target cybersecurity posture, while Tiers characterize the rigor of the organization's cybersecurity risk governance and management practices
  • BOrganizational Profiles define mandatory cybersecurity outcomes that all organizations must achieve, while Tiers specify the exact controls to implement
  • COrganizational Profiles are used only for large enterprises, while Tiers are designed exclusively for government agencies
  • DOrganizational Profiles replace the need for the CSF Core, while Tiers provide alternative frameworks for assessing cybersecurity risk
The section explicitly states that 'CSF Organizational Profiles, which are a mechanism for describing an organization's current and/or target cybersecurity posture in terms of the CSF Core's outcomes' and that 'CSF Tiers, which can be applied to CSF Organizational Profiles to characterize the rigor of an organization's cybersecurity risk governance and management practices.' The option 'Organizational Profiles describe the organization's current or target cybersecurity posture, while Tiers characterize the rigor of the organization's cybersecurity risk governance and management practices' is correct. The second option is wrong because the document states the CSF 'does not prescribe outcomes nor how they may be achieved.' The third option is incorrect because the CSF is 'designed to be used by organizations of all sizes and sectors.' The fourth option misrepresents the relationship - Profiles and Tiers complement rather than replace the CSF Core.
Source: pages 6-7
According to the CSF Overview, how does the sector-, country-, and technology-neutral nature of CSF outcomes benefit organizations?
  • AIt allows each organization to address its unique risks, technologies, and mission considerations while maintaining flexibility
  • BIt eliminates the need for organizations to comply with their own country's cybersecurity regulations
  • CIt guarantees that all organizations will achieve the same level of cybersecurity maturity regardless of their starting point
  • DIt removes the requirement for organizations to tailor the framework to their specific circumstances
The section states that CSF Core outcomes 'provide an organization with the flexibility needed to address its unique risks, technologies, and mission considerations' precisely because they are 'sector-, country-, and technology-neutral.' This matches the correct option about addressing unique risks and maintaining flexibility. The second option is wrong because the document later notes that the CSF 'may be adopted voluntarily and through governmental policies and mandates,' implying regulatory compliance remains a separate concern. The third option contradicts the statement that 'organizations will continue to have unique risks' and 'their implementations of the CSF will vary.' The fourth option is false because the document emphasizes the framework 'is intended to be tailored for use by all organizations.'
Source: page 6
What distinction does the CSF Overview make between what the framework describes versus what it prescribes?
  • AThe CSF describes desirable outcomes organizations can aspire to achieve but does not prescribe outcomes or how to achieve them; guidance on how to achieve outcomes is provided through supplementary online resources
  • BThe CSF prescribes specific cybersecurity controls that organizations must implement and describes the outcomes that will result from those controls
  • CThe CSF describes only the governance structures needed for cybersecurity management and prescribes the technology controls required for compliance
  • DThe CSF prescribes outcomes for large organizations but only describes aspirational goals for smaller organizations
The document explicitly states 'This document describes what desirable outcomes an organization can aspire to achieve. It does not prescribe outcomes nor how they may be achieved. Descriptions of how an organization can achieve those outcomes are provided in a suite of online resources.' This matches the correct option. The second option reverses the relationship - the CSF describes outcomes rather than prescribing specific controls. The third option incorrectly limits the CSF's scope to only governance and technology. The fourth option is unsupported by the text, which states the CSF is 'designed to be used by organizations of all sizes.'
Source: page 6
Must-know

4  Introduction to the CSF Core

p.8–10
Why must-know
This section introduces the foundational structural architecture of the entire CSF 2.0 — the six Functions (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER) and their hierarchical organization into Categories and Subcategories. It explicitly defines what each Function does and how they interrelate, which is essential to understanding the core framework. The clarification that CSF Core is not a checklist and that Functions should be addressed concurrently are critical conceptual points that shape how the framework is applied. This material is load-bearing for all subsequent learning about the CSF.
Likely tested: The six CSF Functions and their definitions (GOVERN as risk strategy, IDENTIFY as understanding current risks, PROTECT as safeguards, DETECT as discovery and analysis, RESPOND as incident actions, RECOVER as restoration); the hierarchical structure (Functions divided into Categories divided into Subcategories); the wheel model showing GOVERN at center informing the other five; concurrent implementation of Functions; applicability to IT, IoT, OT, cloud, mobile, and AI systems.
  • The CSF Core organizes cybersecurity outcomes hierarchically by Function, Category, and Subcategory, but these are not checklists and specific implementation actions vary by organization.
    The Core's structure provides outcomes to guide organizations, not prescriptive steps. Different organizations will take different actions to achieve the same outcome, and responsibility for those actions may differ across organizations.
  • The six CSF Functions are GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, each addressing a distinct phase of cybersecurity risk management.
    GOVERN establishes strategy and oversight; IDENTIFY assesses current risks; PROTECT implements safeguards; DETECT finds attacks; RESPOND contains incidents; RECOVER restores operations. The order and apparent size of these Functions do not indicate priority or sequence.
  • GOVERN is central to the CSF because it informs how an organization implements the other five Functions within its mission and risk management strategy.
    Governance activities establish cybersecurity strategy, supply chain risk management, roles and responsibilities, policy, and oversight. This function ensures that cybersecurity efforts align with broader enterprise risk management and stakeholder expectations.
  • All six Functions must be addressed concurrently, with GOVERN, IDENTIFY, PROTECT, and DETECT happening continuously, while RESPOND and RECOVER remain ready and activate during incidents.
    The Functions are interdependent and relate to one another as a wheel. GOVERN and IDENTIFY inform PROTECT; planning in these areas supports DETECT; and all Functions contribute to incident prevention, discovery, and management.
  • The CSF Core applies to all information and communication technologies used by an organization, including IT, IoT, OT, cloud, mobile, and artificial intelligence systems.
    The framework is forward-looking and designed to remain relevant as technology environments and systems evolve. Its breadth ensures applicability across diverse organizational technology landscapes.

Source: Section: Introduction to the CSF Core, pages 8-10

Practice
Why does the NIST CSF 2.0 place GOVERN at the center of the Functions wheel rather than treating all six Functions as equal?
  • AGOVERN is the most critical Function and must be completed before any other cybersecurity activities can begin
  • BGOVERN informs how an organization will implement the other five Functions and provides the cybersecurity risk management strategy that guides them
  • CGOVERN is responsible for detecting and responding to incidents, which are the most important cybersecurity concerns
  • DGOVERN is listed first alphabetically and the wheel structure simply follows the order of the Functions
The document states that GOVERN is in the center of the wheel because it informs how an organization will implement the other five Functions - it establishes the cybersecurity risk management strategy, expectations, and policy that guide the entire framework. The option about completing before others is incorrect because the document explicitly states Functions should be addressed concurrently. The option about detecting and responding is incorrect because DETECT and RESPOND, not GOVERN, handle incident discovery and management. The alphabetical ordering is false because the Functions are not presented in alphabetical order.
Source: page 9-10
According to the CSF 2.0, what is the relationship between the IDENTIFY Function and the PROTECT Function?
  • AIDENTIFY and PROTECT are independent Functions that do not interact or depend on each other
  • BAn organization categorizes assets and risks under IDENTIFY, and then takes steps to secure those identified assets under PROTECT
  • CPROTECT outcomes must be completed before IDENTIFY outcomes can be determined
  • DIDENTIFY is only used after PROTECT has failed to prevent a cybersecurity incident
The document explicitly states that an organization will categorize assets under IDENTIFY and take steps to secure those assets under PROTECT, showing the sequential relationship between these Functions. The option claiming they are independent contradicts the document's emphasis on how Functions relate to one another. The option suggesting PROTECT must come first reverses the actual sequence. The option about IDENTIFY following PROTECT failure is incorrect because IDENTIFY supports the foundational understanding needed for all other Functions, including PROTECT.
Source: page 9
The CSF 2.0 document states that the order and size of Functions, Categories, and Subcategories should not be interpreted in what way?
  • AThe order and size should not be interpreted as implying the sequence or importance of achieving them
  • BThe order and size should not be interpreted as restricting which Functions apply to cloud and mobile systems
  • CThe order and size should not be interpreted as preventing concurrent implementation of all Functions
  • DThe order and size should not be interpreted as determining which organization is responsible for each outcome
The document explicitly states in the opening section that the order and size of Functions, Categories, and Subcategories in the Core does not imply the sequence or importance of achieving them. This clarification is meant to prevent misunderstanding that listing order reflects priority. The option about cloud and mobile systems restrictions is not addressed in this context - the document actually states these items apply to all technology environments. The option about concurrent implementation addresses a separate point about how Functions should be executed, not what their order implies. The option about organizational responsibility is addressed differently - the document notes that the individual responsible for actions will vary by organization.
Source: page 8
Must-know

5  Introduction to CSF Profiles and Tiers

p.11–13
Why must-know
This section defines two of the CSF 2.0's core structural components - Organizational Profiles and Tiers - which are essential mechanisms for applying the framework. The section explains how organizations use Profiles to characterize current and target cybersecurity posture, and how Tiers provide a maturity model for risk governance practices. These concepts directly enable the practical use of the CSF Core and are foundational to understanding how organizations assess and communicate their cybersecurity state.
Likely tested: CSF Organizational Profile definition and types (Current, Target, Community); steps for creating and using Organizational Profiles; CSF Tiers definition and the four levels (Partial, Risk Informed, Repeatable, Adaptive); Tiers as characterization of cybersecurity risk governance and management practices maturity; relationship between Profiles, Tiers, and the CSF Core outcomes
  • A CSF Organizational Profile describes an organization's current and/or target cybersecurity posture by mapping the Core's outcomes to the organization's mission, stakeholder expectations, threat landscape, and requirements.
    Profiles enable organizations to understand, tailor, assess, prioritize, and communicate cybersecurity outcomes, allowing them to focus actions and inform stakeholders of progress.
  • A Current Profile specifies the Core outcomes an organization is currently achieving and characterizes the extent to which each outcome is being achieved.
    This baseline representation of existing cybersecurity practices provides the starting point for improvement planning and can be shared with external stakeholders to document capabilities and improvement opportunities.
  • A Target Profile specifies the desired outcomes an organization has prioritized for its cybersecurity risk management objectives, considering anticipated changes such as new requirements, technology adoption, and threat trends.
    Target Profiles guide future state planning and can be communicated to suppliers and partners as expectations for their cybersecurity performance.
  • A Community Profile is a baseline of CSF outcomes created and published to address shared interests among multiple organizations, typically developed for a sector, subsector, technology, threat type, or other use case.
    Organizations can use Community Profiles as a foundation for creating their own Target Profiles rather than building from scratch.
  • The five-step Organizational Profile process involves scoping, gathering information, creating the profile, analyzing gaps between Current and Target Profiles, and implementing an action plan while updating the profile iteratively.
    This structured approach enables continuous improvement as organizations can repeat the steps as often as needed to maintain alignment with changing cybersecurity requirements.
  • CSF Tiers characterize the rigor of an organization's cybersecurity risk governance and management practices across four levels: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4).
    The Tiers represent a progression from informal, ad hoc responses to agile, risk-informed, continuously improving approaches, helping organizations set the overall tone for risk management.
  • Tiers should complement rather than replace an organization's existing cybersecurity risk management methodology and can be used as internal benchmarks for organization-wide approaches.
    Progression to higher Tiers is encouraged when risks or mandates increase or when cost-benefit analysis shows feasible and cost-effective risk reduction.
  • An organization can create multiple Organizational Profiles with different scopes, such as profiles addressing the entire organization, specific systems, or particular threat types like ransomware.
    This flexibility allows organizations to apply the CSF at different levels of granularity to match their governance and risk management structure.

Source: Section 3.1-3.2, pages 11-13

Practice
What is the primary purpose of a CSF Organizational Profile?
  • ATo replace an organization's existing risk management methodology with a standardized NIST approach
  • BTo describe an organization's current and/or target cybersecurity posture in terms of the Core's outcomes
  • CTo establish legal compliance requirements that all organizations must follow
  • DTo provide a fixed benchmark that all organizations in a sector must achieve
The section states that 'A CSF Organizational Profile describes an organization's current and/or target cybersecurity posture in terms of the Core's outcomes' and is used to 'understand, tailor, assess, prioritize, and communicate the Core's outcomes.' The option about replacing methodology is wrong because the section explicitly states that 'Tiers should complement an organization's cybersecurity risk management methodology rather than replace it.' The option about legal compliance is wrong because Profiles are tailored to an organization's specific context, not imposed uniformly. The option about fixed benchmarks is wrong because Target Profiles are 'desired outcomes that an organization has selected and prioritized' based on their own objectives.
Source: pages 11-12
How does a Community Profile differ from a Target Profile?
  • AA Community Profile is created by an individual organization to express its internal cybersecurity goals, while a Target Profile is shared across multiple organizations in the same sector
  • BA Community Profile is a baseline of CSF outcomes created and published to address shared interests among multiple organizations, while a Target Profile specifies an individual organization's desired outcomes
  • CA Community Profile must be adopted by all organizations in a sector, while a Target Profile is optional and only used by large enterprises
  • DA Community Profile describes an organization's current achievements, while a Target Profile describes future aspirations
The section defines a Community Profile as 'a baseline of CSF outcomes that is created and published to address shared interests and goals among a number of organizations' and notes that 'An organization can use a Community Profile as the basis for its own Target Profile.' This clarifies the relationship - Community Profiles are sector-wide or use-case baselines, while Target Profiles are individual organization documents. The first option reverses the relationship. The third option is incorrect because Community Profiles are described as optional starting points, not mandatory requirements. The fourth option is incorrect because a Current Profile (not a Target Profile) describes current achievements.
Source: pages 11-12
According to the section, when should an organization consider progressing to higher Tiers?
  • AImmediately upon implementing the CSF, regardless of the organization's risk environment
  • BWhen risks or mandates are greater or when a cost-benefit analysis indicates a feasible and cost-effective reduction of negative cybersecurity risks
  • COnly when mandated by external regulators or industry standards
  • DWhen the organization has completed all actions in its current Tier's action plan
The section explicitly states that 'Progression to higher Tiers is encouraged when risks or mandates are greater or when a cost-benefit analysis indicates a feasible and cost-effective reduction of negative cybersecurity risks.' This demonstrates that progression is based on organizational context and economic analysis, not on automatic timelines or completion of prior activities. The first option is wrong because progression is situational, not automatic. The third option is too restrictive, as the section shows progression is encouraged based on risk and cost-benefit analysis, not only regulatory mandates. The fourth option is wrong because the section does not establish that completing a Tier's action plan is a prerequisite for advancement.
Source: page 12-13
Useful

6  Introduction to Online Resources That Supplement the CSF

p.14–14
Why useful
This section explains three types of supplementary resources (Informative References, Implementation Examples, and Quick Start Guides) that support CSF adoption and use. While these resources are genuinely helpful for practitioners implementing the framework, the section is primarily navigational and reference-oriented rather than core CSF conceptual material. A learner needs to understand that these resources exist and their general purpose, but the detailed mechanics of how to use them are not load-bearing for understanding the CSF's structure, Functions, Categories, Subcategories, Profiles, and Tiers—which are the testable fundamentals.
Likely tested: The existence and general purpose of Informative References, Implementation Examples, and Quick Start Guides as supplementary CSF resources; understanding that Informative References map relationships between the Core and standards/regulations.
  • Three types of online resources supplement the CSF: Informative References, Implementation Examples, and Quick Start Guides.
    These resources are hosted online and can be updated more frequently than the main CSF document, which is updated infrequently for stability. They are also available in machine-readable formats.
  • Informative References are mappings that show relationships between the CSF Core and standards, guidelines, regulations, and other content to help organizations achieve Core outcomes.
    They can be sector- or technology-specific, produced by NIST or other organizations, and may be narrower (like individual controls) or broader (like high-level policy requirements) in scope relative to Subcategories.
  • Implementation Examples provide concise, action-oriented steps to help achieve Subcategory outcomes using verbs such as share, document, develop, perform, monitor, analyze, assess, and exercise.
    These examples are notional and not comprehensive; they do not represent a baseline of required actions or an exhaustive list of all possible actions to address cybersecurity risks.
  • Quick-Start Guides are brief documents on specific CSF topics tailored to particular audiences, designed to distill actionable first steps for improving cybersecurity posture.
    New guides are added as needed and revised on their own time frames independent of the main CSF document updates.

Source: Section 4, page 14

Practice
Why are online resources that supplement the CSF updated more frequently than the CSF document itself?
  • ABecause the CSF document is intentionally updated infrequently to provide stability to its users, while online resources can be updated more readily and offered in machine-readable formats
  • BBecause online resources are required by law to be updated annually, whereas the CSF document has no such requirement
  • CBecause online resources are easier to maintain than a printed document and do not require NIST approval
  • DBecause the CSF document only applies to certain sectors, while online resources must cover all industries and technologies
The text explicitly states that online resources 'can be updated more frequently than this document, which is updated infrequently to provide stability to its users, and be available in machine-readable formats.' This explains the deliberate design choice - the document prioritizes stability while online resources prioritize currency and flexibility. The other options misrepresent the reasons: there is no mention of legal requirements for annual updates, the comparison is not simply about ease of maintenance, and the CSF document is not sector-specific in the way suggested.
Source: page 14
What is the key distinction between Informative References and Implementation Examples in how they guide organizations toward achieving CSF outcomes?
  • AInformative References are mappings showing relationships to standards and guidelines, while Implementation Examples provide concrete, action-oriented steps to achieve Subcategory outcomes
  • BInformative References are mandatory controls that must be implemented, while Implementation Examples are optional suggestions for consideration
  • CInformative References are sector-specific and produced only by NIST, while Implementation Examples are generic and produced by any organization
  • DInformative References describe what outcomes to achieve, while Implementation Examples mandate the specific baseline actions required to address cybersecurity risks
The text describes Informative References as 'mappings that indicate relationships between the Core and various standards, guidelines, regulations, and other content' that 'help inform how an organization may achieve the Core's outcomes.' Implementation Examples are described as 'notional examples of concise, action-oriented steps to help achieve the outcomes of the Subcategories.' The distinction is that References show related standards and guidance, while Examples show potential actions. The second option incorrectly suggests References are mandatory and Examples are optional - the text does not make this distinction. The third option is wrong because References 'may be produced by NIST or another organization' and can be 'sector- or technology-specific,' and Examples are similarly not restricted. The fourth option misrepresents both: Examples 'are not a comprehensive list of all actions... nor do they represent a baseline of required actions.'
Source: page 14
Useful

7  Improving Cybersecurity Risk Communication and Integration

p.15–19
Why useful
This section explains how organizations can use the CSF to improve internal communication between executives, managers, and practitioners, and how to integrate cybersecurity risk management with enterprise risk management and other ICT risk programs (privacy, supply chain, AI). While these integration principles are valuable for holistic cybersecurity governance, the section is primarily guidance on organizational implementation strategy rather than core CSF structure or mechanics. The actual CSF Functions, Categories, and Subcategories—the testable content—are presented in the detailed CSF Core section (pages 20-23). This section provides context for why and how to apply the framework, but learners need the structural knowledge first.
Likely tested: ERM integration concepts, risk communication flow between executives/managers/practitioners, GOVERN Function's role in strategy and oversight, integration with NIST RMF and Privacy Framework, cybersecurity supply chain risk management (C-SCRM), and AI risk management considerations.
  • Organizations use the CSF to prioritize cybersecurity activities based on stakeholder expectations and risk appetite, choosing to mitigate, transfer, avoid, or accept risks depending on potential impacts and likelihoods.
    Understanding organizational mission, risks, and risk tolerance enables informed decision-making about cybersecurity expenditures and actions. The CSF can be used both internally to manage capabilities and externally to communicate with third parties.
  • The CSF improves risk management communication through bidirectional information flow between executives, managers, and practitioners across three organizational levels.
    Executives focus on strategy and priorities, managers translate these into achievable cybersecurity objectives and risk targets, and practitioners implement controls and provide operational insights. This flow enables executives to make informed decisions about cybersecurity posture and adjust strategies accordingly.
  • Creating and using Organizational Profiles involves gathering input from executives about priorities and resources, then having managers and practitioners collaborate to identify gaps between Current and Target Profiles and implement actions to close those gaps.
    Results from control implementation and system-level monitoring are shared through risk registers and progress reports, enabling managers to make ongoing adjustments that reduce harms and increase benefits.
  • The GOVERN Function enables executives to establish cybersecurity priorities, integrate cybersecurity risk with enterprise risk management (ERM) programs, and set expectations about risk appetite, accountability, and resources.
    Executive governance discussions address strategy, risk management approaches including supply chain risk, roles and responsibilities, policies, and oversight mechanisms that cascade down to managers and practitioners.
  • Organizations can integrate cybersecurity risk management with ERM to balance a portfolio of risk considerations and translate cybersecurity terminology into general risk management language that executives understand.
    The CSF helps executives receive and integrate cybersecurity risk data with other types of organizational risk, supporting strategic decision-making at the enterprise level.
  • Cybersecurity and privacy are independent disciplines with overlapping objectives - cybersecurity risk management addresses confidentiality, integrity, and availability of data, while privacy risks can arise from data processing activities unrelated to cybersecurity incidents.
    The NIST Privacy Framework and Cybersecurity Framework can be used together to address different aspects of both risk types. Privacy problems range from dignity-type effects like embarrassment to tangible harms such as discrimination or economic loss.
  • Supply chain risk management (SCRM) and cybersecurity SCRM (C-SCRM) are critical because technology products and services depend on complex, globally distributed, interconnected supply chains composed of multiple public and private sector entities.
    C-SCRM is a systematic process for managing cybersecurity exposure throughout supply chains and developing response strategies. The CSF's C-SCRM Category [GV.SC] connects cybersecurity outcomes with supply chain risk management considerations.
  • Organizations should treat emerging technology risks such as artificial intelligence (AI) alongside other enterprise risks to yield integrated outcomes and organizational efficiencies.
    The NIST Artificial Intelligence Risk Management Framework (AI RMF) uses Functions, Categories, and Subcategories to describe AI outcomes. Cybersecurity and privacy risk management approaches are applicable to the design, development, deployment, evaluation, and use of AI systems.

Source: Section 5, pages 15-19

Practice
According to the CSF framework, what is the primary purpose of establishing bidirectional information flow between executives, managers, and practitioners?
  • ATo ensure that executives maintain direct control over all cybersecurity operational decisions made by practitioners
  • BTo enable executives to communicate organizational priorities and strategy while receiving insights from managers and practitioners about cybersecurity risks and their mitigation
  • CTo reduce the need for formal governance structures by allowing practitioners to communicate directly with executives about resource allocation
  • DTo separate cybersecurity risk management from enterprise risk management so that each discipline can be managed independently
The section states that 'The CSF fosters bidirectional information flow between executives who focus on the organization's priorities and strategic direction and managers who manage specific cybersecurity risks' and that 'the left side of the figure indicates the importance of practitioners sharing their updates, insights, and concerns with managers and executives.' This enables communication in both directions - downward for strategy and expectations, and upward for operational insights and risk information. The option about executives maintaining direct control contradicts the collaborative nature described. The option about reducing governance structures is not supported by the text. The option about separating cybersecurity from ERM contradicts Section 5.2, which discusses integration of cybersecurity with ERM programs.
Source: page 15-16
What does the section identify as a key difference between how cybersecurity risks and privacy risks can arise in an organization?
  • APrivacy risks can only result from cybersecurity incidents such as data breaches, whereas cybersecurity risks are always caused by external threat actors
  • BCybersecurity risk management addresses privacy risks related to loss of data confidentiality, integrity, and availability, but privacy risks can also arise from data processing activities unrelated to cybersecurity incidents
  • CPrivacy risks are more difficult to manage than cybersecurity risks because they involve multiple stakeholder groups across the supply chain
  • DCybersecurity frameworks are designed primarily for privacy risk management, while privacy frameworks are designed for cybersecurity risk management
The section explicitly states that 'Cybersecurity risk management is essential for addressing privacy risks related to the loss of the confidentiality, integrity, and availability of individuals' data' but also notes that 'privacy risks can also arise by means that are unrelated to cybersecurity incidents.' It explains that privacy events can result from data processing activities themselves, giving rise to dignity-type effects or tangible harms independent of cybersecurity breaches. The first option incorrectly suggests privacy risks only come from cybersecurity incidents. The third option about supply chains is not the distinction made between these two types of risk. The fourth option reverses the actual relationship between the frameworks.
Source: page 17-18
Must-know

8  CSF Core

p.20–23
Why must-know
This section is the authoritative reference for all six CSF Functions (Govern, Identify, Protect, Detect, Respond, Recover), their 23 Categories, and 98 Subcategories with specific outcomes. It is the operational core of CSF 2.0 that learners must understand to apply the framework; every functional area and testable outcome is defined here with explicit subcategory identifiers and descriptions.
Likely tested: All six CSF Functions and their Categories; the 23 Category identifiers (GV.OC, GV.RM, ID.AM, ID.RA, PR.AA, PR.DS, DE.CM, RS.MA, RC.RP, etc.); specific Subcategories and outcomes such as asset inventories, vulnerability identification, access control, incident response procedures, and recovery plan execution; the hierarchical structure and function of each category within the framework.
  • The CSF Core consists of six Functions - Govern, Identify, Protect, Detect, Respond, and Recover - each containing Categories and Subcategories that organize cybersecurity outcomes.
    The Functions represent the major phases of cybersecurity risk management, from establishing strategy through recovering from incidents. Categories group related outcomes within each Function, and Subcategories specify detailed actions.
  • The Govern Function establishes the organization's cybersecurity risk management strategy, expectations, and policy through six Categories covering organizational context, risk management strategy, roles and responsibilities, policy, oversight, and supply chain risk management.
    Govern is foundational, requiring understanding of mission and stakeholder needs, establishing risk appetite statements, defining clear roles and authorities, communicating policy, monitoring strategy effectiveness, and managing cyber risks from suppliers.
  • The Identify Function ensures the organization understands its current cybersecurity risks through three Categories: Asset Management, Risk Assessment, and Improvement.
    Organizations must maintain inventories of assets, identify vulnerabilities and threats, assess impacts and likelihoods, prioritize risk responses, and continuously identify improvements across all functions.
  • The Protect Function implements safeguards to manage cybersecurity risks across five Categories: Identity Management and Access Control, Awareness and Training, Data Security, Platform Security, and Technology Infrastructure Resilience.
    Protection measures include managing identities and access permissions, providing personnel training, securing data at rest and in transit, maintaining platforms securely, and implementing resilient architectures.
  • The Detect Function finds and analyzes possible cybersecurity attacks and compromises through two Categories: Continuous Monitoring and Adverse Event Analysis.
    Organizations monitor networks, physical environments, personnel activity, and computing systems for anomalies and indicators of compromise, then analyze events to characterize them and declare incidents when criteria are met.
  • The Respond Function manages actions taken regarding detected incidents through four Categories: Incident Management, Incident Analysis, Incident Response Reporting and Communication, and Incident Mitigation.
    Response includes executing incident plans with third parties, triaging and categorizing incidents, investigating root causes, notifying stakeholders as required, and containing and eradicating incidents.
  • The Recover Function restores assets and operations affected by incidents through two Categories: Incident Recovery Plan Execution and Incident Recovery Communication.
    Recovery involves executing recovery plans, verifying backup integrity, restoring systems and services, establishing post-incident operational norms, declaring recovery completion, and communicating progress to stakeholders.
  • Subcategory numbering is intentionally non-sequential with gaps indicating CSF 1.1 Subcategories that were relocated in CSF 2.0.
    The ordering of Functions, Categories, and Subcategories prioritizes operational implementation over alphabetical arrangement, reflecting how organizations structure their risk management activities.

Source: CSF Core, pages 20-23

Practice
According to CSF 2.0, why are the Functions, Categories, and Subcategories of the Core ordered as they are presented?
  • ATo follow a sequential numbering pattern that makes them easier to reference
  • BTo resonate most with those charged with operationalizing risk management within an organization
  • CTo organize them alphabetically for consistency across all NIST guidance documents
  • DTo prioritize the Functions based on how frequently organizations experience incidents in each area
The document explicitly states that 'The order of Functions, Categories, and Subcategories of the Core is not alphabetical; it is intended to resonate most with those charged with operationalizing risk management within an organization.' The other options are incorrect: the numbering is intentionally not sequential (gaps indicate relocated items), there is no requirement for alphabetical organization, and the order is not based on incident frequency.
Source: page 20
In the Govern Function, what is the relationship between Risk Management Strategy and Roles, Responsibilities, and Authorities?
  • ARisk Management Strategy must be established before Roles, Responsibilities, and Authorities can be determined
  • BRoles, Responsibilities, and Authorities must be in place before Risk Management Strategy can be developed
  • CRoles, Responsibilities, and Authorities foster accountability for executing the Risk Management Strategy that has been established
  • DRisk Management Strategy and Roles, Responsibilities, and Authorities are independent Functions with no direct relationship
The GV.RR (Roles, Responsibilities, and Authorities) Category is defined as establishing 'cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement' while GV.RM (Risk Management Strategy) establishes 'the organization's priorities, constraints, risk tolerance and appetite statements, and assumptions.' The document shows these Functions are complementary, with clear roles needed to support and enforce the strategy. The options claiming one must precede the other or that they are independent mischaracterize their coordinated relationship.
Source: pages 21-22
What does the CSF 2.0 identify as a key distinction in how the Govern Function treats cybersecurity supply chain risk compared to general cybersecurity risks?
  • ASupply chain risks should only be addressed at Tier 3 and above maturity levels
  • BSupply chain risk management is integrated throughout cybersecurity and enterprise risk management processes, with dedicated attention to supplier relationships and third-party dependencies
  • CSupply chain risks are managed exclusively through contracts and do not require ongoing monitoring after agreements are established
  • DSupply chain risk management is considered a subset of the Identify Function rather than a distinct governance concern
The Cybersecurity Supply Chain Risk Management (GV.SC) Category explicitly addresses supply chains as an integrated concern across the Govern Function. Subcategories show that supply chain risk management is integrated into cybersecurity and enterprise risk management (GV.SC-03), suppliers are monitored throughout the relationship (GV.SC-07), suppliers are included in incident planning (GV.SC-08), and performance is monitored throughout the technology life cycle (GV.SC-09). The other options misrepresent the scope and permanence of supply chain risk management obligations.
Source: pages 22-23
Must-know

9  CSF Tiers

p.24–25
Why must-know
This section presents the four CSF Tiers in detail through a comprehensive comparison table that is essential to understanding how organizations characterize and measure their cybersecurity maturity. The Tiers are a foundational structural element of CSF 2.0 (referenced throughout the document), and this is the primary reference for how to distinguish between Partial, Risk Informed, Repeatable, and Adaptive maturity levels across governance and management practices. A learner cannot effectively answer questions about organizational cybersecurity posture assessment or CSF application without knowing what distinguishes each Tier.
Likely tested: Characteristics and outcomes of each CSF Tier (Tier 1 through Tier 4); differences between ad hoc/informal practices (Tier 1-2) and formalized/organization-wide approaches (Tier 3-4); risk governance versus risk management distinction across Tiers; supplier and third-party risk management maturity at each level.
  • CSF Tiers characterize the rigor of an organization's cybersecurity risk governance practices (GOVERN function) and cybersecurity risk management practices (IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER functions).
    The four tiers provide a framework for assessing and communicating the maturity level of an organization's approach to managing cybersecurity risks across both strategic governance and operational management.
  • Tier 1 (Partial) represents ad hoc cybersecurity risk management with limited organizational awareness, informal or case-by-case implementation, and minimal supplier risk consideration.
    Organizations at this level lack formalized processes for sharing cybersecurity information internally and do not prioritize cybersecurity activities based on documented objectives or threat environments.
  • Tier 2 (Risk Informed) involves management-approved risk management practices that inform cybersecurity prioritization but lack organization-wide policy and consistent formal response to supplier risks.
    Cybersecurity awareness exists at the organizational level, and cyber risk assessments occur, but these efforts are not repeatable or consistently applied across all organizational levels.
  • Tier 3 (Repeatable) establishes formally approved risk management policies with consistent implementation, regular updates based on changing requirements and threats, and formal supplier risk management mechanisms.
    Organizations at this level routinely share cybersecurity information, maintain consistent response methods to risk changes, and ensure personnel have the knowledge and skills for their roles, with senior executives regularly communicating about cybersecurity risks.
  • Tier 4 (Adaptive) represents organization-wide cybersecurity risk management integrated with organizational objectives, using real-time information and continuous improvement to adapt to evolving threats and technological changes.
    At this level, cybersecurity risk management is embedded in organizational culture, executives monitor cybersecurity risks alongside financial and other organizational risks, and the organization responds in real-time to supplier and external risks using advanced technologies and predictive indicators.

Source: CSF Tiers, pages 24-25

Practice
What is the primary difference between how Tier 2 and Tier 3 organizations prioritize cybersecurity activities?
  • ATier 2 uses ad hoc prioritization while Tier 3 uses risk-informed policies and procedures that are formally approved and implemented
  • BTier 2 has organization-wide awareness while Tier 3 only considers cybersecurity at some levels
  • CTier 2 shares cybersecurity information formally while Tier 3 shares it only informally
  • DTier 2 uses real-time information to manage risks while Tier 3 uses historical data
The correct answer identifies that Tier 2 prioritization is 'directly informed by organizational risk objectives' but 'may not be established as organization-wide policy,' whereas Tier 3 has 'risk-informed policies, processes, and procedures [that] are defined, implemented as intended, and reviewed.' The second option inverts the actual characteristics - Tier 2 has 'awareness' but an org-wide approach is 'not established,' while Tier 3 has an 'organization-wide approach.' The third option contradicts the text - Tier 2 shares info 'on an informal basis' while Tier 3 shares it 'routinely.' The fourth option misattributes Tier 4 characteristics (real-time information) to Tier 2.
Source: pages 24-25, Table 2
In a Tier 4 organization, how does cybersecurity risk management differ from Tier 3 in terms of adaptation to changing conditions?
  • ATier 4 continuously improves and actively adapts based on lessons learned and predictive indicators, while Tier 3 only updates practices based on application of risk management processes to changes
  • BTier 4 relies on informal awareness of threats while Tier 3 requires formal approved policies
  • CTier 4 shares cybersecurity information only within the organization while Tier 3 shares it with external parties
  • DTier 4 prioritizes cybersecurity based on ad hoc business needs while Tier 3 uses formal organizational objectives
The correct answer accurately describes Tier 4's 'process of continuous improvement that incorporates advanced cybersecurity technologies and practices' and active adaptation to 'a changing technological landscape,' contrasted with Tier 3's updates 'based on the application of risk management processes to changes in business/mission requirements, threats, and technological landscape.' The second option reverses the characteristics - Tier 3 has 'formally approved' practices while Tier 4 goes beyond that. The third option contradicts the text - Tier 4 shares information 'constantly throughout the organization and with authorized third parties,' whereas Tier 3 shares 'routinely shared throughout the organization' without mention of external parties. The fourth option mischaracterizes both tiers by suggesting ad hoc approaches.
Source: pages 24-25, Table 2
What does the CSF Tiers table indicate about supplier risk awareness and management across the four tiers?
  • AOrganizations progress from being unaware of supplier risks at Tier 1 to using real-time information to manage supplier risks at Tier 4
  • BAll tiers share supplier risk information equally with external parties to ensure transparency
  • CTier 3 organizations completely eliminate supplier risks through written agreements
  • DSupplier risk management is not addressed in the NIST Cybersecurity Framework
The correct answer traces the progression: Tier 1 is 'generally unaware of the cybersecurity risks associated with its suppliers,' Tier 2 is 'aware' but 'does not act consistently or formally,' Tier 3 has 'formally act upon those risks through mechanisms such as written agreements,' and Tier 4 'uses real-time or near real-time information to understand and consistently act upon the cybersecurity risks associated with its suppliers and the products and services it acquires and uses.' The second option overstates the external sharing - while Tier 4 shares 'with authorized third parties,' not all tiers share equally or with external parties. The third option incorrectly suggests that agreements eliminate risks rather than manage them. The fourth option contradicts the table's explicit inclusion of supplier risk discussions at each tier level.
Source: pages 24-25, Table 2
Must-know

10  Glossary

p.26–26
Why must-know
The glossary defines essential CSF terminology that is foundational to understanding the entire framework - CSF Core, Functions, Categories, Subcategories, Organizational Profiles, Tiers, and supplementary resources like Implementation Examples and Informative References. Learners must understand these terms precisely to apply the CSF and answer exam questions about its structure and components.
Likely tested: Definitions of CSF Core, Functions, Categories, Subcategories, Current Profile, Target Profile, Organizational Profile, Tiers (Partial, Risk Informed, Repeatable, Adaptive), Informative References, Implementation Examples, and Community Profiles.
  • The CSF Core is a taxonomy of high-level cybersecurity outcomes organized hierarchically into six Functions, 22 Categories, and multiple Subcategories that any organization can use to manage cybersecurity risks.
    The Functions are the highest level of organization, Categories group related outcomes within Functions, and Subcategories detail more specific technical and management activities that achieve those outcomes.
  • A CSF Organizational Profile is a mechanism that describes an organization's current and target cybersecurity posture using CSF Core outcomes, comprising a Current Profile (what is being achieved) and a Target Profile (what is desired).
    Organizations use profiles to align their cybersecurity posture with business objectives and prioritize which outcomes to achieve.
  • CSF Tiers characterize the rigor of an organization's cybersecurity risk governance and management practices on a scale from Partial (Tier 1) to Adaptive (Tier 4).
    Tiers help organizations understand and communicate the maturity level of their risk management approach.
  • A CSF Community Profile is a baseline of CSF outcomes created for a particular sector, subsector, technology, threat type, or use case that organizations can adopt as the foundation for their own Target Profile.
    Community Profiles address shared interests and goals among multiple organizations in similar contexts.
  • CSF Informative References are mappings that show relationships between CSF Core outcomes and existing standards, guidelines, regulations, or other content.
    These references help organizations understand how the CSF connects to other frameworks and compliance requirements.
  • CSF Implementation Examples are concise, action-oriented illustrations of practical ways to achieve specific CSF Core outcomes.
    These examples provide guidance on how to operationalize the outcomes in organizational practice.
  • CSF Quick Start Guides are supplementary resources that provide brief, actionable guidance on specific CSF-related topics.
    These guides help organizations quickly understand and apply CSF concepts to their particular context.

Source: Appendix C. Glossary, pages 26 and 31-32

Practice
What is the primary distinction between a CSF Current Profile and a CSF Target Profile within an Organizational Profile?
  • AThe Current Profile describes desired outcomes while the Target Profile describes outcomes being achieved
  • BThe Current Profile specifies outcomes currently being achieved while the Target Profile specifies desired outcomes that have been selected and prioritized
  • CThe Current Profile is used only for Tier 1 organizations while the Target Profile is used for Tier 2 and above
  • DThe Current Profile applies to Community Profiles while the Target Profile applies only to individual organizations
According to the glossary, a CSF Current Profile 'specifies the Core outcomes that an organization is currently achieving (or attempting to achieve)' while a CSF Target Profile 'specifies the desired Core outcomes that an organization has selected and prioritized for achieving its cybersecurity risk management objectives.' The first option reverses this relationship. The third option incorrectly ties these concepts to specific Tiers, which is not stated in the glossary. The fourth option incorrectly restricts where these profiles apply.
Source: page 26, Glossary
How does a Community Profile relate to an organization's Target Profile?
  • AA Community Profile is created by individual organizations to replace their Target Profile
  • BAn organization can use a Community Profile as the basis for developing its own Target Profile
  • CA Community Profile and Target Profile serve identical purposes within an Organizational Profile
  • DA Community Profile is only applicable to organizations operating in Tier 3 or Tier 4
The glossary explicitly states that 'An organization can use a Community Profile as the basis for its own Target Profile.' Community Profiles are created and published to address shared interests and goals among multiple organizations, typically for particular sectors or use cases. The first option incorrectly suggests replacement rather than a basis. The third option falsely claims they are identical. The fourth option incorrectly restricts Community Profiles to specific Tiers.
Source: page 26, Glossary
Which of the following best describes the relationship between the CSF Core and CSF Functions?
  • ACSF Functions are the lowest level of organization within the CSF Core's hierarchy
  • BCSF Functions are the highest level of organization for cybersecurity outcomes within the CSF Core
  • CCSF Functions and the CSF Core are separate frameworks that do not relate to each other
  • DCSF Functions are supplementary resources that map the CSF Core to external standards
The glossary defines a CSF Function as 'the highest level of organization for cybersecurity outcomes' and notes there are six Functions, while the CSF Core is described as 'a taxonomy of high-level cybersecurity outcomes' whose components are 'a hierarchy of Functions, Categories, and Subcategories.' The first option reverses the hierarchy. The third option incorrectly separates them. The fourth option confuses Functions with CSF Informative References, which are mappings to external standards.
Source: page 26, Glossary
Skippable

11  Back Matter

p.27–32
Why skippable
This section contains only administrative and procedural information: copyright disclaimers, citation guidance, publication metadata, and contact details. None of this content relates to the CSF concepts, governance practices, or risk management guidance that would appear on an exam or certification.
Likely tested: none
  • Identification of commercial products in the document does not constitute NIST endorsement or recommendation of those products or services.
    NIST clarifies that mentioning specific equipment, software, or materials is done only to describe procedures adequately and does not imply these are the best available options or that NIST recommends them.
  • The proper citation for NIST CSF 2.0 is: National Institute of Standards and Technology (2024) The NIST Cybersecurity Framework (CSF) 2.0 (National Institute of Standards and Technology, Gaithersburg, MD), NIST Cybersecurity White Paper (CSWP) NIST CSWP 29, with DOI 10.6028/NIST.CSWP.29.
    This standardized citation format should be used when referencing the NIST CSF 2.0 document in other publications or materials.
  • Questions and comments about NIST CSF 2.0 can be directed to cyberframework@nist.gov or the Applied Cybersecurity Division at the provided postal address.
    NIST provides contact information for inquiries about the framework, with both email and mailing address available for the Information Technology Laboratory in Gaithersburg, Maryland.
  • All comments submitted to NIST regarding this document are subject to release under the Freedom of Information Act (FOIA).
    Contributors and commenters should be aware that their submissions may be made publicly available through FOIA requests.

Source: Back Matter, pages 27-32

Get this for your own book

The same thing for your textbook, certification guide or vendor documentation — up to a few hundred pages. StudySift opens shortly, and everyone on the list gets double credit on their first top-up.