โ† All cheat sheets

NIST-CSF2

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

- Released February 2024, replacing CSF 1.1
- Applies to ALL organizations, not just critical infrastructure
- Adds GOVERN as the 6th core function
- Emphasizes governance, supply chain risk, and continuous improvement
- Free framework; voluntary adoption but widely referenced in regulation

THE 6 CORE FUNCTIONS#

1. GOVERN (GV) - NEW in 2.0
   Establishes and monitors cybersecurity risk management strategy,
   expectations, and policy. Cross-cutting function that informs all others.

2. IDENTIFY (ID)
   Understand the organization's current cybersecurity risks to systems,
   assets, data, and capabilities.

3. PROTECT (PR)
   Implement safeguards to ensure delivery of critical services and
   reduce the likelihood and impact of cybersecurity events.

4. DETECT (DE)
   Develop and implement activities to identify the occurrence of a
   cybersecurity event in a timely manner.

5. RESPOND (RS)
   Take action regarding a detected cybersecurity incident to contain
   its impact.

6. RECOVER (RC)
   Maintain plans for resilience and restore capabilities or services
   impaired due to a cybersecurity incident.

GOVERN (GV) - CATEGORIES#

GV.OC  Organizational Context
GV.RM  Risk Management Strategy
GV.RR  Roles, Responsibilities, and Authorities
GV.PO  Policy
GV.OV  Oversight
GV.SC  Cybersecurity Supply Chain Risk Management

IDENTIFY (ID) - CATEGORIES#

ID.AM  Asset Management
ID.RA  Risk Assessment
ID.IM  Improvement

PROTECT (PR) - CATEGORIES#

PR.AA  Identity Management, Authentication, and Access Control
PR.AT  Awareness and Training
PR.DS  Data Security
PR.PS  Platform Security
PR.IR  Technology Infrastructure Resilience

DETECT (DE) - CATEGORIES#

DE.CM  Continuous Monitoring
DE.AE  Adverse Event Analysis

RESPOND (RS) - CATEGORIES#

RS.MA  Incident Management
RS.AN  Incident Analysis
RS.CO  Incident Response Reporting and Communication
RS.MI  Incident Mitigation

RECOVER (RC) - CATEGORIES#

RC.RP  Incident Recovery Plan Execution
RC.CO  Incident Recovery Communication

IMPLEMENTATION TIERS#

Tier 1 - Partial
  - Ad hoc, reactive risk management
  - Limited awareness of cyber risk
  - No formalized processes
  - Irregular, case-by-case external participation

Tier 2 - Risk Informed
  - Risk management approved by management but not org-wide policy
  - Awareness exists but no consistent practice
  - Some processes exist but not standardized
  - Organization understands its ecosystem role

Tier 3 - Repeatable
  - Risk management formally approved and expressed as policy
  - Practices regularly updated based on risk assessment
  - Organization-wide approach to managing cyber risk
  - Active collaboration with external partners

Tier 4 - Adaptive
  - Continuous improvement using lessons learned and predictive indicators
  - Cyber risk management is part of organizational culture
  - Active adaptation to changing threat landscape
  - Proactive contribution to broader cybersecurity ecosystem

PROFILES#

- Current Profile: documents present cybersecurity posture
- Target Profile: describes desired cybersecurity outcome state
- Gap Analysis: comparison between Current and Target to inform priorities
- Community Profiles: shared baselines for specific sectors/use cases

CSF 2.0 vs CSF 1.1 KEY CHANGES#

- Added GOVERN function (biggest change)
- Expanded scope beyond critical infrastructure to all organizations
- Enhanced supply chain risk management guidance (GV.SC)
- Improved alignment with other frameworks (ISO, COBIT, CIS)
- Introduced Community Profiles concept
- Simplified and consolidated subcategories
- Added implementation examples for each subcategory
- Stronger emphasis on continuous improvement (ID.IM)

MAPPING TO OTHER FRAMEWORKS#

NIST CSF 2.0          ISO 27001:2022       CIS Controls v8
-----------           -------------        ---------------
GV (Govern)           A.5 (Org Controls)   CIS 1-3
ID.AM (Assets)        A.5.9, A.5.10        CIS 1, 2
ID.RA (Risk)          A.5.7, A.8.2-8.3     CIS 3
PR.AA (Access)        A.5.15-5.18, A.8.5   CIS 5, 6
PR.AT (Training)      A.6.3                CIS 14
PR.DS (Data)          A.5.33-5.34, A.8.10  CIS 3
PR.PS (Platform)      A.8.8-8.9            CIS 4, 7, 18
DE.CM (Monitoring)    A.8.15-8.16          CIS 8, 13
DE.AE (Analysis)      A.5.25               CIS 8
RS.MA (Incident)      A.5.24-5.28          CIS 17
RC.RP (Recovery)      A.5.29-5.30          CIS 17

NIST CSF 2.0          NIST SP 800-53 r5    SOC 2 TSC
-----------           -----------------    ---------
GV (Govern)           PM family            CC1, CC2
ID (Identify)         RA, PM, SA families  CC3, CC6
PR (Protect)          AC, AT, SC, SI       CC5, CC6, CC7
DE (Detect)           AU, SI, IR           CC7
RS (Respond)          IR, SI               CC7
RC (Recover)          CP                   A1

PRACTICAL IMPLEMENTATION STEPS#

1. Scope the assessment (business units, systems, data)
2. Build Current Profile using self-assessment or audit
3. Define Target Profile based on risk appetite and requirements
4. Perform gap analysis (Current vs Target)
5. Prioritize gaps using risk-based approach
6. Create action plan with milestones and owners
7. Implement controls aligned to framework categories
8. Monitor and measure progress continuously
9. Update profiles regularly (at least annually)

QUICK REFERENCE RESOURCES#

- NIST CSF 2.0 Full Document: nist.gov/cyberframework
- Informative References: csf.tools
- Implementation Examples: included in CSF 2.0 document
- NIST SP 800-53 mapping: csf.tools/reference
- Community Profiles: nist.gov/cyberframework/profiles

COMMON AUDIT QUESTIONS#

- How is cybersecurity governance structured? (GV.RR)
- What is the risk management strategy? (GV.RM)
- Is there a current asset inventory? (ID.AM)
- How are risks assessed and prioritized? (ID.RA)
- What access control mechanisms are in place? (PR.AA)
- How is security awareness training delivered? (PR.AT)
- What continuous monitoring capabilities exist? (DE.CM)
- Is there a tested incident response plan? (RS.MA)
- What are the recovery time objectives? (RC.RP)
- How is supply chain risk managed? (GV.SC)