NIST-CSF2
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
- Released February 2024, replacing CSF 1.1 - Applies to ALL organizations, not just critical infrastructure - Adds GOVERN as the 6th core function - Emphasizes governance, supply chain risk, and continuous improvement - Free framework; voluntary adoption but widely referenced in regulation
THE 6 CORE FUNCTIONS#
1. GOVERN (GV) - NEW in 2.0 Establishes and monitors cybersecurity risk management strategy, expectations, and policy. Cross-cutting function that informs all others. 2. IDENTIFY (ID) Understand the organization's current cybersecurity risks to systems, assets, data, and capabilities. 3. PROTECT (PR) Implement safeguards to ensure delivery of critical services and reduce the likelihood and impact of cybersecurity events. 4. DETECT (DE) Develop and implement activities to identify the occurrence of a cybersecurity event in a timely manner. 5. RESPOND (RS) Take action regarding a detected cybersecurity incident to contain its impact. 6. RECOVER (RC) Maintain plans for resilience and restore capabilities or services impaired due to a cybersecurity incident.
GOVERN (GV) - CATEGORIES#
GV.OC Organizational Context GV.RM Risk Management Strategy GV.RR Roles, Responsibilities, and Authorities GV.PO Policy GV.OV Oversight GV.SC Cybersecurity Supply Chain Risk Management
IDENTIFY (ID) - CATEGORIES#
ID.AM Asset Management ID.RA Risk Assessment ID.IM Improvement
PROTECT (PR) - CATEGORIES#
PR.AA Identity Management, Authentication, and Access Control PR.AT Awareness and Training PR.DS Data Security PR.PS Platform Security PR.IR Technology Infrastructure Resilience
DETECT (DE) - CATEGORIES#
DE.CM Continuous Monitoring DE.AE Adverse Event Analysis
RESPOND (RS) - CATEGORIES#
RS.MA Incident Management RS.AN Incident Analysis RS.CO Incident Response Reporting and Communication RS.MI Incident Mitigation
RECOVER (RC) - CATEGORIES#
RC.RP Incident Recovery Plan Execution RC.CO Incident Recovery Communication
IMPLEMENTATION TIERS#
Tier 1 - Partial - Ad hoc, reactive risk management - Limited awareness of cyber risk - No formalized processes - Irregular, case-by-case external participation Tier 2 - Risk Informed - Risk management approved by management but not org-wide policy - Awareness exists but no consistent practice - Some processes exist but not standardized - Organization understands its ecosystem role Tier 3 - Repeatable - Risk management formally approved and expressed as policy - Practices regularly updated based on risk assessment - Organization-wide approach to managing cyber risk - Active collaboration with external partners Tier 4 - Adaptive - Continuous improvement using lessons learned and predictive indicators - Cyber risk management is part of organizational culture - Active adaptation to changing threat landscape - Proactive contribution to broader cybersecurity ecosystem
PROFILES#
- Current Profile: documents present cybersecurity posture - Target Profile: describes desired cybersecurity outcome state - Gap Analysis: comparison between Current and Target to inform priorities - Community Profiles: shared baselines for specific sectors/use cases
CSF 2.0 vs CSF 1.1 KEY CHANGES#
- Added GOVERN function (biggest change) - Expanded scope beyond critical infrastructure to all organizations - Enhanced supply chain risk management guidance (GV.SC) - Improved alignment with other frameworks (ISO, COBIT, CIS) - Introduced Community Profiles concept - Simplified and consolidated subcategories - Added implementation examples for each subcategory - Stronger emphasis on continuous improvement (ID.IM)
MAPPING TO OTHER FRAMEWORKS#
NIST CSF 2.0 ISO 27001:2022 CIS Controls v8 ----------- ------------- --------------- GV (Govern) A.5 (Org Controls) CIS 1-3 ID.AM (Assets) A.5.9, A.5.10 CIS 1, 2 ID.RA (Risk) A.5.7, A.8.2-8.3 CIS 3 PR.AA (Access) A.5.15-5.18, A.8.5 CIS 5, 6 PR.AT (Training) A.6.3 CIS 14 PR.DS (Data) A.5.33-5.34, A.8.10 CIS 3 PR.PS (Platform) A.8.8-8.9 CIS 4, 7, 18 DE.CM (Monitoring) A.8.15-8.16 CIS 8, 13 DE.AE (Analysis) A.5.25 CIS 8 RS.MA (Incident) A.5.24-5.28 CIS 17 RC.RP (Recovery) A.5.29-5.30 CIS 17 NIST CSF 2.0 NIST SP 800-53 r5 SOC 2 TSC ----------- ----------------- --------- GV (Govern) PM family CC1, CC2 ID (Identify) RA, PM, SA families CC3, CC6 PR (Protect) AC, AT, SC, SI CC5, CC6, CC7 DE (Detect) AU, SI, IR CC7 RS (Respond) IR, SI CC7 RC (Recover) CP A1
PRACTICAL IMPLEMENTATION STEPS#
1. Scope the assessment (business units, systems, data) 2. Build Current Profile using self-assessment or audit 3. Define Target Profile based on risk appetite and requirements 4. Perform gap analysis (Current vs Target) 5. Prioritize gaps using risk-based approach 6. Create action plan with milestones and owners 7. Implement controls aligned to framework categories 8. Monitor and measure progress continuously 9. Update profiles regularly (at least annually)
QUICK REFERENCE RESOURCES#
- NIST CSF 2.0 Full Document: nist.gov/cyberframework - Informative References: csf.tools - Implementation Examples: included in CSF 2.0 document - NIST SP 800-53 mapping: csf.tools/reference - Community Profiles: nist.gov/cyberframework/profiles
COMMON AUDIT QUESTIONS#
- How is cybersecurity governance structured? (GV.RR) - What is the risk management strategy? (GV.RM) - Is there a current asset inventory? (ID.AM) - How are risks assessed and prioritized? (ID.RA) - What access control mechanisms are in place? (PR.AA) - How is security awareness training delivered? (PR.AT) - What continuous monitoring capabilities exist? (DE.CM) - Is there a tested incident response plan? (RS.MA) - What are the recovery time objectives? (RC.RP) - How is supply chain risk managed? (GV.SC)