NIST Cybersecurity Framework 2.0 Resource and Overview Guide

NIST Special Publication NIST SP 12991299

NIST Cybersecurity Framework (CSFCSF) 2.02.0: Resource & Overview Guide (February 20242024). Published by the National Institute of Standards and Technology, U.S. Department of Commerce.

Understanding and Utilizing CSF 2.02.0

The NIST Cybersecurity Framework (CSFCSF) 2.02.0 provides outcomes to manage and reduce cybersecurity risks. It is organized by six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. The framework includes:

  • CSF Core: A taxonomy of high-level outcomes.

  • CSF Organizational Profiles: Documentation of current and/or target cybersecurity posture.

  • CSF Tiers: Metrics to characterize the rigor of an organization’s risk governance and management.

Explore CSF 2.02.0 Resources

  • Informative References: Mappings between CSFCSF 2.02.0 and other documents.

  • Cybersecurity & Privacy Reference Tool (CPRT): Standardized mechanism for managing and downloading reference datasets.

  • Implementation Examples: Action-oriented steps for CSFCSF Subcategories.

  • CSF 2.02.0 Reference Tool: Human and machine-readable versions of the Core in JSON and Excel.

  • Additional Assets: Community Profiles, Search tools, Concept papers, and FAQs.

Quick Start Guides (QSG)

NIST provides specialized guides to assist specific audiences:

  • Small Business (SMB): Strategy for organizations with modest cybersecurity plans.

  • Creating and Using Organizational Profiles: Guidance on implementing Current and Target Profiles.

  • Using the CSF Tiers: Applying Tiers to Organizational Profiles.

  • Draft Cybersecurity Supply Chain Risk Management (C-SCRM): Improving processes for acquirers and suppliers of technology.

  • Draft Enterprise Risk Management (ERM) Practitioners: Integrating CSFCSF outcomes into broader ERM practices.

Govern and Identify Functions

Govern: Focuses on establishing and monitoring the organization’s cybersecurity risk management strategy, expectations, and policy. Key actions include determining risk appetite, defining roles/responsibilities, and establishing Cybersecurity Supply Chain Risk Management (CSCRMC-SCRM).

Identify: Focuses on understanding current risks. Key actions include identifying critical business processes, maintaining inventories of hardware/software/services, documenting information flows, and maintaining risk registers.

Protect and Detect Functions

Protect: Focuses on safeguards to manage risks. Key actions include access management (authentication and unique accounts), user training, device security (endpoint protection and configuration), data encryption, and regular backups maintained offline (11 set) to protect against ransomware.

Detect: Focuses on finding and analyzing potential attacks. Key actions include continuous network/facility monitoring, collecting log information, and conducting impact analysis for detected events.

Respond and Recover Functions

Respond: Actions taken once an incident is detected. Key actions include executing incident response plans, prioritizing incidents by root cause, preserving data integrity, and notifying internal/external stakeholders.

Recover: Restoring assets and operations. Key actions include prioritizing recovery tasks, verifying the integrity of backups before use, and communicating lessons learned and revisions to processes to the staff.

Administrative Recognition

  • U.S. Department of Commerce: Secretary Gina M. Raimondo.

  • NIST: Laurie E. Locascio, Director and Under Secretary of Commerce for Standards and Technology.