NIST Cybersecurity Framework
Also known as: NIST CSF
Six core functions (Govern, Identify, Protect, Detect, Respond, Recover) plus implementation tiers and profiles.
The NIST CSF provides a voluntary risk-based framework for organizations to manage cybersecurity, organized around six core functions (Govern, Identify, Protect, Detect, Respond, Recover) — Govern was added in version 2.0 released in 2024 — alongside categories, subcategories, and informative references mapping to specific controls in frameworks like NIST 800-53. The framework was originally developed under Executive Order 13636 to improve critical infrastructure cybersecurity and has been broadly adopted across critical infrastructure sectors and beyond, including international adoption. Implementation tiers and target/current state profiles allow organizations to articulate cybersecurity maturity and improvement roadmaps in a standardized vocabulary.
Core components
- Six core functions: Govern, Identify, Protect, Detect, Respond, Recover
- Categories and subcategories under each function
- Implementation tiers (1-4)
- Profiles (current state and target state)
- Informative references mapping to control catalogs
Primary use case
Cybersecurity risk management for critical infrastructure and other organizations; common vocabulary for cybersecurity maturity discussions; mapping organizational controls to standardized outcomes.
Common criticisms
- Voluntary nature limits enforcement
- outcome-focused approach can leave implementation ambiguity
- substantial mapping work needed when organizations also follow ISO 27001 or other standards
- subcategories number in the hundreds, creating coverage burden.
Lineage
- Siblings
- ISO/IEC 27001, CIS Controls, NIST 800-53, NIST Risk Management Framework