NIST Cybersecurity Framework

Also known as: NIST CSF

framework · cybersecurity · regulatory-standard

Six core functions (Govern, Identify, Protect, Detect, Respond, Recover) plus implementation tiers and profiles.

The NIST CSF provides a voluntary risk-based framework for organizations to manage cybersecurity, organized around six core functions (Govern, Identify, Protect, Detect, Respond, Recover) — Govern was added in version 2.0 released in 2024 — alongside categories, subcategories, and informative references mapping to specific controls in frameworks like NIST 800-53. The framework was originally developed under Executive Order 13636 to improve critical infrastructure cybersecurity and has been broadly adopted across critical infrastructure sectors and beyond, including international adoption. Implementation tiers and target/current state profiles allow organizations to articulate cybersecurity maturity and improvement roadmaps in a standardized vocabulary.

Originators

National Institute of Standards and Technology (NIST) high

Year / Decade

2014 (v1.0); 2018 (v1.1); 2024 (v2.0) high

Primary sources

NIST (2014). Framework for Improving Critical Infrastructure Cybersecurity v1.0, NIST (2024). Cybersecurity Framework v2.0 high

Core components

Primary use case

Cybersecurity risk management for critical infrastructure and other organizations; common vocabulary for cybersecurity maturity discussions; mapping organizational controls to standardized outcomes.

Common criticisms

Lineage

Siblings
ISO/IEC 27001, CIS Controls, NIST 800-53, NIST Risk Management Framework