NIST Cybersecurity Framework
The NIST Cybersecurity Framework is flexible guidance for managing cybersecurity risk. It gives organizations a shared set of outcomes for understanding priorities, describing current and target practices, and communicating what should improve.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — NIST Cybersecurity Framework
The NIST Cybersecurity Framework, or CSF, is a way to talk about cybersecurity risk without pretending that one spreadsheet can operate a security program. It gives people who make decisions, people who run systems, and people who ask awkward questions about both a shared language. This is unusually useful. Cybersecurity conversations otherwise tend to arrive as a mixed bag of controls, budgets, alarms, and nouns with capital letters.
The useful bit is the CSF Core. It organizes outcomes into Functions, Categories, and Subcategories. An outcome says what needs to be true, not which product, process, or heroic Tuesday evening produces it. That distinction saves considerable trouble. A list of outcomes is not a control library wearing a sensible hat.
The six Functions provide the map: Govern, Identify, Protect, Detect, Respond, and Recover. They are concurrent, not a relay race in which Recover waits patiently at the finish line. Govern matters because it connects risk decisions to mission, expectations, roles, oversight, and resources. The remaining Functions describe the work that makes those decisions real.
An Organizational Profile is where this broad map meets one actual boundary: a service, system, organization, or risk. A Current Profile records what is achieved or attempted, with evidence. A Target Profile records what is needed. Comparing them reveals gaps. It does not reveal a magical priority order, because risk, dependencies, resources, and mission consequences refuse to live inside one magic number.
That is the surprise: the framework is deliberately not a compliance certificate or an implementation recipe. An Implementation Tier describes how rigorous the scoped risk governance and management need to be. It is not a score to maximize. Tier 4 is not a prize for collecting enough colored cells.
Read the Intro when you need the complete map and the relationship between outcomes, Profiles, Tiers, and evidence. Use the Cheatsheet when you need the hierarchy, Profile cycle, evidence patterns, and review questions nearby. The Exercise turns one bounded fictional service into a Profile and action plan. The Reference tab supplies NIST's framework, templates, guides, mappings, and the Reference Tool for the details that this overview wisely declines to staple to your desk.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://doi.org/10.6028/NIST.CSWP.29
Supports
- CSF 2.0 purpose, audience, flexibility, and technology-neutral outcome model
- Core, Organizational Profile, and Implementation Tier components
- Function, Category, and Subcategory hierarchy
- Names and purposes of Govern, Identify, Protect, Detect, Respond, and Recover
- Concurrent operation of the Functions
- Current, Target, and Community Profile definitions
- Seven-step example cycle for creating and using an Organizational Profile
- Four Tier names and their use in characterizing governance and management rigor
- Informative References, Implementation Examples, Quick Start Guides, and Profile templates
- CSF use for understanding, assessing, prioritizing, and communicating cybersecurity risk
- https://www.nist.gov/cyberframework
Supports
- Current official CSF 2.0 resource hub
- Availability of the framework document, Quick Start Guides, Profiles, mappings, videos, translations, and tool
- https://www.nist.gov/cyberframework/faqs
Supports
- Govern added in CSF 2.0 to emphasize cybersecurity governance
- Core outcomes as non-prescriptive
- Four Tier names and interpretation
- Current and Target Profile use in finding gaps and prioritizing action
- Informative References and Implementation Examples as non-exhaustive
- Reference Tool export in JSON and Excel
- https://www.nist.gov/cyberframework/profiles
Supports
- Organizational Profile template for Current and Target comparison
- Community Profile definition and examples
- Community Profiles as resources for applying the CSF
- https://www.nist.gov/cyberframework/quick-start-guides
Supports
- Available official guides for Profiles, Tiers, small businesses, supply chain risk, enterprise risk management, workforce management, and Informative References
- Purpose of each guide listed in the Reference path
- https://www.nist.gov/cyberframework/informative-references
Supports
- Informative References as mappings between CSF outcomes and other documents
- Availability of Core, Implementation Example, and mapping data
- https://github.com/sindresorhus/awesome
Supports
- Discovery of the Awesome Security list from the curated Awesome index
- https://github.com/sbilly/awesome-security
Supports
- Inclusion of OpenVAS, Wazuh, Security Onion, and Lynis in the fetched security ecosystem list
- Discovery descriptions for vulnerability scanning, monitoring, detection, response, and auditing tools
- https://greenbone.github.io/docs/latest/background
Supports
- OpenVAS as a scan engine executing vulnerability tests against target systems
- Greenbone components for vulnerability scanning and vulnerability management
- https://wazuh.com/platform/overview/
Supports
- Wazuh system inventory, vulnerability detection, file integrity monitoring, and security monitoring capabilities
- https://docs.securityonion.net/en/3/main/introduction/
Supports
- Security Onion network visibility, host visibility, intrusion detection, log management, threat hunting, and case management capabilities
- https://cisofy.com/documentation/lynis/
Supports
- Lynis as an open source audit tool for Unix-like systems
- Lynis reporting, warnings, suggestions, hardening guidance, and compliance-testing support
- https://www.nist.gov/cyberframework/framework-development-archive
Supports
- 2013 request for information and Preliminary Framework milestones
- CSF 1.0 release in February 2014
- Cybersecurity Enhancement Act of 2014
- CSF 1.1 draft milestones
- https://www.nist.gov/news-events/news/2018/04/nist-releases-version-11-its-popular-cybersecurity-framework
Supports
- CSF 1.1 release on April 16, 2018 and its refinement of the Framework
- https://www.nist.gov/cyberframework/nists-journey-csf-20
Supports
- CSF 2.0 development beginning in 2022
- CSF 1.0, 1.1, and 2.0 release years
- CSF 2.0 concept-paper, Core-draft, and public-draft progression
- https://csrc.nist.gov/news/2023/nist-releases-cybersecurity-framework-2-0-draft
Supports
- CSF 2.0 public draft release in August 2023 and implementation examples
- https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
Supports
- CSF 2.0 release in February 2024
- CSF 2.0 expansion to all organizations and addition of Govern
- https://www.servicenow.com/products/integrated-risk-management.html
Supports
- ServiceNow Integrated Risk Management capabilities for risk, compliance, evidence, issues, and remediation workflows
- https://www.metricstream.com/products/cyber-grc.htm
Supports
- MetricStream Cyber GRC support for NIST CSF-aligned cyber risk, policy, control, and exception management
- https://www.archerirm.com/
Supports
- Archer Integrated Risk Management product availability
- https://www.onetrust.com/solutions/grc/
Supports
- OneTrust governance, risk, and compliance product availability
- https://www.logicgate.com/risk-cloud/
Supports
- LogicGate Risk Cloud product availability for risk and compliance workflows
