openskills.info
NIST Cybersecurity Framework logoOpen Course

NIST Cybersecurity Framework

The NIST Cybersecurity Framework is flexible guidance for managing cybersecurity risk. It gives organizations a shared set of outcomes for understanding priorities, describing current and target practices, and communicating what should improve.

itCybersecurity fundamentals and governance

Don't Panic — NIST Cybersecurity Framework

The NIST Cybersecurity Framework, or CSF, is a way to talk about cybersecurity risk without pretending that one spreadsheet can operate a security program. It gives people who make decisions, people who run systems, and people who ask awkward questions about both a shared language. This is unusually useful. Cybersecurity conversations otherwise tend to arrive as a mixed bag of controls, budgets, alarms, and nouns with capital letters.

The useful bit is the CSF Core. It organizes outcomes into Functions, Categories, and Subcategories. An outcome says what needs to be true, not which product, process, or heroic Tuesday evening produces it. That distinction saves considerable trouble. A list of outcomes is not a control library wearing a sensible hat.

The six Functions provide the map: Govern, Identify, Protect, Detect, Respond, and Recover. They are concurrent, not a relay race in which Recover waits patiently at the finish line. Govern matters because it connects risk decisions to mission, expectations, roles, oversight, and resources. The remaining Functions describe the work that makes those decisions real.

An Organizational Profile is where this broad map meets one actual boundary: a service, system, organization, or risk. A Current Profile records what is achieved or attempted, with evidence. A Target Profile records what is needed. Comparing them reveals gaps. It does not reveal a magical priority order, because risk, dependencies, resources, and mission consequences refuse to live inside one magic number.

That is the surprise: the framework is deliberately not a compliance certificate or an implementation recipe. An Implementation Tier describes how rigorous the scoped risk governance and management need to be. It is not a score to maximize. Tier 4 is not a prize for collecting enough colored cells.

Read the Intro when you need the complete map and the relationship between outcomes, Profiles, Tiers, and evidence. Use the Cheatsheet when you need the hierarchy, Profile cycle, evidence patterns, and review questions nearby. The Exercise turns one bounded fictional service into a Profile and action plan. The Reference tab supplies NIST's framework, templates, guides, mappings, and the Reference Tool for the details that this overview wisely declines to staple to your desk.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources