NIST Cybersecurity Framework
The NIST Cybersecurity Framework is flexible guidance for managing cybersecurity risk. It gives organizations a shared set of outcomes for understanding priorities, describing current and target practices, and communicating what should improve.
itCybersecurity fundamentals and governance | OpenSkills.info
Intro
NIST Cybersecurity Framework
The NIST Cybersecurity Framework, or CSF, helps you manage cybersecurity risk without prescribing one technology stack or one implementation method. It gives leaders, managers, and practitioners a shared vocabulary for describing desired cybersecurity outcomes.
CSF 2.0 applies to organizations of any size, sector, or maturity. You tailor it to your mission, risks, requirements, and resources. The result is not a certificate or a universal checklist. It is a structured way to understand your posture, choose priorities, and communicate decisions.
The mental model
Think of CSF 2.0 as three connected components:
Core outcomes
↓ selected and tailored into
Organizational Profiles
↓ interpreted with
Implementation Tiers
The CSF Core organizes high-level outcomes. An Organizational Profile selects and describes outcomes for a particular scope. An Implementation Tier characterizes the rigor of risk governance and management for that Profile.
Supplementary NIST resources help you move from outcomes to action. Informative References connect outcomes to other documents. Implementation Examples show possible ways to achieve outcomes. Quick Start Guides explain common uses. Community Profiles provide baselines for shared sectors, technologies, threats, or use cases.
The Core: outcomes, not controls
The Core is a hierarchy:
Function → Category → Subcategory
A Function groups outcomes at the highest level. A Category groups related outcomes within a Function. A Subcategory states a more specific technical or management outcome.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://doi.org/10.6028/NIST.CSWP.29
Supports
- CSF 2.0 purpose, audience, flexibility, and technology-neutral outcome model
- Core, Organizational Profile, and Implementation Tier components
- Function, Category, and Subcategory hierarchy
- Names and purposes of Govern, Identify, Protect, Detect, Respond, and Recover
- Concurrent operation of the Functions
- Current, Target, and Community Profile definitions
- Seven-step example cycle for creating and using an Organizational Profile
- Four Tier names and their use in characterizing governance and management rigor
- Informative References, Implementation Examples, Quick Start Guides, and Profile templates
- CSF use for understanding, assessing, prioritizing, and communicating cybersecurity risk
- https://www.nist.gov/cyberframework
Supports
- Current official CSF 2.0 resource hub
- Availability of the framework document, Quick Start Guides, Profiles, mappings, videos, translations, and tool
- https://www.nist.gov/cyberframework/faqs
Supports
- Govern added in CSF 2.0 to emphasize cybersecurity governance
- Core outcomes as non-prescriptive
- Four Tier names and interpretation
- Current and Target Profile use in finding gaps and prioritizing action
- Informative References and Implementation Examples as non-exhaustive
- Reference Tool export in JSON and Excel
- https://www.nist.gov/cyberframework/profiles
Supports
- Organizational Profile template for Current and Target comparison
- Community Profile definition and examples
- Community Profiles as resources for applying the CSF
- https://www.nist.gov/cyberframework/quick-start-guides
Supports
- Available official guides for Profiles, Tiers, small businesses, supply chain risk, enterprise risk management, workforce management, and Informative References
- Purpose of each guide listed in the Reference path
- https://www.nist.gov/cyberframework/informative-references
Supports
- Informative References as mappings between CSF outcomes and other documents
- Availability of Core, Implementation Example, and mapping data
- https://github.com/sindresorhus/awesome
Supports
- Discovery of the Awesome Security list from the curated Awesome index
- https://github.com/sbilly/awesome-security
Supports
- Inclusion of OpenVAS, Wazuh, Security Onion, and Lynis in the fetched security ecosystem list
- Discovery descriptions for vulnerability scanning, monitoring, detection, response, and auditing tools
- https://greenbone.github.io/docs/latest/background
Supports
- OpenVAS as a scan engine executing vulnerability tests against target systems
- Greenbone components for vulnerability scanning and vulnerability management
- https://wazuh.com/platform/overview/
Supports
- Wazuh system inventory, vulnerability detection, file integrity monitoring, and security monitoring capabilities
- https://docs.securityonion.net/en/3/main/introduction/
Supports
- Security Onion network visibility, host visibility, intrusion detection, log management, threat hunting, and case management capabilities
- https://cisofy.com/documentation/lynis/
Supports
- Lynis as an open source audit tool for Unix-like systems
- Lynis reporting, warnings, suggestions, hardening guidance, and compliance-testing support
