Govern (GV)
New in 2.0. Sets the organization’s cybersecurity strategy, expectations, and accountability: the risk management decisions, roles, policy, and oversight that inform every other function.
Frameworks · Foundational
A common language for organizing, measuring, and improving your whole security program.
The NIST Cybersecurity Framework is a voluntary, outcome-based way to organize and talk about a cybersecurity program. Rather than handing you a fixed list of products to buy, it describes the outcomes a mature program achieves and lets you decide how to reach them with the people, processes, and technology that fit your organization.
It was first published in 2014 for operators of critical infrastructure, but its plain language and flexibility made it one of the most widely adopted security frameworks across sectors and organization sizes. Version 2.0, released in 2024, broadened that scope explicitly to all organizations and added a new Govern function to put leadership accountability and risk decisions at the centre.
Because it is technology-neutral and scales from a small charity to a multinational, the CSF works best as the backbone of a program: a shared structure that leadership, IT, and outside partners can all point to when deciding what to do next and how to measure progress.
The framework has three parts that work together. The Core is the catalogue of cybersecurity outcomes, arranged as six Functions, which break down into Categories and then specific Subcategories. Implementation Tiers describe how rigorous and risk-informed your practices are, from Tier 1 (Partial) to Tier 4 (Adaptive). Profiles let you record where you are today (your Current Profile) and where you want to be (your Target Profile), so the gap between them becomes your roadmap.
The six Functions below are the part most people mean when they say "NIST." They are not sequential steps but ongoing, concurrent capabilities, and a healthy program is doing all six at once.
New in 2.0. Sets the organization’s cybersecurity strategy, expectations, and accountability: the risk management decisions, roles, policy, and oversight that inform every other function.
Understand what you have and what could go wrong: assets, data, suppliers, and the risks to them. You cannot protect what you have not inventoried.
The safeguards that limit or contain an incident: access control and identity, awareness training, data security, and resilient configuration.
Find attacks in progress: continuous monitoring and the analysis that turns raw logs and alerts into a recognized incident.
Act once something is detected: an incident response plan, communications, analysis, and containment to limit the damage.
Restore what was affected and return to normal operations: recovery planning, restoration, and the lessons that feed back into the program.
Almost any organization can use the CSF, which is precisely its strength. It is the natural choice when leadership wants a single, defensible structure to organize a security program and report on it, without committing to a formal certification or audit cycle.
It is especially valuable when you need a common language between technical staff, executives, the board, and outside advisors, or when several other obligations (a cyber-insurance application, a customer security questionnaire, a regulator’s expectations) all need to be answered from one coherent program rather than managed as separate fire drills.
It works less well as a literal checklist. Because outcomes are deliberately high-level, smaller teams often pair the CSF’s structure with the more prescriptive CIS Controls for the "exactly what do we configure" detail.
Think of the CSF as the organizing layer that other frameworks plug into. It tells you what outcomes to pursue and how to govern them, the CIS Controls tell you specifically which safeguards to implement, and ISO/IEC 27001 turns the same ideas into a certifiable management system you can be audited against.
The CSF maps cleanly onto both. Many organizations run the CSF as their program backbone, use CIS Controls as the technical to-do list underneath it, and adopt ISO 27001 later if a contract or market demands an independent certificate. None of these choices are mutually exclusive, because they answer different questions.
NIST CSF 2.0 is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.
Free readiness checklist
Answer honestly across the 6 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.
Your result
Govern
—Identify
—Protect
—Detect
—Respond
—Recover
—This is a self-assessment, not a formal audit or a guarantee of compliance. Talk to our team for a detailed gap review.
Authoritative source: NIST Cybersecurity Framework 2.0 (nist.gov)
FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.