Skip to content
FioSec Consulting

Frameworks · Foundational

NIST Cybersecurity Framework

A common language for organizing, measuring, and improving your whole security program.

Maintained by
U.S. National Institute of Standards and Technology (NIST)
Origin
United States · version 2.0, released 2024
Certifiable?
No. It is voluntary and self-directed; there is no NIST CSF certificate.

What it is

The NIST Cybersecurity Framework is a voluntary, outcome-based way to organize and talk about a cybersecurity program. Rather than handing you a fixed list of products to buy, it describes the outcomes a mature program achieves and lets you decide how to reach them with the people, processes, and technology that fit your organization.

It was first published in 2014 for operators of critical infrastructure, but its plain language and flexibility made it one of the most widely adopted security frameworks across sectors and organization sizes. Version 2.0, released in 2024, broadened that scope explicitly to all organizations and added a new Govern function to put leadership accountability and risk decisions at the centre.

Because it is technology-neutral and scales from a small charity to a multinational, the CSF works best as the backbone of a program: a shared structure that leadership, IT, and outside partners can all point to when deciding what to do next and how to measure progress.

How it's structured

The framework has three parts that work together. The Core is the catalogue of cybersecurity outcomes, arranged as six Functions, which break down into Categories and then specific Subcategories. Implementation Tiers describe how rigorous and risk-informed your practices are, from Tier 1 (Partial) to Tier 4 (Adaptive). Profiles let you record where you are today (your Current Profile) and where you want to be (your Target Profile), so the gap between them becomes your roadmap.

The six Functions below are the part most people mean when they say "NIST." They are not sequential steps but ongoing, concurrent capabilities, and a healthy program is doing all six at once.

Govern (GV)

New in 2.0. Sets the organization’s cybersecurity strategy, expectations, and accountability: the risk management decisions, roles, policy, and oversight that inform every other function.

Identify (ID)

Understand what you have and what could go wrong: assets, data, suppliers, and the risks to them. You cannot protect what you have not inventoried.

Protect (PR)

The safeguards that limit or contain an incident: access control and identity, awareness training, data security, and resilient configuration.

Detect (DE)

Find attacks in progress: continuous monitoring and the analysis that turns raw logs and alerts into a recognized incident.

Respond (RS)

Act once something is detected: an incident response plan, communications, analysis, and containment to limit the damage.

Recover (RC)

Restore what was affected and return to normal operations: recovery planning, restoration, and the lessons that feed back into the program.

Who it's for

Almost any organization can use the CSF, which is precisely its strength. It is the natural choice when leadership wants a single, defensible structure to organize a security program and report on it, without committing to a formal certification or audit cycle.

It is especially valuable when you need a common language between technical staff, executives, the board, and outside advisors, or when several other obligations (a cyber-insurance application, a customer security questionnaire, a regulator’s expectations) all need to be answered from one coherent program rather than managed as separate fire drills.

It works less well as a literal checklist. Because outcomes are deliberately high-level, smaller teams often pair the CSF’s structure with the more prescriptive CIS Controls for the "exactly what do we configure" detail.

How it compares

Think of the CSF as the organizing layer that other frameworks plug into. It tells you what outcomes to pursue and how to govern them, the CIS Controls tell you specifically which safeguards to implement, and ISO/IEC 27001 turns the same ideas into a certifiable management system you can be audited against.

The CSF maps cleanly onto both. Many organizations run the CSF as their program backbone, use CIS Controls as the technical to-do list underneath it, and adopt ISO 27001 later if a contract or market demands an independent certificate. None of these choices are mutually exclusive, because they answer different questions.

How it maps to a Layered Defence

NIST CSF 2.0 is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.

Free readiness checklist

How ready are you for NIST CSF 2.0?

Answer honestly across the 6 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.

Govern

Leadership ownership of cyber risk.

Is there a named owner accountable for cybersecurity, with risk reported to leadership or the board?

A real owner and a reporting line, not "IT handles it."

Do you have written security policies that staff actually know about and follow?
Are the cyber risks from your key suppliers and vendors identified and managed?

Identify

Knowing what you have and what’s at risk.

Do you keep a current inventory of your devices, systems, and the data that matters most?
Have you assessed and documented your top cybersecurity risks?

A risk assessment that drives decisions, refreshed periodically.

Protect

The safeguards that prevent and contain.

Is multi-factor authentication (MFA) enforced and is access limited to what each role needs?
Do staff get regular security-awareness training, not just a once-a-year session?
Are systems patched on a schedule and configured to a known secure baseline?

Detect

Seeing an attack in progress.

Are security logs centrally collected and actually monitored, so an intrusion would be noticed?

A SIEM or managed detection service watching, not logs nobody reads.

Would you be alerted to suspicious activity quickly, day or night?

Respond

Acting decisively when it happens.

Do you have a written incident response plan that names who does what?
Has that plan been tested with a tabletop exercise in the past year?

Recover

Getting back to normal, without paying a ransom.

Are backups immutable (provably safe from ransomware) and recently test-restored?
Do you have a recovery plan with target timelines for restoring critical systems?

No email required; scored in your browser, never sent anywhere.

Authoritative source: NIST Cybersecurity Framework 2.0 (nist.gov)

Explore other frameworks

Need help putting NIST CSF 2.0 into practice?

FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.