modern auditing

Glossary

NIST Cybersecurity Framework 2.0

Also known as: NIST CSF, CSF 2.0

A voluntary framework organising cybersecurity outcomes into six functions — Govern, Identify, Protect, Detect, Respond, Recover — widely used as a common language between technical and board audiences.

CSF 2.0, released in 2024, added Govern as a sixth function alongside the original five, elevating organisational context, risk management strategy, roles, policy and oversight of the supply chain to first-class status. It also formally broadened the framework’s scope beyond critical infrastructure to organisations of any size or sector.

Its strength is as a communication layer. The function-category-subcategory structure gives a board a defensible summary of where capability sits without descending into control detail, and it maps cleanly onto more prescriptive standards underneath — the compliance map records 106 CSF 2.0 subcategories against 295 NIST 800-53 controls.

Its weakness is that it is outcome-oriented rather than prescriptive, which means a CSF profile is not by itself an audit programme. “Detect: anomalies and events are analysed” is a statement of intent; testing it requires descending to the specific controls that deliver it. Functions that report CSF maturity without that underlying testing are reporting a self-assessment, and it is worth being clear with the audit committee about which one they are receiving.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.