NIST Cybersecurity Framework 2.0
A voluntary framework organising cybersecurity outcomes into six functions — Govern, Identify, Protect, Detect, Respond, Recover — widely used as a common language between technical and board audiences.
CSF 2.0, released in 2024, added Govern as a sixth function alongside the original five, elevating organisational context, risk management strategy, roles, policy and oversight of the supply chain to first-class status. It also formally broadened the framework’s scope beyond critical infrastructure to organisations of any size or sector.
Its strength is as a communication layer. The function-category-subcategory structure gives a board a defensible summary of where capability sits without descending into control detail, and it maps cleanly onto more prescriptive standards underneath — the compliance map records 106 CSF 2.0 subcategories against 295 NIST 800-53 controls.
Its weakness is that it is outcome-oriented rather than prescriptive, which means a CSF profile is not by itself an audit programme. “Detect: anomalies and events are analysed” is a statement of intent; testing it requires descending to the specific controls that deliver it. Functions that report CSF maturity without that underlying testing are reporting a self-assessment, and it is worth being clear with the audit committee about which one they are receiving.
Related