Key Takeaways
- NIST CSF 2.0 has 6 core functions: Govern, Identify, Protect, Detect, Respond, Recover
- CSF 2.0 adds GOVERN as the 6th function — cybersecurity governance at the organizational level
- Start with Govern and Identify — establish oversight and know your assets
- The framework is voluntary and adaptable to any organization size
- CSF 2.0 expands scope beyond critical infrastructure to all organizations and adds supply chain guidance
Test Your Knowledge
Latest from the Blog
NIST Cybersecurity Framework (CSF 2.0)
Quick reference guide to NIST CSF 2.0 — a voluntary framework for organizations to manage and reduce cybersecurity risk. CSF 2.0 (released February 2024) adds a 6th core function, Govern, expands scope beyond critical infrastructure to all organizations, and strengthens supply chain risk guidance.
The Govern function is the foundation of CSF 2.0 — it ensures cybersecurity risk management is integrated into broader enterprise risk management and driven by organizational leadership.
Understand mission, stakeholder expectations, and legal/regulatory requirements
Establish risk management priorities, constraints, tolerances, and appetite statements
Define cybersecurity roles and accountability across the organization
Establish, communicate, and enforce cybersecurity policy based on organizational context and risk strategy
Review and adjust cybersecurity strategy, including results of risk management activities
Identify, establish, manage, monitor, and improve supply chain risk management processes
Identify and manage data, personnel, devices, systems, and facilities
Understand organization's mission, objectives, stakeholders, and activities
Policies, procedures, and processes to manage and monitor requirements
Understand cybersecurity risk to operations, assets, and individuals
Establish priorities, constraints, risk tolerances, and assumptions
Identify, assess, and manage supply chain risks
Limit access to assets and facilities to authorized users and processes
Educate personnel to perform security-related duties
Manage information and records consistent with risk strategy
Maintain security policies, processes, and procedures
Perform maintenance and repairs of system components
Technical security solutions to ensure resilience
Detect anomalous activity and understand potential impact
Monitor systems and assets to identify cybersecurity events
Maintain and test detection processes and procedures
Execute response processes and procedures during/after an incident
Coordinate response activities with internal and external stakeholders
Conduct analysis to ensure effective response and support recovery
Perform activities to prevent expansion and mitigate effects
Improve response activities by incorporating lessons learned
Execute recovery processes and procedures to restore systems
Improve recovery planning by incorporating lessons learned
Coordinate restoration activities with internal and external parties
Implementation Tiers
| Tier | Name | Description |
|---|---|---|
| Tier 1 | Partial | Risk management is ad hoc, limited awareness, no external collaboration |
| Tier 2 | Risk Informed | Risk management approved but not organization-wide, informal external sharing |
| Tier 3 | Repeatable | Formal policies, regularly updated, collaborates with partners |
| Tier 4 | Adaptive | Adapts based on lessons learned, continuous improvement, active sharing |
Quick Implementation Checklist
🏛️ Govern
- Define cybersecurity risk appetite and tolerances
- Assign cybersecurity roles and accountability
- Establish cybersecurity policies
- Integrate supply chain risk management
🔍 Identify
- Maintain hardware and software inventory
- Document data flows and classifications
- Conduct regular risk assessments
- Define organizational risk tolerance
🛡️ Protect
- Implement identity management and MFA
- Conduct security awareness training
- Encrypt data at rest and in transit
- Maintain baseline configurations
👁️ Detect
- Deploy SIEM and log aggregation
- Implement network monitoring
- Establish security baselines and alerts
- Conduct vulnerability scanning
🚨 Respond
- Develop incident response plan
- Define communication procedures
- Establish forensics capabilities
- Test response procedures regularly
♻️ Recover
- Maintain tested backup procedures
- Document recovery procedures
- Establish business continuity plans
- Conduct post-incident reviews
Need Detailed NIST Implementation Guides?
For comprehensive tutorials and implementation guides:
Visit FixTheVuln.com →FixTheVuln Store
Preparing for CISSP or Security+?
Master NIST frameworks with a structured certification study planner.
Related Resources
FixTheVuln Store
Studying for CompTIA Security+? Get the Study Planner
Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.
CompTIA Security+ Planner60+ certifications available — from $5.99