Skip to main content
Category: GRC Frameworks

Cybersecurity Framework

Also known as: CSF, NIST Cybersecurity Framework, NIST CSF
Simply put

A cybersecurity framework is a structured, risk-based approach that helps organizations understand, manage, and reduce cybersecurity risk. The term is most commonly associated with the NIST Cybersecurity Framework, which offers voluntary guidance that industry, government agencies, and other organizations can adapt to their own circumstances. It is a reference model rather than a mandatory legal standard, though some jurisdictions or sectors may adopt or reference it.

Formal definition

As defined by NIST, the Cybersecurity Framework (CSF) is a risk-based approach to reducing cybersecurity risk, composed of three parts: the Framework Core, the Framework Profile, and the Framework Implementation Tiers. The Core organizes cybersecurity outcomes into high-level Functions; in CSF 2.0 (published by NIST on February 26, 2024) these comprise six Functions, GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, with the GOVERN Function added in version 2.0 to the five Functions present in the earlier version. Profiles express an organization's current or target alignment of those outcomes to its business needs, risk tolerance, and resources, while Implementation Tiers characterize the rigor of an organization's cybersecurity risk governance and management practices. The CSF is a voluntary guidance framework and does not itself prescribe specific controls, tooling, or implementation details; its applicability and any binding force depend on jurisdiction, sector, and organizational adoption. This entry does not cover related but distinct NIST resources, such as the NICE Workforce Framework for Cybersecurity, which addresses cybersecurity work roles rather than risk-management outcomes.

Why it matters

Cybersecurity risk cuts across nearly every organizational objective, yet without a common structure it can be difficult to describe, prioritize, and communicate that risk consistently to executives, boards, and external stakeholders. A cybersecurity framework such as the NIST Cybersecurity Framework provides a shared vocabulary and a risk-based structure that helps organizations understand their current posture, define a target state aligned to business needs, and reason about the rigor of their governance and management practices. This makes it easier to align technical activity with organizational risk tolerance rather than treating cybersecurity as a purely operational or compliance exercise.

The framework's status as voluntary guidance is itself significant. Because it is a reference model rather than a mandatory legal standard, organizations can adapt it to their own circumstances, size, and sector. At the same time, some jurisdictions or sectors may adopt or reference the framework, so its practical force depends on context. Compliance officers and risk managers should be careful not to treat framework alignment as evidence of legal compliance in itself; adherence to any binding obligation depends on the specific jurisdiction, sector, and how the framework has been incorporated into applicable requirements.

The release of CSF 2.0 by NIST on February 26, 2024 is a notable development, as it added a GOVERN Function to the previously five Functions. This reflects growing emphasis on cybersecurity governance, the structures, roles, and decision rights that direct how an organization manages cyber risk, as a first-class concern alongside operational activities such as protection and detection. Organizations referencing the framework should ensure they are working from the current version, since descriptions based on the earlier five-Function model no longer fully reflect the current NIST specification.

Who it's relevant to

Risk Managers
Risk managers can use the framework as a structured, risk-based approach to understand, manage, and reduce cybersecurity risk, and to map cybersecurity outcomes to the organization's risk tolerance and resources through the use of Profiles.
Governance Professionals and Boards
With the addition of the GOVERN Function in CSF 2.0, governance professionals have a clearer reference for the structures, roles, and decision rights that direct how cybersecurity risk is managed. The framework supports communicating risk posture and target state to executives and boards using a common vocabulary.
Compliance and Regulatory Specialists
Compliance specialists should recognize that the framework is voluntary guidance rather than a mandatory legal standard. Its applicability and any binding force depend on jurisdiction, sector, and whether an authority has adopted or referenced it, so framework alignment should not be equated with legal compliance on its own.
Internal Auditors and Assurance Functions
Internal auditors can use the framework's Functions, Profiles, and Implementation Tiers as reference points when evaluating the rigor and coverage of an organization's cybersecurity risk management practices, while maintaining independence from the management activities they assess.

Inside CSF

Core
A set of high-level Functions that organize cybersecurity outcomes and activities. Under the NIST Cybersecurity Framework Version 2.0 (issued by the National Institute of Standards and Technology), the Core comprises six Functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER. The GOVERN Function was added in Version 2.0 to address organizational context, roles and responsibilities, policy, and oversight; earlier versions organized the Core around the original five Functions (IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER). Each Function is further broken down into Categories and Subcategories representing more specific outcomes.
GOVERN Function
The Function introduced in Version 2.0 that addresses how an organization's cybersecurity risk management strategy, expectations, roles and responsibilities, and policy are established, communicated, and monitored. It reflects the governance pillar and situates cybersecurity risk within broader enterprise risk management.
Profiles
A mechanism for describing an organization's current and target cybersecurity posture by selecting and prioritizing Framework outcomes according to business needs, risk appetite, and resources. Profiles support gap analysis between a current state and a desired target state.
Tiers
A means of characterizing the rigor and maturity of an organization's cybersecurity risk governance and management practices. Tiers describe a range from more informal, reactive approaches to more adaptive, risk-informed approaches; they are intended as context for decision-making rather than as a strict maturity score.
Categories and Subcategories
Subdivisions of each Function that express specific cybersecurity outcomes. Subcategories are commonly cross-referenced to other standards, guidelines, and practices through informative references, allowing organizations to map the Framework to complementary controls.

Common questions

Answers to the questions practitioners most commonly ask about CSF.

Does the NIST Cybersecurity Framework have only five Core Functions?
No. The original framework organized activities under five Functions, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER. NIST Cybersecurity Framework Version 2.0, published by the National Institute of Standards and Technology in February 2024, added a sixth Function, GOVERN, which addresses the organization's cybersecurity risk management strategy, expectations, policy, and oversight. Any current description should reflect all six Functions; references to only five typically describe the earlier version.
Is adopting the Cybersecurity Framework a legal requirement that guarantees compliance?
Not in general. The framework is a voluntary, risk-based set of guidance issued by NIST, and using it does not by itself satisfy any specific law or regulation. It is a governance and risk-management tool rather than a compliance mandate. Certain jurisdictions, sectors, or contracts may reference it, but its applicability and any obligation to use it depend on that context. Adopting it may help structure a cybersecurity program, but it does not guarantee security outcomes or regulatory adherence.
How do the framework's Functions relate to setting up a cybersecurity program?
The Functions provide a high-level structure for organizing outcomes. GOVERN typically frames the strategy, roles, and oversight; IDENTIFY supports understanding assets and risks; PROTECT, DETECT, RESPOND, and RECOVER address safeguarding, monitoring, responding to, and recovering from events. Organizations commonly use these Functions to group Categories and Subcategories of outcomes rather than as a step-by-step procedure. Implementation specifics, tooling, and control selection are out of scope for the framework itself and are left to the organization.
How is the framework typically tailored to a specific organization?
Organizations commonly develop profiles that describe a Current Profile and a Target Profile, reflecting how the framework's outcomes align with their business needs, risk appetite, jurisdiction, sector, and resources. This tailoring lets an organization prioritize outcomes rather than treat every element as universally applicable. The framework is intentionally outcome-focused and does not prescribe particular technologies, so tailoring decisions and their supporting controls remain the organization's responsibility.
How does the framework interact with other standards and frameworks an organization may already use?
The framework is designed to be used alongside other references and commonly maps its outcomes to informative references, which may include other standards and guidelines. It is generally treated as complementary to, rather than a replacement for, established risk management or control frameworks. Because mappings and versions change, organizations typically confirm the current informative references rather than assume a fixed correspondence.
How can assurance functions use the framework without compromising their independence?
Internal audit or other independent assurance functions may use the framework as a reference to assess whether cybersecurity outcomes are being achieved, while management retains responsibility for designing and operating the controls. Keeping this distinction clear supports the independence and objectivity of assurance work: the framework informs what is evaluated, but assurance should not design the same controls it later audits. How responsibilities are allocated may follow an organization's governance model and lines of responsibility.

Common misconceptions

The Cybersecurity Framework Core consists of five Functions.
The five-Function model (IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER) reflects earlier versions. NIST Cybersecurity Framework Version 2.0 added a sixth Function, GOVERN, so the current Core comprises six Functions. Describing only five gives an incomplete and potentially outdated picture.
The Framework is a mandatory regulation that organizations are legally required to adopt.
The NIST Cybersecurity Framework is a voluntary, outcome-based framework rather than a law. It may be referenced or incorporated by regulators, contracts, or sector-specific requirements in particular jurisdictions, but adoption obligations depend on context and are not universal.
Implementing the Framework guarantees an organization is secure or compliant.
The Framework is intended to help organize and prioritize cybersecurity outcomes and communicate risk; it does not guarantee protection against incidents, nor does it by itself establish compliance with any specific legal or regulatory obligation. Its effectiveness depends on how outcomes are implemented and maintained.

Best practices

Confirm you are working from NIST Cybersecurity Framework Version 2.0 and account for all six Functions, including the GOVERN Function, when mapping cybersecurity outcomes.
Use Profiles to document a current-state and target-state comparison so that gaps can be identified and prioritized against business needs and risk appetite.
Situate cybersecurity risk within the organization's broader enterprise risk management and governance structures, using the GOVERN Function to clarify roles, responsibilities, and oversight.
Apply Tiers as contextual descriptors of risk management rigor rather than treating them as a definitive maturity score or pass/fail rating.
Leverage Categories, Subcategories, and informative references to map the Framework to complementary standards and internal controls rather than treating the Framework as a standalone control set.
Treat Framework adoption as voluntary and context-dependent, verifying applicable jurisdictional, sectoral, or contractual requirements before presenting it as an obligation.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps