Book

The NIST Cybersecurity Framework (CSF) 2.0

by National Institute of Standards and Technology (NIST) · 2024 · 1 reading card · public domain

1 card

  1. The NIST Cybersecurity Framework (CSF) 2.0 · 2024

    Governance is not an extra heading but the function that decides how all the others are applied.

    Until 2024 the NIST framework had five functions: identify, protect, detect, respond, recover. Version 2.0, published on 26 February 2024, added a sixth — GOVERN — and moved it to the centre of the wheel. It is not an extra heading but an admission: risk strategy, executive expectations, policy, roles and authorities, supply chain risk and oversight are not technical activities, yet they decide how well the technical ones get done. The consequence is unwelcome for teams that start with tools. If nobody has decided which objectives the organisation defends, who decides, and with what budget, then detection and response are optimised in a vacuum. The same idea underpins clause 5 of ISO/IEC 27001, leadership: top management does not support the system, it is accountable for it. An auditor hunting for governance evidence reads written management decisions with a date and an author, not monitoring screens.

    GOVERN is in the center of the wheel because it informs how an organization will implement the other five Functions.

    Open the card