GRC Careers

HomeResourcesNIST Cybersecurity Framework (CSF)

CS-104 · Compliance & Frameworks

NIST Cybersecurity Framework (CSF)

A voluntary, risk-based framework that organizes security work into six core functions.

Executive Summary

The NIST Cybersecurity Framework (CSF) is a voluntary, risk-based structure published by the U.S. National Institute of Standards and Technology to help organizations understand, manage, and reduce cybersecurity risk. It organizes activity into a small set of core functions and a common vocabulary that technical and non-technical leaders can share. CSF 2.0 added Govern as a function and broadened the framework beyond critical infrastructure to organizations of any size or sector.

What It Is

The NIST Cybersecurity Framework is a flexible model for describing and improving how an organization manages cybersecurity risk. It is not a checklist of mandatory rules and it is not a certification. Instead it gives leaders a shared language and a structure for deciding where to focus. The current version, CSF 2.0, is built around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Each function breaks down into categories and subcategories that describe outcomes an organization is trying to achieve, such as knowing what assets it owns or having a plan to recover after an incident. The framework is intentionally outcome-focused, so it can be applied to a small nonprofit or a global enterprise without prescribing specific products.

Why It Matters

Because the CSF is widely recognized across government and private industry, it has become a common reference point when organizations describe their security posture to boards, regulators, insurers, and business partners. Adopting it helps an organization move from ad hoc security spending to a defensible, prioritized program tied to actual risk. For professionals, fluency in the CSF is often expected in GRC, audit, and security leadership roles because it frames conversations that cut across compliance, operations, and executive strategy. Many other requirements, contracts, and internal policies map back to the CSF, so understanding it makes many other frameworks easier to navigate.

How It Works

Organizations use the CSF by describing a current profile (what they do today) and a target profile (what they want to achieve), then closing the gap between them in a way that reflects their risk tolerance and resources. The six functions provide the top-level structure. Govern sets the strategy, roles, and risk decisions that steer the whole program. Identify builds understanding of assets, suppliers, and risks. Protect puts safeguards in place. Detect finds events as they happen. Respond contains and manages incidents. Recover restores operations and captures lessons. Implementation tiers describe how mature and integrated the program is, from informal and reactive to adaptive and repeatable. Because the framework references other standards and control sets, teams often pair it with a detailed control catalog for the specifics.

Architecture Diagram

Govern (strategy, roles, risk decisions)Identify (assets and risks)Protect (safeguards)Detect (find events)Respond (contain incidents)Recover (restore and learn)
The six CSF 2.0 functions form a continuous cycle, with Govern at the center steering the other five.

Visual Workflow

Establish governance: define who owns cybersecurity risk, the risk appetite, and how decisions are made.Build a current profile that honestly describes the controls and practices in place today.Define a target profile aligned to the organization's mission, risk, and obligations.Analyze the gap between current and target profiles and prioritize by risk.Implement improvements across the functions and track progress over time.Reassess periodically and update the profiles as the business and threats change.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

GRC platform
Tracks CSF profiles, mappings, gaps, and evidence in one place
Control mapping spreadsheet or catalog
Links CSF categories to detailed controls you already run
Risk register
Records prioritized risks that drive the target profile
Maturity assessment template
Scores implementation tier and tracks progress over time

Industry Standards

NIST Cybersecurity Framework (CSF) 2.0
The framework itself, organized around Govern, Identify, Protect, Detect, Respond, Recover
NIST SP 800-53
Detailed control catalog often used to implement CSF outcomes
ISO/IEC 27001
International standard that many organizations map to the CSF

Career Relevance

The NIST CSF is a core competency for GRC analysts, compliance analysts, security auditors, and CISOs, who use it to structure programs, report to leadership, and align with other requirements. It also appears in the work of risk managers, security architects, and privacy and AI governance professionals, the audience AI-Governance-Jobs.com serves, because it provides the shared language that connects technical controls to business risk.

Interview Questions

Related Certifications

ISACA CISM ISC2 CISSP CompTIA Security+

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Is the NIST CSF mandatory?

For most private organizations it is voluntary. Some contracts, regulators, or sectors may require it or something similar, but the framework itself is designed as a flexible, adoptable reference rather than a legal mandate.

What changed in CSF 2.0?

The most notable change was adding Govern as a sixth core function to emphasize leadership ownership and risk decisions. CSF 2.0 also broadened the audience beyond critical infrastructure to organizations of any size and sector.

Is the NIST CSF the same as NIST SP 800-53?

No. The CSF is a high-level framework of outcomes and functions, while SP 800-53 is a detailed catalog of specific controls. Many organizations use the CSF to structure their program and SP 800-53 to implement the details.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

ISACA CISMISC2 CISSPCompTIA Security+

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: NIST Cybersecurity Framework (CSF)
  3. Go deeper: CIS Controls
  4. Go deeper: ISO/IEC 27001
  5. Validate it: work toward ISACA CISM
  6. Find the role: browse current openings

Related sheets

More in Compliance & Frameworks

Share this LinkedIn Facebook X Email