The US National Institute of Standards and Technology (NIST) has updated its widely used Cybersecurity Framework (CSF). The new 2.0 edition is the outcome of a multiyear process of discussions and public comments aimed at making the framework more effective.
NIST first released the CSF in 2014 to help organizations understand, reduce and communicate about cyber security risk. The framework’s core is now organized around six key functions: Identify, Protect, Detect, Respond and Recover, along with CSF 2.0’s newly added Govern function. When considered together, these functions provide a comprehensive view of the life cycle for managing cyber security risk.
The six key cyber security functions are:
- GOVERN (GV): The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
- IDENTIFY (ID): The organization’s current cybersecurity risks are understood.
- PROTECT (PR): Safeguards to manage the organization’s cybersecurity risks are used.
- DETECT (DE): Possible cybersecurity attacks and compromises are found and analyzed.
- RESPOND (RS): Actions regarding a detected cybersecurity incident are taken.
- RECOVER (RC): Assets and operations affected by a cybersecurity incident are restored.
Key developments include:
- A new CSF 2.0 Reference Tool now simplifies the way organizations can implement the CSF, allowing users to browse, search and export data and details from the CSF’s core guidance in human-consumable and machine-readable formats.
- The CSF 2.0 offers a searchable catalog of informative references that shows how their current actions map onto the CSF. This catalog allows an organization to cross-reference the CSF’s guidance to more than 50 other cybersecurity documents.
- Organizations can also consult the Cybersecurity and Privacy Reference Tool (CPRT), which contains an interrelated, browsable and downloadable set of NIST guidance documents.






