The six functions
Govern sets strategy, roles, policy and supplier risk oversight. Identify covers assets, risks and improvement. Protect includes identity and access, awareness, data security and platform hardening. Detect covers continuous monitoring and analysis of events. Respond and Recover cover incident management, communication and restoring operations. Each function is broken down into categories and subcategories that describe outcomes, not specific tools.
Version 2.0
CSF 2.0, published in February 2024, added the Govern function, broadened the scope from critical infrastructure to organisations of any size and sector, and added implementation examples and quick start guides for small businesses. The framework and its resources are free on the NIST website.
Profiles and tiers
Companies describe where they are today (current profile) and where they want to be (target profile), and the gap between them becomes the improvement roadmap. Tiers describe how rigorous and integrated the practices are, from partial to adaptive.
NIST CSF and ISO 27001
The CSF describes what good security outcomes look like; ISO 27001 defines a certifiable management system to achieve them. NIST publishes mappings between the two, and the control attributes in ISO 27002 use the same five concepts (identify, protect, detect, respond, recover), so many European companies use the CSF to explain their maturity to management while certifying against ISO 27001.




