Management Systems

NIST CSF

Cybersecurity Framework 2.0

Formal standard US / Global NIST Since 2014

An outcome-based framework organised into six functions (Govern, Identify, Protect, Detect, Respond, Recover), each broken into categories and subcategories that describe what good looks like without prescribing how to get there.

Version 2.0 added the Govern function and dropped the critical-infrastructure framing, which is what made it usable as a general risk-communication layer above whatever control catalogue you actually implement.

At a glance

Category
Management Systems
Jurisdiction
US / Global
Governance
NIST
Status
CSF 2.0 (2024); six functions including Govern
First released
2014

Links

Related frameworks

Other entries under Management Systems.

See NIST CSF in context

Open the interactive Data Landscape for Regulation to compare NIST CSF against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.