Management Systems
NIST CSF
Cybersecurity Framework 2.0
An outcome-based framework organised into six functions (Govern, Identify, Protect, Detect, Respond, Recover), each broken into categories and subcategories that describe what good looks like without prescribing how to get there.
Version 2.0 added the Govern function and dropped the critical-infrastructure framing, which is what made it usable as a general risk-communication layer above whatever control catalogue you actually implement.
At a glance
- Category
- Management Systems
- Jurisdiction
- US / Global
- Governance
- NIST
- Status
- CSF 2.0 (2024); six functions including Govern
- First released
- 2014
Links
Related frameworks
Other entries under Management Systems.
- ISO/IEC 27001: Information Security Management Systems
- NIST RMF: Risk Management Framework (SP 800-37)
- Grundschutz: BSI IT-Grundschutz
See NIST CSF in context
Open the interactive Data Landscape for Regulation to compare NIST CSF against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.