NIST: Security Framework
02 Jul 2026

NIST: Security Framework

Relevant Cybersecurity Publications

Description

The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations on managing cybersecurity risks. It offers a high-level taxonomy of cybersecurity outcomes that any organization—regardless of its size, sector, or level of maturity—can use to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not specify how the outcomes should be achieved. Rather, it provides links to online resources that offer additional guidance on practices and controls that could be used to achieve those outcomes. This document describes the CSF 2.0, its components, and some of the many ways it can be used.

The NIST CSF 2.0 framework is structured around six core functions that enable organizations to manage their cybersecurity risks on an ongoing basis:

  • Govern: This is where the organization defines its cybersecurity strategy, the rules of the game, roles, and security expectations.
  • Identify: This involves gaining a thorough understanding of the organization’s assets, software, data, and processes to determine what needs to be protected.
  • Protect: This is the phase of implementing practical measures (such as passwords, firewalls, or training) to prevent incidents from occurring.
  • Detect: This is the ability to remain vigilant in order to quickly identify any suspicious events or activities on the systems.
  • Respond: These are the coordinated actions that are triggered as soon as an incident is confirmed, to stop it and minimize the damage.
  • Recover: This is the final phase in which services are restored, systems are repaired, and operations return to normal after a problem has occurred.

 

PDF Documents