US framework providing standards and best practices for managing cybersecurity risk.
The NIST Cybersecurity Framework (CSF) provides voluntary guidance for managing cybersecurity risk. Organised around five functions—Identify, Protect, Detect, Respond, Recover—the framework helps organisations understand their risk posture and prioritise improvements. While developed in the US, NIST CSF is used globally and maps to other frameworks. Version 2.0 adds Govern as a sixth function, emphasising cybersecurity governance. NIST CSF is often used as a maturity assessment tool.
Why It Matters
The DSC Perspective:
NIST CSF provides a common language for discussing security maturity. It's useful for assessing current state, identifying gaps, and communicating with leadership about security programme development.
