Back to Frameworks
Security

NIST CSF

The NIST Cybersecurity Framework gives organizations a shared vocabulary for describing and managing cybersecurity risk, without prescribing a specific set of technical controls.

CSF 2.0 organizes activity into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — with Govern added in the 2024 update to emphasize risk management as a leadership responsibility, not just an IT one.

See how LumiGRC handles NIST CSF

Get a Demo
6

Core functions

0%
Typical certification profile
Audit Rigor58%
Time to Certify70%
Surveillance Burden71%
Issued & Enforced By

NIST

NIST Cybersecurity Framework 2.0 (2024)

Key Points

  • Six functions: Govern, Identify, Protect, Detect, Respond, Recover
  • Voluntary — no certification, used as a maturity and communication tool
  • Maps to more prescriptive frameworks like ISO 27001 and 800-53
  • Widely adopted as a common risk-management vocabulary