The NIST Cybersecurity Framework gives organizations a shared vocabulary for describing and managing cybersecurity risk, without prescribing a specific set of technical controls.
CSF 2.0 organizes activity into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — with Govern added in the 2024 update to emphasize risk management as a leadership responsibility, not just an IT one.
Core functions
NIST
NIST Cybersecurity Framework 2.0 (2024)