AiVibe

Cybersecurity & Compliance

NIST Cybersecurity Framework (CSF)

A voluntary framework from the US National Institute of Standards and Technology that organises cybersecurity outcomes into functions, categories and subcategories, helping organisations of any size understand, assess and improve cyber risk management.

Version 2.0, released in February 2024, structures outcomes under six functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern, new in version 2.0, covers organisational context, risk management strategy, roles, policy, oversight and cybersecurity supply-chain risk management. Each function divides into categories and subcategories that describe desired outcomes rather than prescribing specific controls, and informative references map them to standards such as ISO/IEC 27001 and NIST SP 800-53.

Originally published in 2014 for critical infrastructure, the framework is now used across sectors and countries as a common language between technical teams and executives. Organisations create profiles describing their current and target outcomes, identify gaps and prioritise actions, and use tiers to characterise the rigour of their risk governance and management practices. NIST has also published a Manufacturing Profile that applies the framework to manufacturing environments.

The CSF is not a certification scheme and does not specify how outcomes are achieved, so it is usually combined with control catalogues and standards. It works well for gap analysis, board reporting and aligning security programmes across business units, and NIST publishes implementation examples and quick-start guides to help smaller organisations apply it.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Terms that refer to NIST Cybersecurity Framework (CSF)

Ask AiMuruga can explain NIST Cybersecurity Framework (CSF) for your plant, product or security programme, and draw how it fits.