Don’t do SECURITY. Do business SECURELY.

NIST Cybersecurity Framework 2.0 released

NIST has released CSF 2.0, adding a new Govern function and broadening the framework to all organisations.

NIST has released Cybersecurity Framework (CSF) 2.0, the first major update since the framework was launched in 2014.

Key changes

  • A new sixth function, Govern, covering cyber security strategy, roles, policy, oversight and supply chain risk management, joins Identify, Protect, Detect, Respond and Recover.
  • The scope is broadened from critical infrastructure to all organisations, of any size or sector.
  • Expanded guidance on supply chain risk.
  • New quick-start guides, implementation examples and online reference tools, including mappings to other frameworks.

The new Govern function aligns closely with the leadership and planning requirements of ISO/IEC 27001, making it easier than ever to use both frameworks together.

Source: NIST Cybersecurity Framework 2.0 (NIST CSRC)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights