NIST has released Cybersecurity Framework (CSF) 2.0, the first major update since the framework was launched in 2014.
Key changes
- A new sixth function, Govern, covering cyber security strategy, roles, policy, oversight and supply chain risk management, joins Identify, Protect, Detect, Respond and Recover.
- The scope is broadened from critical infrastructure to all organisations, of any size or sector.
- Expanded guidance on supply chain risk.
- New quick-start guides, implementation examples and online reference tools, including mappings to other frameworks.
The new Govern function aligns closely with the leadership and planning requirements of ISO/IEC 27001, making it easier than ever to use both frameworks together.
Source: NIST Cybersecurity Framework 2.0 (NIST CSRC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.