01 NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) is one of the most widely used cybersecurity risk-management frameworks in the world.
It provides a structured way for organizations to understand, communicate, prioritize, and improve cybersecurity risk management.
The framework is designed to help organizations answer questions such as:
What Cybersecurity RisksDo We Face?
What OutcomesDo We Need?
What ControlsShould We Prioritize?
Where AreOur Gaps?
What ShouldWe Improve First?
How Do WeCommunicate Cyber Riskto Leadership?The framework is intentionally flexible.
It can be used by:
Small Businesses
Large Enterprises
Government Agencies
Cloud Providers
Financial Institutions
Healthcare Organizations
Technology Companies
Critical InfrastructureNIST CSF does not prescribe one fixed technology stack.
Instead, it provides a common structure for managing cybersecurity outcomes.
Learning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the purpose of the NIST Cybersecurity Framework.
-
understand the structure of NIST CSF 2.0.
-
understand the six CSF Functions.
-
understand Categories and Subcategories.
-
understand Organizational Profiles.
-
understand Current and Target Profiles.
-
understand Implementation Tiers.
-
understand the Govern Function.
-
understand the Identify Function.
-
understand the Protect Function.
-
understand the Detect Function.
-
understand the Respond Function.
-
understand the Recover Function.
-
understand how CSF supports risk management.
-
understand how CSF supports executive governance.
-
understand how to perform a CSF gap assessment.
-
understand how to prioritize cybersecurity improvements.
-
understand how to map CSF outcomes to controls.
-
understand how CSF can support multiple compliance frameworks.
-
design a practical enterprise CSF operating model.
1. What Is the NIST Cybersecurity Framework?
Section titled “1. What Is the NIST Cybersecurity Framework?”The NIST Cybersecurity Framework is a risk-based framework for managing cybersecurity.
At a high level:
Business Objectives ↓Cybersecurity Risks ↓CSF Outcomes ↓Controls ↓Evidence ↓Risk ReductionThe framework helps organizations connect cybersecurity activities with:
Business Risk
Governance
Technology
Operations
Compliance
Executive Reporting2. Why Organizations Use NIST CSF
Section titled “2. Why Organizations Use NIST CSF”Cybersecurity programs often become fragmented.
Different teams may focus independently on:
Firewalls
IAM
Cloud Security
Vulnerability Management
Incident Response
Data Protection
Third-Party RiskNIST CSF provides a common structure for bringing these areas together.
Cybersecurity Activities ↓Common Framework ↓Enterprise Risk View3. NIST CSF 2.0 Structure
Section titled “3. NIST CSF 2.0 Structure”NIST CSF 2.0 organizes cybersecurity outcomes around six Functions:
GOVERN
IDENTIFY
PROTECT
DETECT
RESPOND
RECOVERConceptually:
GOVERN ↓ IDENTIFY ↓ PROTECT ↓ DETECT ↓ RESPOND ↓ RECOVER ↺Govern operates across the entire cybersecurity lifecycle.
4. The Six CSF Functions
Section titled “4. The Six CSF Functions”The six Functions provide the highest-level view of cybersecurity risk management.
GOVERNHow cybersecurity riskis directed and overseen.
IDENTIFYWhat assets, risks,and dependencies exist.
PROTECTWhat safeguardsreduce cybersecurity risk.
DETECTHow cybersecurity eventsare identified.
RESPONDHow the organizationacts during incidents.
RECOVERHow services and capabilitiesare restored.5. Function 1 — Govern
Section titled “5. Function 1 — Govern”The Govern Function establishes how cybersecurity risk is managed across the organization.
It addresses areas such as:
Risk Management Strategy
Policies
Roles
Responsibilities
Authorities
Supply Chain Risk
Legal Requirements
OversightGovern answers:
Who Is Accountable?
What Is OurRisk Strategy?
What PoliciesApply?
How Much RiskWill We Accept?
How Do LeadersOversee Cybersecurity?6. Why Govern Matters
Section titled “6. Why Govern Matters”Without governance:
Security Tools ↓Security Activities ↓No Clear Ownership ↓No Risk PrioritizationWith governance:
Business Strategy ↓Risk Appetite ↓Cybersecurity Strategy ↓Controls ↓Measurement7. Governance Outcomes
Section titled “7. Governance Outcomes”A mature governance program may define:
Cybersecurity Policies
Risk Appetite
Risk Owners
Control Owners
Security Roles
Executive Oversight
Third-Party Expectations
Regulatory Obligations8. Example — Governance
Section titled “8. Example — Governance”Scenario:
Critical Cloud ServicesSupport Customer TransactionsGovernance may establish:
Risk Owner:CTO
Cybersecurity Owner:CISO
Risk Appetite:Low Service Disruption
Required Controls:MFALoggingEncryptionResilience9. Function 2 — Identify
Section titled “9. Function 2 — Identify”The Identify Function focuses on understanding what the organization needs to protect and the cybersecurity risks affecting it.
This may include:
Assets
Data
Systems
Services
Business Processes
Dependencies
Threats
Vulnerabilities
Risks10. Asset Management
Section titled “10. Asset Management”Organizations cannot protect assets they do not know exist.
Identify:
Applications
Servers
Endpoints
Cloud Accounts
Databases
Network Devices
SaaS Platforms
Vendors11. Asset Inventory Example
Section titled “11. Asset Inventory Example”Enterprise │ ├── Applications ├── Cloud Accounts ├── Endpoints ├── Databases ├── Networks └── Vendors12. Asset Criticality
Section titled “12. Asset Criticality”Assets should be prioritized based on:
Business Importance
Data Sensitivity
Availability Requirements
Regulatory Impact
Customer ImpactExample:
Tier 1Critical
Tier 2High
Tier 3Moderate
Tier 4Low13. Risk Assessment
Section titled “13. Risk Assessment”Identify also includes cybersecurity risk assessment.
Example:
Threat ↓Vulnerability ↓Asset ↓Business Impact ↓Cyber Risk14. Example Risk
Section titled “14. Example Risk”Threat:Credential Theft
Asset:Cloud Admin Account
Weakness:No MFA
Risk:Unauthorized Cloud Access
Impact:Data ExposureService Disruption15. Supply Chain Identification
Section titled “15. Supply Chain Identification”Organizations must also understand:
Critical Vendors
Cloud Providers
Software Suppliers
Managed Service Providers
Data ProcessorsThese dependencies can create cybersecurity risk.
16. Function 3 — Protect
Section titled “16. Function 3 — Protect”The Protect Function focuses on safeguards that reduce cybersecurity risk.
Typical areas include:
Identity Management
Access Control
Awareness Training
Data Security
Platform Security
Technology Resilience17. Identity Protection
Section titled “17. Identity Protection”Examples:
MFA
Least Privilege
Privileged Access Management
Access Reviews
Account Lifecycle Management18. Example
Section titled “18. Example”Risk:
Privileged AccountCompromiseProtective controls:
MFA
PAM
Conditional Access
Strong Authentication
Least Privilege19. Data Security
Section titled “19. Data Security”Protective measures may include:
Encryption
Data Classification
DLP
Backup
Secure Disposal
Access Restrictions20. Platform Security
Section titled “20. Platform Security”Examples:
Secure Configuration
Patch Management
Endpoint Security
Network Segmentation
Cloud Security
Application Security21. Security Awareness
Section titled “21. Security Awareness”Human risk also requires protection.
Examples:
Security Training
Phishing Awareness
Role-Based Training
Secure Development Training22. Resilience
Section titled “22. Resilience”Protection also includes:
Backups
Redundancy
Failover
Capacity Management
Recovery Preparation23. Function 4 — Detect
Section titled “23. Function 4 — Detect”The Detect Function focuses on finding cybersecurity events.
Typical capabilities include:
Logging
Security Monitoring
Threat Detection
Anomaly Detection
Continuous Monitoring24. Detection Architecture
Section titled “24. Detection Architecture”Endpoints ────────┐Cloud ────────────┤Network ──────────┤Identity ─────────┤Applications ─────┘ ↓ SIEM ↓ Detection ↓ Alert25. Logging
Section titled “25. Logging”Organizations should identify what requires logging.
Examples:
Authentication
Administrative Activity
Cloud Changes
Security Events
Application Events
Network Traffic26. Detection Use Case
Section titled “26. Detection Use Case”Example:
Multiple Failed Logins ↓Successful Admin Login ↓Unusual Geography ↓Alert27. Continuous Monitoring
Section titled “27. Continuous Monitoring”Detection should not depend solely on occasional reviews.
Monitor:
Identity
Endpoints
Cloud
Networks
Applications
Vulnerabilities28. Detection Coverage
Section titled “28. Detection Coverage”Organizations should ask:
What AreWe Monitoring?
What AreWe Not Monitoring?
Are Critical AssetsCovered?
Are LogsAvailable?29. Function 5 — Respond
Section titled “29. Function 5 — Respond”The Respond Function focuses on actions taken after a cybersecurity incident is identified.
Common areas include:
Incident Management
Analysis
Communication
Containment
Mitigation
Reporting30. Incident Response Lifecycle
Section titled “30. Incident Response Lifecycle”Alert ↓Triage ↓Investigation ↓Containment ↓Eradication ↓Recovery ↓Lessons Learned31. Response Planning
Section titled “31. Response Planning”Organizations should maintain:
Incident Response Plan
Roles
Escalation Paths
Communication Plans
Technical Runbooks
External Contacts32. Incident Analysis
Section titled “32. Incident Analysis”During response, teams determine:
What Happened?
What SystemsAre Affected?
What DataIs Affected?
How DidIt Happen?
What Isthe Business Impact?33. Communication
Section titled “33. Communication”Incident response may involve:
Security
IT
Legal
Privacy
Executives
Customers
Regulators
Law Enforcementdepending on the incident.
34. Mitigation
Section titled “34. Mitigation”Actions may include:
Disable Accounts
Isolate Endpoints
Block Indicators
Patch Systems
Remove Malware
Restrict Network Access35. Function 6 — Recover
Section titled “35. Function 6 — Recover”The Recover Function focuses on restoring services and improving resilience after incidents.
Typical areas include:
Recovery Planning
Restoration
Communication
Lessons Learned
Improvement36. Recovery Example
Section titled “36. Recovery Example”Incident ↓Containment ↓Systems Restored ↓Data Validated ↓Service Resumed ↓Monitoring Increased37. Recovery Objectives
Section titled “37. Recovery Objectives”Recovery activities should align with:
RTO
RPO
Business Priorities
Criticality
Dependency Mapping38. Recovery Time Objective
Section titled “38. Recovery Time Objective”RTO asks:
How QuicklyMust the ServiceBe Restored?39. Recovery Point Objective
Section titled “39. Recovery Point Objective”RPO asks:
How Much Data LossCan the OrganizationAccept?40. Recovery Improvement
Section titled “40. Recovery Improvement”Recovery should feed lessons back into:
Govern
Identify
Protect
Detect
RespondThis creates continuous improvement.
41. CSF Categories
Section titled “41. CSF Categories”Each Function contains Categories.
Categories group related cybersecurity outcomes.
Conceptually:
Function ↓Category ↓Subcategory42. CSF Subcategories
Section titled “42. CSF Subcategories”Subcategories describe more specific outcomes.
They help organizations define:
Desired Cybersecurity Outcomesrather than prescribing one specific product.
43. Outcome-Based Design
Section titled “43. Outcome-Based Design”NIST CSF generally asks:
What OutcomeShould Exist?rather than:
Which ProductMust You Buy?This makes it technology-neutral.
44. Example Outcome
Section titled “44. Example Outcome”Outcome:
Access to systemsis managed basedon risk.Possible implementation:
RBAC
MFA
PAM
Access Reviews
Conditional Access45. Organizational Profiles
Section titled “45. Organizational Profiles”A CSF Organizational Profile describes how an organization applies CSF outcomes.
Profiles help answer:
Where Are We Now?
Where Do WeWant to Be?46. Current Profile
Section titled “46. Current Profile”The Current Profile represents:
Current CybersecurityStateExample:
MFAPartially Implemented
LoggingImplemented
Vendor MonitoringWeak
Recovery TestingPartial47. Target Profile
Section titled “47. Target Profile”The Target Profile represents:
Desired CybersecurityStateExample:
MFAFully Implemented
LoggingCentralized
Vendor MonitoringContinuous
Recovery TestingQuarterly48. Current vs Target
Section titled “48. Current vs Target”Current Profile ↓Gap ↓Target Profile49. Gap Analysis
Section titled “49. Gap Analysis”Example:
| Outcome | Current | Target | Gap |
|---|---|---|---|
| Privileged MFA | Partial | Full | High |
| Central Logging | Full | Full | None |
| Vendor Monitoring | Weak | Mature | High |
| Recovery Testing | Annual | Quarterly | Medium |
50. Prioritizing Gaps
Section titled “50. Prioritizing Gaps”Not all gaps have equal priority.
Consider:
Business Risk
Asset Criticality
Threat Exposure
Regulatory Requirements
Risk Appetite
Cost
Dependencies51. Example Prioritization
Section titled “51. Example Prioritization”Gap A:
Privileged MFAMissingGap B:
Minor DocumentationFormatting IssueBoth are gaps.
But the first likely carries much higher cybersecurity risk.
52. Implementation Tiers
Section titled “52. Implementation Tiers”CSF Implementation Tiers describe characteristics of how cybersecurity risk is managed.
They help organizations understand the maturity and consistency of their approach.
Conceptually:
Tier 1Partial
Tier 2Risk Informed
Tier 3Repeatable
Tier 4Adaptive53. Tier 1 — Partial
Section titled “53. Tier 1 — Partial”Characteristics may include:
Ad Hoc
Reactive
Limited Governance
Inconsistent Processes54. Tier 2 — Risk Informed
Section titled “54. Tier 2 — Risk Informed”Characteristics may include:
Risk Awareness
Some Defined Practices
Not Fully Standardized55. Tier 3 — Repeatable
Section titled “55. Tier 3 — Repeatable”Characteristics may include:
Formal Policies
Consistent Processes
Organization-Wide Practices
Repeatable Risk Management56. Tier 4 — Adaptive
Section titled “56. Tier 4 — Adaptive”Characteristics may include:
Continuous Improvement
Threat-Informed Decisions
Adaptive Controls
Integrated Risk Management57. Tiers Are Not Simple Maturity Scores
Section titled “57. Tiers Are Not Simple Maturity Scores”Do not assume:
Every OrganizationMust Reach Tier 4Organizations should select appropriate practices based on:
Risk
Business Need
Resources
Threat Environment58. CSF and Enterprise Risk Management
Section titled “58. CSF and Enterprise Risk Management”NIST CSF should connect cybersecurity to enterprise risk.
Business Objective ↓Cyber Risk ↓CSF Outcome ↓Control ↓KRI / KCI ↓Executive Reporting59. Example
Section titled “59. Example”Business objective:
Maintain CustomerSaaS AvailabilityRisk:
RansomwareDisruptionRelevant CSF areas:
Govern
Protect
Detect
Respond
Recover60. Risk Register Integration
Section titled “60. Risk Register Integration”A risk record may include:
Risk ID
CSF Function
CSF Outcome
Control
Owner
Residual Risk
Treatment61. CSF and Risk Appetite
Section titled “61. CSF and Risk Appetite”Example:
Risk:Privileged Account Compromise
Residual Risk:High
Risk Appetite:LowCSF gap:
Privileged AccessProtectionIncompleteTreatment:
Deploy PAM+Enforce MFA62. CSF and Control Libraries
Section titled “62. CSF and Control Libraries”Organizations can map CSF outcomes to enterprise controls.
Example:
CSF Outcome ↓IAM-001Privileged MFA
IAM-002Access Review
IAM-003PAM63. Common Control Model
Section titled “63. Common Control Model”One control can support multiple frameworks.
NIST CSF ↑ |ISO 27001 ← IAM-001 → PCI DSS | ↓ SOC 264. Benefits of Mapping
Section titled “64. Benefits of Mapping”This reduces:
Duplicate Controls
Duplicate Testing
Duplicate Evidence
Duplicate Remediation65. CSF and ISO 27001
Section titled “65. CSF and ISO 27001”NIST CSF and ISO 27001 have different purposes but can complement each other.
Simplified:
NIST CSF→ Cybersecurity Risk Outcomes
ISO 27001→ Information SecurityManagement SystemOrganizations may map controls between them.
66. CSF and CIS Controls
Section titled “66. CSF and CIS Controls”CIS Controls provide more prescriptive security safeguards.
Conceptually:
NIST CSFWhat OutcomesShould We Achieve?
CIS ControlsWhat Security SafeguardsCan Help?67. CSF and NIST RMF
Section titled “67. CSF and NIST RMF”NIST CSF provides high-level cybersecurity risk outcomes.
The Risk Management Framework provides a structured lifecycle for managing security and privacy risk for systems and organizations.
They can be complementary.
68. CSF and SOC 2
Section titled “68. CSF and SOC 2”A SOC 2 program may use CSF to help organize cybersecurity capabilities while mapping controls to applicable Trust Services Criteria.
69. CSF and PCI DSS
Section titled “69. CSF and PCI DSS”PCI DSS contains specific payment-card security requirements.
NIST CSF can help place those controls into a broader cybersecurity-risk-management model.
70. CSF and Cloud Security
Section titled “70. CSF and Cloud Security”CSF outcomes can be implemented across:
AWS
Azure
Google Cloud
SaaS
Hybrid Infrastructure71. Example — Cloud Identity
Section titled “71. Example — Cloud Identity”CSF outcome:
Access IsAppropriately ManagedImplementation:
Cloud IAM
MFA
PAM
Least Privilege
Access Reviews72. Example — Cloud Logging
Section titled “72. Example — Cloud Logging”CSF outcome:
Cybersecurity EventsAre DetectedImplementation:
CloudTrail
Azure Activity Logs
Cloud Audit Logs
SIEM73. Example — Cloud Recovery
Section titled “73. Example — Cloud Recovery”CSF outcome:
Services AreRestoredImplementation:
Backups
Multi-Region Architecture
Disaster Recovery
Recovery Testing74. CSF and Third-Party Risk
Section titled “74. CSF and Third-Party Risk”The framework also addresses cybersecurity supply-chain risk.
Organizations should consider:
Vendor Criticality
Security Requirements
Due Diligence
Contractual Controls
Monitoring
Incident Coordination75. Third-Party Example
Section titled “75. Third-Party Example”Critical vendor:
Payment ProviderRisk:
Vendor Security BreachCSF approach:
GovernDefine Supplier Requirements
IdentifyUnderstand Dependency
ProtectRequire Safeguards
DetectMonitor Security Signals
RespondCoordinate Incidents
RecoverPlan Service Continuity76. CSF Gap Assessment
Section titled “76. CSF Gap Assessment”A practical CSF assessment can follow:
Define Scope ↓Select Outcomes ↓Assess Current State ↓Define Target State ↓Identify Gaps ↓Prioritize ↓Create Improvement Plan77. Step 1 — Define Scope
Section titled “77. Step 1 — Define Scope”Scope may include:
Enterprise
Business Unit
Application
Cloud Platform
Product
Critical Service78. Step 2 — Identify Relevant Outcomes
Section titled “78. Step 2 — Identify Relevant Outcomes”Not every outcome needs identical implementation everywhere.
Select based on:
Business Context
Risk
Criticality
Regulation
Threat Exposure79. Step 3 — Assess Current State
Section titled “79. Step 3 — Assess Current State”Possible rating approach:
Not Implemented
Partially Implemented
Implemented
OptimizedThe organization may define its own consistent assessment scale.
80. Step 4 — Define Target State
Section titled “80. Step 4 — Define Target State”Target state should reflect:
Risk Appetite
Business Requirements
Regulatory Obligations
Threat Environment
Resources81. Step 5 — Identify Gap
Section titled “81. Step 5 — Identify Gap”Example:
Current:Access ReviewsAnnual
Target:QuarterlyGap:
Review FrequencyInsufficient82. Step 6 — Assess Risk
Section titled “82. Step 6 — Assess Risk”Ask:
What HappensIf We Do NotClose the Gap?83. Step 7 — Create Improvement Action
Section titled “83. Step 7 — Create Improvement Action”Document:
Gap
Risk
Action
Owner
Due Date
Priority
Status84. CSF Improvement Register
Section titled “84. CSF Improvement Register”Example:
| Gap | Risk | Action | Owner | Priority |
|---|---|---|---|---|
| Admin MFA incomplete | Account compromise | Enforce MFA | IAM | Critical |
| Vendor monitoring weak | Supply chain breach | Continuous monitoring | TPRM | High |
| Recovery tests annual | Recovery failure | Quarterly testing | IT Ops | High |
85. Prioritize Improvement Roadmap
Section titled “85. Prioritize Improvement Roadmap”Use:
Risk +Criticality +Effort +Dependencies86. Quick Wins
Section titled “86. Quick Wins”Examples may include:
Enable MFA
Disable Dormant Accounts
Centralize Logging
Fix Public Exposure87. Strategic Improvements
Section titled “87. Strategic Improvements”Examples may include:
PAM Deployment
Zero Trust Program
Enterprise Asset Inventory
Multi-Region Recovery
Security Data Platform88. CSF Metrics
Section titled “88. CSF Metrics”Organizations can define metrics tied to CSF outcomes.
Examples:
MFA Coverage
Asset Inventory Coverage
Logging Coverage
Critical Vulnerabilities Past SLA
Incident Response Time
Recovery Test Success89. KRI Example
Section titled “89. KRI Example”Risk:
Privileged AccountCompromiseKRI:
Privileged AccountsWithout MFATarget:
090. KCI Example
Section titled “90. KCI Example”Control:
Privileged MFAKCI:
MFA CoverageTarget:
100%91. CSF Dashboard
Section titled “91. CSF Dashboard”An executive dashboard may include:
Governance Health
Asset Visibility
Protection Coverage
Detection Coverage
Incident Readiness
Recovery Readiness92. Function-Level Dashboard
Section titled “92. Function-Level Dashboard”Example:
| Function | Status |
|---|---|
| Govern | Moderate |
| Identify | Strong |
| Protect | Moderate |
| Detect | Strong |
| Respond | Moderate |
| Recover | Weak |
93. Function Scores Require Context
Section titled “93. Function Scores Require Context”Avoid treating CSF as:
One Percentage=Cybersecurity RiskA strong average can hide a critical weakness.
Example:
Overall:90%but:
Recovery:45%for critical services.
94. Executive Reporting
Section titled “94. Executive Reporting”Executives need:
Material Gaps
Risk
Trend
Owner
Treatment
Decision Requirednot hundreds of subcategory rows.
95. Example Executive Narrative
Section titled “95. Example Executive Narrative”Recovery capability remainsbelow the target CSF profilefor critical customer services.
Two Tier-1 applications havenot completed recovery testingwithin the approved period.
Residual resilience risk remainsabove appetite.
IT Operations is implementingquarterly recovery exercises,with completion targeted for Q4.96. Continuous Improvement
Section titled “96. Continuous Improvement”CSF should not be treated as:
Assessment ↓FinishedUse:
Assess ↓Improve ↓Measure ↓Reassess ↺97. Triggered Reassessment
Section titled “97. Triggered Reassessment”Reassess after:
Major Incident
Acquisition
Cloud Migration
New Regulation
Significant Architecture Change
Critical Vendor Change98. CSF and Continuous Compliance
Section titled “98. CSF and Continuous Compliance”Some CSF outcomes can be continuously monitored.
Examples:
MFA
Logging
Encryption
Vulnerability Management
Endpoint Coverage
Cloud Configuration99. Example Continuous Monitoring
Section titled “99. Example Continuous Monitoring”CSF Outcome ↓IAM-001 ↓Identity Provider ↓Daily MFA Test ↓Control Health100. CSF Does Not Replace Risk Judgment
Section titled “100. CSF Does Not Replace Risk Judgment”A framework result such as:
Protect:85%does not automatically tell you:
Residual Cyber RiskProfessional risk analysis remains necessary.
101. CSF Does Not Equal Certification
Section titled “101. CSF Does Not Equal Certification”NIST CSF is primarily a cybersecurity risk-management framework.
Using the framework does not automatically mean:
Certifiedor:
Compliant withEvery Regulation102. CSF Is Not a Checklist-Only Framework
Section titled “102. CSF Is Not a Checklist-Only Framework”Weak approach:
Subcategory ↓Yes / No ↓DoneBetter:
Outcome ↓Business Risk ↓Control ↓Evidence ↓Effectiveness ↓Improvement103. Common Mistake — Start With Controls Without Scope
Section titled “103. Common Mistake — Start With Controls Without Scope”First understand:
What BusinessAre We Protecting?104. Common Mistake — Treat All Outcomes Equally
Section titled “104. Common Mistake — Treat All Outcomes Equally”Prioritize based on:
Risk
Criticality
Threat
Business Impact105. Common Mistake — Aim for Perfect Scores
Section titled “105. Common Mistake — Aim for Perfect Scores”The objective is:
Manage CybersecurityRisk Effectivelynot:
Score 100%Everywhere106. Common Mistake — Ignore Govern
Section titled “106. Common Mistake — Ignore Govern”Technical teams may focus on:
Protect
Detectwhile ignoring:
GovernThis can create strong tools but weak accountability.
107. Common Mistake — Weak Asset Inventory
Section titled “107. Common Mistake — Weak Asset Inventory”If assets are unknown:
Identify=Weakand many other functions become unreliable.
108. Common Mistake — Protect Without Detect
Section titled “108. Common Mistake — Protect Without Detect”Strong preventive controls do not eliminate the need for monitoring.
109. Common Mistake — Detect Without Respond
Section titled “109. Common Mistake — Detect Without Respond”Alerts without response capability create:
VisibilityWithout Action110. Common Mistake — Respond Without Recover
Section titled “110. Common Mistake — Respond Without Recover”Containing an incident is not the same as restoring critical services.
111. Common Mistake — Ignore Third Parties
Section titled “111. Common Mistake — Ignore Third Parties”Critical suppliers may materially affect cybersecurity risk.
112. Common Mistake — No Target Profile
Section titled “112. Common Mistake — No Target Profile”Without a target:
GapCannot BeClearly Defined113. Common Mistake — Improvement Plan Without Owner
Section titled “113. Common Mistake — Improvement Plan Without Owner”Every action should have:
Owner
Priority
Due Date
Status114. Common Mistake — Framework Assessment Becomes Annual Exercise
Section titled “114. Common Mistake — Framework Assessment Becomes Annual Exercise”Use CSF as an ongoing risk-management model.
115. End-to-End Example — Ransomware
Section titled “115. End-to-End Example — Ransomware”Business objective:
Maintain CriticalCustomer ServicesRisk:
RansomwareDisruptionGovern
Section titled “Govern”Define Risk Appetite
Assign Ownership
Approve Resilience StrategyIdentify
Section titled “Identify”Identify Critical Assets
Identify Dependencies
Assess Ransomware RiskProtect
Section titled “Protect”EDR
MFA
Segmentation
Patch Management
BackupsDetect
Section titled “Detect”EDR Alerts
SIEM
Behavior AnalyticsRespond
Section titled “Respond”Contain Malware
Isolate Systems
Activate Incident ResponseRecover
Section titled “Recover”Restore Systems
Validate Data
Resume Services
Review Lessons116. End-to-End Example — Privileged Access
Section titled “116. End-to-End Example — Privileged Access”Risk:
Privileged AccountCompromiseCurrent Profile:
MFA:Partial
PAM:Not Implemented
Access Reviews:AnnualTarget Profile:
MFA:100%
PAM:Implemented
Access Reviews:QuarterlyGap:
MFA Coverage
PAM
Review FrequencyImprovement:
IAM Program117. End-to-End Example — Vendor Risk
Section titled “117. End-to-End Example — Vendor Risk”Risk:
Critical SaaSProvider BreachCurrent:
Initial Assessment OnlyTarget:
Risk Tiering
Annual Assessment
Incident Monitoring
Contract Requirements
Continuous Monitoring118. End-to-End Example — Recovery
Section titled “118. End-to-End Example — Recovery”Current:
Annual Backup CheckTarget:
Quarterly Recovery Test
Critical Service RTO Testing
Dependency ValidationThe gap may materially affect:
Recover119. Enterprise CSF Operating Model
Section titled “119. Enterprise CSF Operating Model”A mature operating model may look like:
Board / Executives ↓Cyber Risk Governance ↓NIST CSF Profile ↓Enterprise Controls ↓Technology Implementation ↓Monitoring ↓Metrics ↓Risk Reporting ↓Improvement120. CSF Implementation Roadmap
Section titled “120. CSF Implementation Roadmap”A practical implementation may follow:
Phase 1Business Context
Phase 2Scope
Phase 3Current Profile
Phase 4Risk Assessment
Phase 5Target Profile
Phase 6Gap Analysis
Phase 7Prioritization
Phase 8Improvement Plan
Phase 9Metrics
Phase 10Continuous ImprovementPhase 1 — Business Context
Section titled “Phase 1 — Business Context”Understand:
Mission
Products
Critical Services
Customers
Regulation
Threat EnvironmentPhase 2 — Scope
Section titled “Phase 2 — Scope”Define:
Business Units
Applications
Cloud
Locations
Vendors
DataPhase 3 — Current Profile
Section titled “Phase 3 — Current Profile”Assess current outcomes.
Phase 4 — Risk Assessment
Section titled “Phase 4 — Risk Assessment”Determine:
Threats
Weaknesses
Impacts
Residual RiskPhase 5 — Target Profile
Section titled “Phase 5 — Target Profile”Define desired state based on risk.
Phase 6 — Gap Analysis
Section titled “Phase 6 — Gap Analysis”Compare:
Current vsTargetPhase 7 — Prioritize
Section titled “Phase 7 — Prioritize”Use:
Risk
Criticality
Effort
DependenciesPhase 8 — Improvement Plan
Section titled “Phase 8 — Improvement Plan”Assign:
Action
Owner
Funding
Due Date
PriorityPhase 9 — Metrics
Section titled “Phase 9 — Metrics”Define:
KRIs
KCIs
KPIsPhase 10 — Continuous Improvement
Section titled “Phase 10 — Continuous Improvement”Repeat assessment as the environment changes.
NIST CSF Assessment Checklist
Section titled “NIST CSF Assessment Checklist”Govern
Section titled “Govern”-
cybersecurity governance defined.
-
roles and responsibilities assigned.
-
risk-management strategy documented.
-
risk appetite established.
-
policies maintained.
-
supply-chain governance established.
-
legal and regulatory obligations identified.
-
executive oversight established.
Identify
Section titled “Identify”-
assets inventoried.
-
applications inventoried.
-
cloud resources inventoried.
-
data identified.
-
vendors identified.
-
dependencies understood.
-
risks assessed.
-
critical assets prioritized.
Protect
Section titled “Protect”-
IAM controls implemented.
-
MFA implemented.
-
privileged access governed.
-
awareness training maintained.
-
data protected.
-
secure configuration maintained.
-
vulnerabilities managed.
-
resilience safeguards implemented.
Detect
Section titled “Detect”-
logging enabled.
-
critical systems monitored.
-
anomalies detected.
-
security alerts managed.
-
monitoring coverage understood.
-
detection processes tested.
Respond
Section titled “Respond”-
incident-response plan maintained.
-
roles defined.
-
escalation established.
-
investigation procedures maintained.
-
communication processes defined.
-
containment procedures maintained.
-
exercises performed.
Recover
Section titled “Recover”-
recovery plans documented.
-
backups maintained.
-
RTOs defined.
-
RPOs defined.
-
recovery exercises performed.
-
critical dependencies tested.
-
lessons learned incorporated.
NIST CSF Deliverables
Section titled “NIST CSF Deliverables”After completing this lesson, you should be able to design:
01 NIST CSF Scope Document
02 Business Context Assessment
03 CSF Current Profile
04 CSF Target Profile
05 CSF Gap Assessment
06 Cyber Risk Register
07 CSF-to-Control Mapping
08 CSF-to-Framework Mapping
09 CSF Improvement Register
10 CSF Prioritization Matrix
11 CSF KRI Catalogue
12 CSF KCI Catalogue
13 Function-Level Dashboard
14 Risk Appetite Mapping
15 Third-Party CSF Assessment
16 Cloud CSF Assessment
17 Incident Readiness Assessment
18 Recovery Readiness Assessment
19 Executive CSF Dashboard
20 CSF Continuous Improvement RoadmapPractical Activity — Build a CSF Current Profile
Section titled “Practical Activity — Build a CSF Current Profile”Your organization operates:
AWS
Azure
Microsoft 365
Customer SaaS
Remote Workforce
Critical SaaS VendorsAssess:
Govern
Identify
Protect
Detect
Respond
Recoverusing:
Strong
Moderate
WeakFor every rating, document:
Evidence
Gap
RiskPractical Activity — Build a Target Profile
Section titled “Practical Activity — Build a Target Profile”For each Function define:
Current State
Target State
Gap
Owner
PriorityExample:
Function:Recover
Current:Annual Recovery Testing
Target:Quarterly Tier-1Recovery Testing
Gap:Testing Frequency
Owner:IT Operations
Priority:HighPractical Activity — Map Controls
Section titled “Practical Activity — Map Controls”Map these controls:
Privileged MFA
Cloud Logging
Vulnerability Management
Incident Response
Backup & Recovery
Vendor Assessmentto relevant NIST CSF outcomes.
Then map the same controls to:
ISO 27001
SOC 2
PCI DSSwhere appropriate.
Practical Activity — Prioritize CSF Gaps
Section titled “Practical Activity — Prioritize CSF Gaps”You identify:
15 CSF Gapsincluding:
Privileged MFA Missing
Weak Asset Inventory
Recovery Testing Incomplete
Vendor Monitoring Weak
Policy Review Overdue
Minor Documentation GapPrioritize using:
Business Risk
Control Criticality
Threat Exposure
Regulatory Impact
EffortPractical Activity — Build Executive CSF Dashboard
Section titled “Practical Activity — Build Executive CSF Dashboard”Display:
Function Health
Top CSF Gaps
Critical Risks
Risk Appetite Breaches
Improvement Actions
Overdue ActionsExample:
GOVERN Moderate
IDENTIFY Strong
PROTECT Moderate
DETECT Strong
RESPOND Moderate
RECOVER WeakThen identify:
What RequiresLeadership Attention?NIST CSF GRC Mindset
Section titled “NIST CSF GRC Mindset”When applying NIST CSF, ask:
What BusinessAre We Protecting?
What ServicesAre Critical?
What Cyber RisksCould Affect Them?
Who OwnsThose Risks?
What IsOur Risk Appetite?
What CSF OutcomesMatter Most?
What IsOur Current Profile?
What ShouldOur Target Profile Be?
What GapsExist?
Which GapsCreate Material Risk?
What ControlsAddress Them?
Who OwnsThose Controls?
What EvidenceShows They Work?
How Do WeMeasure Effectiveness?
What KRIsShow Risk Increasing?
What KCIsShow Controls Weakening?
Are OurCritical Assets Known?
Are WeProtecting Them?
Can WeDetect Attacks?
Can WeRespond Effectively?
Can WeRecover Critical Services?
Are Third PartiesIncluded?
Are RisksWithin Appetite?
What ImprovementsShould Come First?
What DoesLeadership Needto Decide?
Are WeUsing CSFas a Checklist?
Or Are WeUsing It toManage Cyber Risk?That is the mindset of a GRC professional using the NIST Cybersecurity Framework.
Key Takeaways
Section titled “Key Takeaways”-
NIST CSF is a cybersecurity risk-management framework.
-
CSF 2.0 is organized around Govern, Identify, Protect, Detect, Respond, and Recover.
-
Govern provides enterprise direction and oversight across the cybersecurity lifecycle.
-
Identify helps organizations understand assets, dependencies, and cybersecurity risk.
-
Protect focuses on safeguards that reduce cybersecurity exposure.
-
Detect focuses on monitoring and identifying cybersecurity events.
-
Respond focuses on managing cybersecurity incidents.
-
Recover focuses on restoring services and improving resilience.
-
CSF is outcome-based rather than tied to specific technologies.
-
Organizational Profiles help compare current and desired cybersecurity states.
-
Current Profiles describe present capabilities.
-
Target Profiles describe desired cybersecurity outcomes.
-
Gap analysis identifies differences between Current and Target Profiles.
-
Gaps should be prioritized based on risk rather than simple completion percentages.
-
Implementation Tiers describe characteristics of how cybersecurity risk is managed.
-
Tier 4 is not automatically the required target for every organization.
-
CSF should connect cybersecurity controls to enterprise risks and business objectives.
-
CSF outcomes can be mapped to enterprise common controls.
-
Common controls can support CSF alongside ISO 27001, SOC 2, PCI DSS, and other requirements.
-
CSF can support cloud, third-party, resilience, identity, and incident-management programs.
-
CSF assessment should include evidence and control effectiveness rather than only yes/no responses.
-
Executive reporting should focus on material gaps, trends, ownership, treatment, and decisions.
-
CSF does not automatically provide certification.
-
Strong average scores can hide critical weaknesses.
-
Continuous monitoring can provide ongoing evidence for selected CSF outcomes.
-
CSF should operate as a continuous risk-management and improvement model.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is NIST CSF?
-
What is the primary purpose of NIST CSF?
-
What are the six CSF 2.0 Functions?
-
What is the purpose of Govern?
-
What activities belong under Identify?
-
What activities belong under Protect?
-
What activities belong under Detect?
-
What activities belong under Respond?
-
What activities belong under Recover?
-
Why is asset inventory important?
-
Why should asset criticality be defined?
-
What is a cybersecurity risk scenario?
-
What is an Organizational Profile?
-
What is a Current Profile?
-
What is a Target Profile?
-
What is CSF gap analysis?
-
How should CSF gaps be prioritized?
-
What are CSF Implementation Tiers?
-
What characterizes Tier 1?
-
What characterizes Tier 2?
-
What characterizes Tier 3?
-
What characterizes Tier 4?
-
Why should tiers not be treated as simple maturity scores?
-
How can CSF connect with enterprise risk management?
-
How can CSF connect with risk appetite?
-
How can CSF outcomes map to enterprise controls?
-
How can common controls support multiple frameworks?
-
How does NIST CSF differ from ISO 27001?
-
How can CIS Controls complement NIST CSF?
-
How does NIST RMF differ from NIST CSF?
-
How can CSF support cloud-security governance?
-
How can CSF support third-party risk?
-
What is a CSF Current-to-Target gap?
-
Why should CSF assessments include evidence?
-
What KRIs can support CSF reporting?
-
What KCIs can support CSF reporting?
-
Why can overall CSF scores be misleading?
-
Why is continuous improvement important?
-
When should a CSF reassessment occur?
-
How should executives use CSF reporting?
What’s Next?
Section titled “What’s Next?”➡️ Next: 02 — NIST Risk Management Framework (RMF)
In the next lesson, you will move from the broad cybersecurity-risk outcomes of NIST CSF into the more structured NIST Risk Management Framework.
You will learn how RMF organizes security and privacy risk management through a lifecycle involving:
PREPARE ↓CATEGORIZE ↓SELECT ↓IMPLEMENT ↓ASSESS ↓AUTHORIZE ↓MONITORYou will explore how organizations connect:
Systems
Information Types
Impact Levels
Security Controls
Control Implementation
Assessment
Risk Acceptance
Authorization
Continuous Monitoringinto a disciplined system-level risk-management process.
➡️ Next: 02 — NIST Risk Management Framework (RMF)