# What is the NIST Cybersecurity Framework (CSF)?

> The NIST Cybersecurity Framework is a voluntary framework of outcomes that helps organizations understand, manage, and reduce cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

- Canonical URL: https://yellowcube.eu/glossary/nist-cybersecurity-framework/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Version 2.0, published in 2024 as NIST CSWP 29, extended the framework beyond its original critical-infrastructure focus to organizations of any size and sector. The framework describes desired outcomes rather than prescriptive controls, so organizations can map it to their own obligations, architecture, and maturity.

The framework is used in three main ways: as a common language between technical teams and leadership, as a structure for assessing current posture against a target profile, and as a bridge to detailed control catalogs such as NIST SP 800-53 or ISO/IEC 27001 through published mappings.

### Key points

- **Functions and categories:** Govern establishes the risk-management strategy and accountability; Identify covers assets and risks; Protect, Detect, Respond, and Recover cover safeguards, detection, response, and restoration outcomes respectively.
- **Profiles and tiers:** An organizational profile compares current and target outcomes, while the four tiers describe increasing rigor in risk-management practices; tiers indicate process maturity, not a score of security.
- **Application:** Scope the systems and services covered, document current outcomes, set a target profile, prioritize gaps by risk, and track progress with owners and evidence.
- **Important limitation:** CSF alignment is a management outcome, not certification or proof of security. Self-assessed profiles can overstate capability, and the framework’s flexibility means two organizations claiming conformance may operate very different controls.

### Related terms

[Cybersecurity](<https://yellowcube.eu/glossary/cybersecurity/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [National Institute of Standards and Technology Special Publication (NIST SP) 800-53](<https://yellowcube.eu/glossary/national-institute-of-standards-and-technology-special-publication-800-53/>) · [International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001](<https://yellowcube.eu/glossary/international-organization-for-standardization-international-electrotechnical-commission-27001/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Cyber resilience](<https://yellowcube.eu/glossary/cyber-resilience/>)

### Sources

[NIST, Cybersecurity Framework (CSF) 2.0](https://www.nist.gov/cyberframework) · [NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0](https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

