Back to Frameworks
NIST CSF
National Institute of Standards and Technology

NIST Cybersecurity Framework

A voluntary framework for managing cybersecurity risk, organized around five core functions: Identify, Protect, Detect, Respond, and Recover. Originally designed for critical infrastructure, now used broadly because it is actually useful.

The Five Core Functions

NIST CSF organizes cybersecurity into five functions that represent the complete cybersecurity lifecycle. Every organization, regardless of size or maturity, should be able to place their current activities into these five categories.

Identify
Function
Develop organizational understanding to manage cybersecurity risk to systems, assets, data, and capabilities.

Categories

  • Asset Management
  • Business Environment
  • Governance
  • Risk Assessment
  • Risk Management Strategy
  • Supply Chain Risk Management

Maturity Levels

1

Partial

Processes are not formalized. Cybersecurity risk is managed in an ad hoc, reactive manner.

2

Risk Informed

Processes are approved by management but may not be established as organizational-wide policy.

3

Repeatable

Processes are formally approved and expressed as policy. Regular reviews ensure compliance.

4

Adaptive

Organization adapts its cybersecurity practices based on lessons learned and predictive indicators.

Protect
Function
Develop and implement appropriate safeguards to ensure delivery of critical services.

Categories

  • Identity Management and Access Control
  • Awareness and Training
  • Data Security
  • Information Protection Processes
  • Maintenance
  • Protective Technology

Maturity Levels

1

Partial

Limited security controls. Not consistently applied across systems.

2

Risk Informed

Security controls are in place but may vary in coverage and consistency.

3

Repeatable

Controls are formally approved, documented, and consistently implemented organization-wide.

4

Adaptive

Active monitoring and automated responses. Controls evolve with threats.

Detect
Function
Develop and implement appropriate activities to identify the occurrence of a cybersecurity event.

Categories

  • Anomalies and Events
  • Security Continuous Monitoring
  • Detection Processes

Maturity Levels

1

Partial

Limited detection capability. Often discovered after damage is done.

2

Risk Informed

Some monitoring in place. Alerts may require manual investigation.

3

Repeatable

Continuous monitoring with defined detection processes and automated alerts.

4

Adaptive

AI-assisted detection. Automated threat identification and initial response.

Respond
Function
Develop and implement appropriate activities to take action regarding a detected cybersecurity incident.

Categories

  • Response Planning
  • Communications
  • Analysis
  • Mitigation
  • Improvements

Maturity Levels

1

Partial

Ad hoc responses. No formal incident response plan.

2

Risk Informed

Documented response procedures exist but may not be regularly practiced.

3

Repeatable

Formal response plan with regular drills and clearly defined roles.

4

Adaptive

Automated containment. Post-incident analysis feeds continuous improvement.

Recover
Function
Develop and implement appropriate activities to restore capabilities or services that were impaired.

Categories

  • Recovery Planning
  • Improvements
  • Communications

Maturity Levels

1

Partial

Limited recovery capability. Restoration is chaotic and inconsistent.

2

Risk Informed

Basic recovery plans exist but untested. May not cover all scenarios.

3

Repeatable

Tested recovery procedures with defined priorities and resource requirements.

4

Adaptive

Automated restoration. Lessons from incidents feed resilience improvements.

Implementation Tiers

Tiers describe how much cybersecurity risk management is embedded in organizational behavior. They are not maturity levels, but rather how systematically you approach cybersecurity.

Tier 1
Partial
Organization does not have formal cybersecurity risk management practices. Processes are ad hoc.

Best suited for:

Small teams with minimal regulatory pressure, or as a starting point before maturing.

Tier 2
Risk Informed
Risk management practices are approved by management but not organization-wide. Prioritization is based on threats but not formally analyzed.

Best suited for:

Growing businesses with some compliance requirements, or teams with limited resources.

Tier 3
Repeatable
Formal policies and processes are established, documented, and consistently followed. Regular review and testing occurs.

Best suited for:

Organizations with regulatory compliance needs, or those handling sensitive data.

Tier 4
Adaptive
Organization actively improves based on lessons learned and predictive indicators. Advanced technologies and processes in place.

Best suited for:

Mature organizations, critical infrastructure, or high-risk environments.

Common Implementation Challenges

Resource Constraints

Small teams cannot implement everything at once. NIST CSF explicitly supports partial implementation. Start with the functions that address your highest risks, then expand.

Cultural Adoption

Policies that nobody follows are worse than no policies. Involve end users in developing awareness training. Make security expectations realistic and achievable.

Legacy Systems

Older systems may not support modern controls. Document compensating controls and plan for eventual replacement. Not every gap can be fixed immediately.

Third-Party Risk

Supply chain risks are difficult to control. Focus on what you can verify: security questionnaires, certifications, contractual requirements, and monitoring.

Ready to assess your NIST CSF posture?

ABC of Cyber maps your current controls to the framework and identifies gaps worth addressing first.