NIST Cybersecurity Framework
A voluntary framework for managing cybersecurity risk, organized around five core functions: Identify, Protect, Detect, Respond, and Recover. Originally designed for critical infrastructure, now used broadly because it is actually useful.
The Five Core Functions
NIST CSF organizes cybersecurity into five functions that represent the complete cybersecurity lifecycle. Every organization, regardless of size or maturity, should be able to place their current activities into these five categories.
Categories
- Asset Management
- Business Environment
- Governance
- Risk Assessment
- Risk Management Strategy
- Supply Chain Risk Management
Maturity Levels
Partial
Processes are not formalized. Cybersecurity risk is managed in an ad hoc, reactive manner.
Risk Informed
Processes are approved by management but may not be established as organizational-wide policy.
Repeatable
Processes are formally approved and expressed as policy. Regular reviews ensure compliance.
Adaptive
Organization adapts its cybersecurity practices based on lessons learned and predictive indicators.
Categories
- Identity Management and Access Control
- Awareness and Training
- Data Security
- Information Protection Processes
- Maintenance
- Protective Technology
Maturity Levels
Partial
Limited security controls. Not consistently applied across systems.
Risk Informed
Security controls are in place but may vary in coverage and consistency.
Repeatable
Controls are formally approved, documented, and consistently implemented organization-wide.
Adaptive
Active monitoring and automated responses. Controls evolve with threats.
Categories
- Anomalies and Events
- Security Continuous Monitoring
- Detection Processes
Maturity Levels
Partial
Limited detection capability. Often discovered after damage is done.
Risk Informed
Some monitoring in place. Alerts may require manual investigation.
Repeatable
Continuous monitoring with defined detection processes and automated alerts.
Adaptive
AI-assisted detection. Automated threat identification and initial response.
Categories
- Response Planning
- Communications
- Analysis
- Mitigation
- Improvements
Maturity Levels
Partial
Ad hoc responses. No formal incident response plan.
Risk Informed
Documented response procedures exist but may not be regularly practiced.
Repeatable
Formal response plan with regular drills and clearly defined roles.
Adaptive
Automated containment. Post-incident analysis feeds continuous improvement.
Categories
- Recovery Planning
- Improvements
- Communications
Maturity Levels
Partial
Limited recovery capability. Restoration is chaotic and inconsistent.
Risk Informed
Basic recovery plans exist but untested. May not cover all scenarios.
Repeatable
Tested recovery procedures with defined priorities and resource requirements.
Adaptive
Automated restoration. Lessons from incidents feed resilience improvements.
Implementation Tiers
Tiers describe how much cybersecurity risk management is embedded in organizational behavior. They are not maturity levels, but rather how systematically you approach cybersecurity.
Best suited for:
Small teams with minimal regulatory pressure, or as a starting point before maturing.
Best suited for:
Growing businesses with some compliance requirements, or teams with limited resources.
Best suited for:
Organizations with regulatory compliance needs, or those handling sensitive data.
Best suited for:
Mature organizations, critical infrastructure, or high-risk environments.
Common Implementation Challenges
Small teams cannot implement everything at once. NIST CSF explicitly supports partial implementation. Start with the functions that address your highest risks, then expand.
Policies that nobody follows are worse than no policies. Involve end users in developing awareness training. Make security expectations realistic and achievable.
Older systems may not support modern controls. Document compensating controls and plan for eventual replacement. Not every gap can be fixed immediately.
Supply chain risks are difficult to control. Focus on what you can verify: security questionnaires, certifications, contractual requirements, and monitoring.
Ready to assess your NIST CSF posture?
ABC of Cyber maps your current controls to the framework and identifies gaps worth addressing first.