NIST Cybersecurity Framework 2.0
NIST (US)Organise cybersecurity outcomes into functions that can be assessed and communicated to leadership.
- Audience
- Any organisation; widely used as a common language between technical teams and executives.
- Best used for
- Assessing overall security posture and building an improvement roadmap that non specialists can follow.
- Core concepts
- GovernIdentifyProtectDetectRespondRecoverProfiles and tiers for current and target state
- Relationship to others
- Maps to CIS Controls and ISO 27001 control sets; often used as the umbrella with CIS providing the technical detail.
