{
  "converted": 1,
  "failed": 0,
  "documents": [
    {
      "ok": true,
      "source": "https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf",
      "name": "NIST.CSWP.29.pdf",
      "format": "PDF",
      "mimeType": "application/pdf",
      "bytes": 1518858,
      "characters": 65426,
      "approxTokens": 16357,
      "truncated": false,
      "emptyText": false,
      "preview": "National Institute of Standards and Technology This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.29 Febr…",
      "ms": 1379,
      "metadata": {
        "PDFFormatVersion": "1.6",
        "Language": "EN-US",
        "IsLinearized": "true",
        "IsAcroFormPresent": "false",
        "IsXFAPresent": "false",
        "IsCollectionPresent": "false",
        "IsSignaturesPresent": "false",
        "Author": "National Institute of Standards and Technology",
        "Custom.ContentTypeId": "0x01010039BCE524E722AC4882B40135ECFFCA17",
        "Custom.DOI (Machine-readable PubID)": "NIST.CSWP.29",
        "Custom.DOI Value": "NIST.CSWP.29",
        "Custom.GrammarlyDocumentId": "b30b891388ea4e76087a9e77cdc664db0d1859c0ea00bed42f0042bade33dbcd",
        "Custom.PubID": "NIST CSWP 29",
        "Custom.PubID (DOI)": "NIST.CSWP.29",
        "Custom.PubID (Human-readable)": "NIST CSWP 29",
        "Custom.Publication Date": "Month DD, 2024",
        "Custom.ShortTitleLine1": "The NIST Cybersecurity Framework (CSF) 2.0",
        "CreationDate": "D:20240306154645-05'00'",
        "Creator": "Acrobat PDFMaker 23 for Word",
        "Keywords": "cybersecurity; Cybersecurity Framework (CSF); cybersecurity risk governance; cybersecurity risk management; enterprise risk management; Profiles; Tiers",
        "ModDate": "D:20250604105823-04'00'",
        "Producer": "Adobe PDF Library 23.8.53",
        "Subject": "The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes. This document describes CSF 2.0, its components, and some of the many ways that it can be used.",
        "Title": "The NIST Cybersecurity Framework (CSF) 2.0",
        "xmp:modifydate": "2025-06-04T10:58:23-04:00",
        "xmp:createdate": "2024-03-06T15:46:45-05:00",
        "xmp:metadatadate": "2025-06-04T10:58:23-04:00",
        "xmp:creatortool": "Acrobat PDFMaker 23 for Word",
        "xmpmm:documentid": "uuid:b3e5db79-3fc1-419e-8795-117f12c23b4c",
        "xmpmm:instanceid": "uuid:aad63db6-5809-4392-a6c8-eedf05d3621a",
        "xmpmm:subject": "3",
        "dc:format": "application/pdf",
        "dc:title": "The NIST Cybersecurity Framework (CSF) 2.0",
        "dc:description": "The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes. This document describes CSF 2.0, its components, and some of the many ways that it can be used.",
        "dc:creator": "National Institute of Standards and Technology",
        "pdf:producer": "Adobe PDF Library 23.8.53",
        "pdf:keywords": "cybersecurity; Cybersecurity Framework (CSF); cybersecurity risk governance; cybersecurity risk management; enterprise risk management; Profiles; Tiers",
        "pdfx:contenttypeid": "0x01010039BCE524E722AC4882B40135ECFFCA17",
        "pdfx:pubidↂ0020ↂ0028doiↂ0029": "NIST.CSWP.29",
        "pdfx:doiↂ0020ↂ0028machine-readableↂ0020pubidↂ0029": "NIST.CSWP.29",
        "pdfx:shorttitleline1": "The NIST Cybersecurity Framework (CSF) 2.0",
        "pdfx:pubid": "NIST CSWP 29",
        "pdfx:pubidↂ0020ↂ0028human-readableↂ0029": "NIST CSWP 29",
        "pdfx:publicationↂ0020date": "Month DD, 2024",
        "pdfx:doiↂ0020value": "NIST.CSWP.29",
        "pdfx:grammarlydocumentid": "b30b891388ea4e76087a9e77cdc664db0d1859c0ea00bed42f0042bade33dbcd",
        "photoshop:headline": "The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization â•fl regardless of its size, sector, or maturity â•fl to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes. This document describes CSF 2.0, its components, and some of the many ways that it can be used."
      },
      "markdown": "# NIST.CSWP.29.pdf\n### Page 1\n\nNational Institute of Standards and Technology\n\n\nThis publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.29\n\n\nFebruary 26, 2024\n\n\n![National Institute of Standards and Technology \\(NIST\\) logo\u0000]()\n\n# The NIST Cybersecurity\nFramework (CSF) 2.0\n\n\n### Page 2\n## NIST CSWP 29\nFebruary 26, 2024Abstract\n\n\nThe NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government\nagencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-\nlevel cybersecurity outcomes that can be used by any organization — regardless of its size,\nsector, or maturity — to better understand, assess, prioritize, and communicate its\ncybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it\nlinks to online resources that provide additional guidance on practices and controls that could\nbe used to achieve those outcomes. This document describes CSF 2.0, its components, and\nsome of the many ways that it can be used.\n\n## Keywords\n\n\ncybersecurity; Cybersecurity Framework (CSF); cybersecurity risk governance; cybersecurity risk\nmanagement; enterprise risk management; Profiles; Tiers.\n\n## Audience\n\n\nIndividuals responsible for developing and leading cybersecurity programs are the primary\naudience for the CSF. The CSF can also be used by others involved in managing risk — including\nexecutives, boards of directors, acquisition professionals, technology professionals, risk\nmanagers, lawyers, human resources specialists, and cybersecurity and risk management\nauditors — to guide their cybersecurity-related decisions. Additionally, the CSF can be useful to\nthose making and influencing policy (e.g., associations, professional organizations, regulators)\nwho set and communicate priorities for cybersecurity risk management.\n\n## Supplemental Content\n\n\nNIST will continue to build and host additional resources to help organizations implement the\nCSF, including Quick Start Guides and Community Profiles. All resources are made publicly\navailable on the. Suggestions for additional resources to reference on theNIST CSF website can always be shared with NIST at.\n\n## Note to Readers\n\n\nUnless otherwise noted, documents cited, referenced, or excerpted in this publication are not\nwholly incorporated into this publication.\n\n\nBefore version 2.0, the Cybersecurity Framework was called the “Framework for Improving\nCritical Infrastructure Cybersecurity.” This title is not used for CSF 2.0.\n\n\n### Page 3\n## Acknowledgments\n\n\nThe CSF is the result of a multi-year collaborative effort across industry, academia, and\ngovernment in the United States and around the world. NIST acknowledges and thanks all of\nthose who have contributed to this revised CSF. Information on the CSF development process\ncan be found on the Lessons learned about the use of the CSF can always beshared with NIST at.\n\n\n### Page 4\n\n\n### Page 5\n# Preface\n\n\nThe Cybersecurity Framework (CSF) 2.0 is designed to help organizations of all sizes and sectors\n— including industry, government, academia, and nonprofit — to manage and reduce their\ncybersecurity risks. It is useful regardless of the maturity level and technical sophistication of an\norganization’s cybersecurity programs. Nevertheless, the CSF does not embrace a one-size-fits-\nall approach. Each organization has both common and unique risks, as well as varying risk\nappetites and tolerances, specific missions, and objectives to achieve those missions. By\nnecessity, the way organizations implement the CSF will vary.\n\n\nIdeally, the CSF will be used to address cybersecurity risks alongside other risks of the\nenterprise, including those that are financial, privacy, supply chain, reputational, technological,\nor physical in nature.\n\n\nThe CSF describes desired outcomes that are intended to be understood by a broad audience,\nincluding executives, managers, and practitioners, regardless of their cybersecurity expertise.\nBecause these outcomes are sector-, country-, and technology-neutral, they provide an\norganization with the flexibility needed to address their unique risks, technologies, and mission\nconsiderations. Outcomes are mapped directly to a list of potential security controls for\nimmediate consideration to mitigate cybersecurity risks.\n\n\nAlthough not prescriptive, the CSF assists its users in learning about and selecting specific\noutcomes. Suggestions for how specific outcomes may be achieved are provided in an\nexpanding suite of online resources that complement the CSF, including a series of Quick Start\nGuides (QSGs). Also, various tools offer downloadable formats to help organizations that\nchoose to automate some of their processes. The QSGs suggest initial ways to use the CSF and\ninvite the reader to explore the CSF and related resources in greater depth. Available through\nthe, the CSF and these supplementary resources from NIST and others shouldbe viewed as a “CSF portfolio” to help manage and reduce risks. Regardless of how it is applied,\nthe CSF prompts its users to consider their cybersecurity posture in context and then adapt the\nCSF to their specific needs.\n\n\nBuilding on previous versions, CSF 2.0 contains new features that highlight the importance ofgovernance and supply chains. Special attention is paid to the QSGs to ensure that the CSF is\nrelevant and readily accessible by smaller organizations as well as their larger counterparts.\nNIST now provides Implementation Examples and Informative References, which are available\nonline and updated regularly. Creating current and target state Organizational Profiles helps\norganizations to compare where they are versus where they want or need to be and allows\nthem to implement and assess security controls more quickly.\n\n\nCybersecurity risks are expanding constantly, and managing those risks must be a continuous\nprocess. This is true regardless of whether an organization is just beginning to confront its\ncybersecurity challenges or whether it has been active for many years with a sophisticated,\nwell-resourced cybersecurity team. The CSF is designed to be valuable for any type of\norganization and is expected to provide appropriate guidance over a long time.\n\n\n### Page 6\n# 1. Cybersecurity Framework (CSF) Overview\n\n\nThis document is version 2.0 of the NIST Cybersecurity Framework (Framework or CSF). It\nincludes the following components:\n\n\n- • CSF Core, the nucleus of the CSF, which is a taxonomy of high-level cybersecurity\noutcomes that can help any organization manage its cybersecurity risks. The CSF Core\ncomponents are a hierarchy of Functions, Categories, and Subcategories that detail each\noutcome. These outcomes can be understood by a broad audience, including\nexecutives, managers, and practitioners, regardless of their cybersecurity expertise.\nBecause the outcomes are sector-, country-, and technology-neutral, they provide an\norganization with the flexibility needed to address its unique risks, technologies, and\nmission considerations.\n\n- • CSF Organizational Profiles, which are a mechanism for describing an organization’s\ncurrent and/or target cybersecurity posture in terms of the CSF Core’s outcomes.\n\n- • CSF Tiers, which can be applied to CSF Organizational Profiles to characterize the rigor of\nan organization’s cybersecurity risk governance and management practices. Tiers can\nalso provide context for how an organization views cybersecurity risks and the processes\nin place to manage those risks.\n\n\nThis document describes what desirable outcomes an organization can aspire to achieve. It\ndoes not prescribe outcomes nor how they may be achieved. Descriptions of how an\norganization can achieve those outcomes are provided in a suite of online resources that\ncomplement the CSF and are available through the. These resources offeradditional guidance on practices and controls that could be used to achieve outcomes and are\nintended to help an organization understand, adopt, and use the CSF. They include:\n\n\n-  that point to sources of guidance on each outcome from existingglobal standards, guidelines, frameworks, regulations, policies, etc.\n\n-  that illustrate potential ways to achieve each outcome\n\n-  that give actionable guidance on using the CSF and its onlineresources, including transitioning from previous CSF versions to version 2.0\n\n-  that help an organization putthe CSF into practice and set priorities for managing cybersecurity risks\n\n\nAn organization can use the CSF Core, Profiles, and Tiers with the supplementary resources to\nunderstand, assess, prioritize, and communicate cybersecurity risks.\n\n\n- • Understand and Assess: Describe the current or target cybersecurity posture of part or\nall of an organization, determine gaps, and assess progress toward addressing those\ngaps.\n\n-\n\n\n### Page 7\n\n- • Prioritize: Identify, organize, and prioritize actions for managing cybersecurity risks that\nalign with the organization’s mission, legal and regulatory requirements, and risk\nmanagement and governance expectations.\n\n- • Communicate: Provide a common language for communicating inside and outside the\norganization about cybersecurity risks, capabilities, needs, and expectations.\n\n\nThe CSF is designed to be used by organizations of all sizes and sectors, including industry,\ngovernment, academia, and nonprofit organizations, regardless of the maturity level of their\ncybersecurity programs. The CSF is a foundational resource that may be adopted voluntarily\nand through governmental policies and mandates. The CSF’s taxonomy and referenced\nstandards, guidelines, and practices are not country-specific, and previous versions of the CSF\nhave been leveraged successfully by many governments and other organizations both inside\nand outside of the United States.\n\n\nThe CSF should be used in conjunction with other resources (e.g., frameworks, standards,\nguidelines, leading practices) to better manage cybersecurity risks and inform the overall\nmanagement of information and communications technology (ICT) risks at an enterprise level.\nThe CSF is a flexible framework that is intended to be tailored for use by all organizations\nregardless of size. Organizations will continue to have unique risks — including different threats\nand vulnerabilities — and risk tolerances, as well as unique mission objectives and\nrequirements. Thus, organizations’ approaches to managing risks and their implementations of\nthe CSF will vary.\n\n\nThe remainder of this document is structured as follows:\n\n\n- • Section explains the basics of the CSF Core: Functions, Categories, and Subcategories.\n\n- • Section defines the concepts of CSF Profiles and Tiers.\n\n- • Section provides an overview of selected components of the CSF’s suite of online\nresources: Informative References, Implementation Examples, and Quick Start Guides.\n\n- • Section discusses how an organization can integrate the CSF with other risk\nmanagement programs.\n\n-  is the CSF Core.\n\n-  contains a notional illustration of the CSF Tiers.\n\n-  is a glossary of CSF terminology.\n\n\n### Page 8\n# 2. Introduction to the CSF Core\n\n\nis the CSF Core — a set of cybersecurity outcomes arranged by Function, then\nCategory, and finally Subcategory, as depicted in. These outcomes are not a checklist of\nactions to perform; specific actions taken to achieve an outcome will vary by organization and\nuse case, as will the individual responsible for those actions. Additionally, the order and size of\nFunctions, Categories, and Subcategories in the Core does not imply the sequence or\nimportance of achieving them. The structure of the Core is intended to resonate most with\nthose charged with operationalizing risk management within an organization.\n\n\nFig. 1. CSF Core structure\n\n\n![This figure depicts the CSF Core as a hierarchy of six Functions, each of which contains multiple Categories. Each of those Categories contains multiple Subcategories.\u0000]()\n\n\nThe CSF Core Functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER — organize\ncybersecurity outcomes at their highest level.\n\n\n- • GOVERN (GV) — The organization’s cybersecurity risk management strategy,\nexpectations, and policy are established, communicated, and monitored. The GOVERN\nFunction provides outcomes to inform what an organization may do to achieve and\nprioritize the outcomes of the other five Functions in the context of its mission and\nstakeholder expectations. Governance activities are critical for incorporating\ncybersecurity into an organization’s broader enterprise risk management (ERM)\nstrategy. GOVERN addresses an understanding of organizational context; the\nestablishment of cybersecurity strategy and cybersecurity supply chain risk\nmanagement; roles, responsibilities, and authorities; policy; and the oversight of\ncybersecurity strategy.\n\n- • IDENTIFY (ID) — The organization’s current cybersecurity risks are understood.Understanding the organization’s assets (e.g., data, hardware, software, systems,\nfacilities, services, people), suppliers, and related cybersecurity risks enables an\norganization to prioritize its efforts consistent with its risk management strategy and the\nmission needs identified under GOVERN. This Function also includes the identification of\n\n-\n\n-\n\n-\n\n-\n\n\n### Page 9\n\n-\n\n- improvement opportunities for the organization’s policies, plans, processes, procedures,\nand practices that support cybersecurity risk management to inform efforts under all six\nFunctions.\n\n- • PROTECT (PR) — Safeguards to manage the organization’s cybersecurity risks are used.Once assets and risks are identified and prioritized, PROTECT supports the ability to\nsecure those assets to prevent or lower the likelihood and impact of adverse\ncybersecurity events, as well as to increase the likelihood and impact of taking\nadvantage of opportunities. Outcomes covered by this Function include identity\nmanagement, authentication, and access control; awareness and training; data security;\nplatform security (i.e., securing thehardware, software, and services of physical and\nvirtual platforms); and the resilience of technology infrastructure.\n\n- • DETECT (DE) — Possible cybersecurity attacks and compromises are found and analyzed.DETECT enables the timely discovery and analysis of anomalies, indicators of\ncompromise, and other potentially adverse events that may indicate that cybersecurity\nattacks and incidents are occurring. This Function supports successful incident response\nand recovery activities.\n\n- • RESPOND (RS) — Actions regarding a detected cybersecurity incident are taken. RESPOND\nsupports the ability to contain the effects of cybersecurity incidents. Outcomes within\nthis Function cover incident management, analysis, mitigation, reporting, and\ncommunication.\n\n- • RECOVER (RC) — Assets and operations affected by a cybersecurity incident are restored.RECOVER supports the timely restoration of normal operations to reduce the effects of\ncybersecurity incidents and enable appropriate communication during recovery efforts.\n\n\nshows the CSF Functions as a wheel because all of the Functions relate to one another.\nFor example, an organization will categorize assets under IDENTIFY and take steps to secure\nthose assets under PROTECT. Investments in planning and testing in the GOVERN and IDENTIFY\nFunctions will support timely detection of unexpected events in the DETECT Function, as well as\nenabling incident response and recovery actions for cybersecurity incidents in the RESPOND and\nRECOVER Functions. GOVERN is in the center of the wheel because it informs how an organization\nwill implement the other five Functions.\n\n\nWhile many cybersecurity risk management activities focus on preventing negative eventsfrom occurring, they may also support taking advantage of positive opportunities. Actions toreduce cybersecurity risk might benefit an organization in other ways, like increasingrevenue (e.g., first offering excess facility space to a commercial hosting provider for hostingtheir own and other organizations’ data centers, then moving a major financial system fromthe organization’s in-house data center to the hosting provider to reduce cybersecurityrisks).\n\n\n### Page 10\n\nFig. 2. CSF Functions\n\n\n![This figure depicts the six Framework Functions as a wheel. The inner layer of the wheel contains only the Govern Function. The outer layer, which surrounds the Govern circle, contains the other five Functions.\u0000]()\n\n\nThe Functions should be addressed concurrently. Actions that support GOVERN, IDENTIFY, PROTECT,\nand DETECT should all happen continuously, and actions that support RESPOND and RECOVER\nshould be ready at all times and happen when cybersecurity incidents occur. All Functions have\nvital roles related to cybersecurity incidents. GOVERN, IDENTIFY, and PROTECT outcomes help\nprevent and prepare for incidents, while GOVERN, DETECT, RESPOND, and RECOVER outcomes help\ndiscover and manage incidents.\n\n\nEach Function is named after a verb that summarizes its contents. Each Function is divided intoCategories, which are related cybersecurity outcomes that collectively comprise the Function.Subcategories further divide each Category into more specific outcomes of technical and\nmanagement activities. The Subcategories are not exhaustive, but they describe detailed\noutcomes that support each Category.\n\n\nThe Functions, Categories, and Subcategories apply to all ICT used by an organization, including\ninformation technology (IT), the Internet of Things (IoT), and operational technology (OT). They\nalso apply to all types of technology environments, including cloud, mobile, and artificial\nintelligence systems. The CSF Core is forward-looking and intended to apply to future changes\nin technologies and environments.\n\n\n### Page 11\n# 3. Introduction to CSF Profiles and Tiers\n\n\nThis section defines the concepts of CSF Profiles and Tiers.\n\n## 3.1. CSF Profiles\n\n\nA CSF Organizational Profile describes an organization’s current and/or target cybersecurity\nposture in terms of the Core’s outcomes. are used to understand, tailor,assess, prioritize, and communicate the Core’s outcomes by considering an organization’s\nmission objectives, stakeholder expectations, threat landscape, and requirements. An\norganization can then prioritize its actions to achieve specific outcomes and communicate that\ninformation to stakeholders.\n\n\nEvery Organizational Profile includes one or both of the following:\n\n\n- 1. A Current Profile specifies the Core outcomes that an organization is currently achieving\n(or attempting to achieve) and characterizes how or to what extent each outcome is\nbeing achieved.\n\n- 2. A Target Profile specifies the desired outcomes that an organization has selected and\nprioritized for achieving its cybersecurity risk management objectives. A Target Profile\nconsiders anticipated changes to the organization’s cybersecurity posture, such as new\nrequirements, new technology adoption, and threat intelligence trends.\n\n\nA Community Profile is a baseline of CSF outcomes that is created and published to addressshared interests and goals among a number of organizations. A Community Profile istypically developed for a particular sector, subsector, technology, threat type, or other usecase. An organization can use a Community Profile as the basis for its own Target Profile.Examples of Community Profiles can be found on the.\n\n\n- The steps shown inand summarized below illustrate one way that an organization could\nuse an Organizational Profile to help inform continuous improvement of its cybersecurity.Fig. 3. Steps for creating and using a CSF Organizational Profile\n![This figure shows a five-step process for creating and using a CSF Organizational Profile. The same information is communicated in more detail immediately following the graphic.\u0000]()\n\n\n-\n\n-\n\n-\n\n-\n\n\n### Page 12\n\n-\n![This figure shows a five-step process for creating and using a CSF Organizational Profile. The same information is communicated in more detail immediately following the graphic.\u0000]()\n1. Scope the Organizational Profile. Document the high-level facts and assumptions on\nwhich the Profile will be based to define its scope. An organization can have as many\nOrganizational Profiles as desired, each with a different scope. For example, a Profile\ncould address an entire organization or be scoped to an organization’s financial systems\nor to countering ransomware threats and handling ransomware incidents involving\nthose financial systems.\n\n- 2. Gather the information needed to prepare the Organizational Profile. Examples of\ninformation may include organizational policies, risk management priorities and\nresources, enterprise risk profiles, business impact analysis (BIA) registers, cybersecurity\nrequirements and standards followed by the organization, practices and tools (e.g.,\nprocedures and safeguards), and work roles.\n\n- 3. Create the Organizational Profile. Determine what types of information the Profile\nshould include for the selected CSF outcomes, and document the needed information.\nConsider the risk implications of the Current Profile to inform Target Profile planning\nand prioritization. Also, consider using a Community Profile as the basis for the Target\nProfile.\n\n- 4. Analyze the gaps between the Current and Target Profiles, and create an action plan.Conduct a gap analysis to identify and analyze the differences between the Current and\nTarget Profiles, and develop a prioritized action plan (e.g., risk register, risk detail report,\nPlan of Action and Milestones [POA&M]) to address those gaps.\n\n- 5. Implement the action plan, and update the Organizational Profile. Follow the action\nplan to address the gaps and move the organization toward the Target Profile. An action\nplan may have an overall deadline or be ongoing.\n\n\nGiven the importance of continual improvement, an organization can repeat these steps as\noften as needed.\n\n\nThere are additional uses for Organizational Profiles. For example, a Current Profile can be used\nto document and communicate the organization’s cybersecurity capabilities and known\nopportunities for improvement with external stakeholders, such as business partners or\nprospective customers. Also, a Target Profile can help express the organization’s cybersecurity\nrisk management requirements and expectations to suppliers, partners, and other third parties\nas a target for those parties to achieve.\n\n## 3.2. CSF Tiers\n\n\nAn organization can choose to use the Tiers to inform its Current and Target Profiles. Tierscharacterize the rigor of an organization’s cybersecurity risk governance and management\npractices, and they provide context for how an organization views cybersecurity risks and the\nprocesses in place to manage those risks. The Tiers, as shown in and notionally illustrated\nin, reflect an organization’s practices for managing cybersecurity risk as Partial (Tier\n1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). The Tiers describe a\nprogression from informal, ad hoc responses to approaches that are agile, risk-informed, and\n\n\n### Page 13\n\ncontinuously improving. Selecting Tiers helps set the overall tone for how an organization will\nmanage its cybersecurity risks.\n\n\nFig. 4. CSF Tiers for cybersecurity risk governance and management\n\n\n![This figure depicts the four CSF Tiers as a set of columns, with Tier 1 being the shortest and Tier.4 being the tallest.\u0000]()\n\n\nTiers should complement an organization’s cybersecurity risk management methodology rather\nthan replace it. For example, an organization can use the Tiers to communicate internally as a\nbenchmark for an organization-wide\n\n1 For the purposes of this document, the terms “organization-wide” and “enterprise” have the same meaning.\n\napproach to managing cybersecurity risks. Progression to\nhigher Tiers is encouraged when risks or mandates are greater or when a cost-benefit analysis\nindicates a feasible and cost-effective reduction of negative cybersecurity risks.\n\n\nThe provides additional information on using Profiles and Tiers. It includespointers to and a repository of in a variety of machine-readable and human-usable formats.\n\n\n### Page 14\n# 4. Introduction to Online Resources That Supplement the CSF\n\n\nNIST and other organizations have produced a suite of online resources that help organizations\nunderstand, adopt, and use the CSF. Since they are hosted online, these additional resources\ncan be updated more frequently than this document, which is updated infrequently to provide\nstability to its users, and be available in machine-readable formats. This section provides an\noverview of three types of online resources: Informative References, Implementation Examples,\nand Quick Start Guides.\n\n\nare mappings that indicate relationships between the Core and variousstandards, guidelines, regulations, and other content. Informative References help inform how\nan organization may achieve the Core’s outcomes. Informative References can be sector- or\ntechnology-specific. They may be produced by NIST or another organization. Some Informative\nReferences are narrower in scope than a Subcategory. For example, a particular control from, Security and Privacy Controls for Information Systems and Organizations, may be one ofmany references needed to achieve the outcome described in one Subcategory. Other\nInformative References may be higher-level, such as a requirement from a policy that partially\naddresses numerous Subcategories. When using the CSF, an organization can identify the most\nrelevant Informative References.\n\n\nprovide notional examples of concise, action-oriented steps to helpachieve the outcomes of the Subcategories. Verbs used to express Examples include share,\ndocument, develop, perform, monitor, analyze, assess, and exercise. The Examples are not a\ncomprehensive list of all actions that could be taken by an organization to achieve an outcome,\nnor do they represent a baseline of required actions to address cybersecurity risks.\n\n\nare brief documents on specific CSF-related topics and are oftentailored to specific audiences. QSGs can help an organization implement the CSF because they\ndistill specific portions of the CSF into actionable “first steps” that an organization can consider\non the path to improving their cybersecurity posture and management of associated risks. The\nguides are revised in their own time frames, and new guides are added as needed.\n\n\nSuggestions for new Informative References for CSF 2.0 can always be shared with NIST at. Suggestions for other resources to reference on the NIST CSF website, includingadditional QSG topics, should be directed to.\n\n\n### Page 15\n# 5. Improving Cybersecurity Risk Communication and Integration\n\n\nThe CSF’s use will vary based on an organization’s unique mission and risks. With an\nunderstanding of stakeholder expectations and risk appetite and tolerance (as outlined in\nGOVERN), an organization can prioritize cybersecurity activities to make informed decisions\nabout cybersecurity expenditures and actions. An organization may choose to handle risk in one\nor more ways — including mitigating, transferring, avoiding, or accepting negative risks and\nrealizing, sharing, enhancing, or accepting positive risks — depending on the potential impacts\nand likelihoods. Importantly, an organization can use the CSF both internally to manage its\ncybersecurity capabilities and externally to oversee or communicate with third parties.\n\n\nRegardless of the CSF’s utilization, an organization may benefit from using the CSF as guidance\nto help it understand, assess, prioritize, and communicate cybersecurity risks and the actions\nthat will manage those risks. The selected outcomes can be used to focus on and implement\nstrategic decisions to improve cybersecurity postures and maintain continuity of mission-\nessential functions while taking priorities and available resources into account.\n\n## 5.1. Improving Risk Management Communication\n\n\nThe CSF provides a basis for improved communication regarding cybersecurity expectations,\nplanning, and resources. The CSF fosters bidirectional information flow (as shown in the top\nhalf of) between executives who focus on the organization’s priorities and strategic\ndirection and managers who manage specific cybersecurity risks that could affect the\nachievement of those priorities. The CSF also supports a similar flow (as shown in the bottom\nhalf of) between managers and the practitioners who implement and operate the\ntechnologies. The left side of the figure indicates the importance of practitioners sharing their\nupdates, insights, and concerns with managers and executives.\n\n\nFig. 5. Using the CSF to improve risk management communication\n\n\n![This figure depicts communication flows between executives and managers, and between managers and practitioners, as two loops.\u0000]()\n\n\n### Page 16\n\nPreparing to create and use Organizational Profiles involves gathering information about\norganizational priorities, resources, and risk direction from executives. Managers then\ncollaborate with practitioners to communicate business needs and create risk-informed\nOrganizational Profiles. Actions to close any gaps identified between the Current and Target\nProfiles will be implemented by managers and practitioners and will provide key inputs into\nsystem-level plans. As the target state is achieved throughout the organization — including\nthrough controls and monitoring applied at the system level — the updated results can be\nshared through risk registers and progress reports. As part of ongoing assessment, managers\ngain insights to make adjustments that further reduce potential harms and increase potential\nbenefits.\n\n\nThe GOVERN Function supports organizational risk communication with executives. Executives’\ndiscussions involve strategy, particularly how cybersecurity-related uncertainties might affect\nthe achievement of organizational objectives. These governance discussions support dialogue\nand agreement about risk management strategies (including cybersecurity supply chain risk);\nroles, responsibilities, and authorities; policies; and oversight. As executives establish\ncybersecurity priorities and objectives based on those needs, they communicate expectations\nabout risk appetite, accountability, and resources. Executives are also responsible for\nintegrating cybersecurity risk management with ERM programs and lower-level risk\nmanagement programs (see Sec.). The communications reflected in the top half of can\ninclude considerations for ERM and the lower-level programs and, thus, inform managers and\npractitioners.\n\n\nThe overall cybersecurity objectives set by executives are informed by and cascade tomanagers. In a commercial entity, these may apply to a line-of-business or operating division.\nFor government entities, these may be division- or branch-level considerations. When\nimplementing the CSF, managers will focus on how to achieve risk targets through common\nservices, controls, and collaboration, as expressed in the Target Profile and improved through\nthe actions being tracked in the action plan (e.g., risk register, risk detail report, POA&M).\n\n\nPractitioners focus on implementing the target state and measuring changes in operational risk\nto help plan, carry out, and monitor specific cybersecurity activities. As controls are\nimplemented to manage risk at an acceptable level, practitioners provide managers and\nexecutives with the information (e.g., key performance indicators, key risk indicators) they need\nto understand the organization’s cybersecurity posture, make informed decisions, and maintain\nor adjust the risk strategy accordingly. Executives can also combine this cybersecurity risk data\nwith information about other types of risk from across the organization. Updates to\nexpectations and priorities are included in updated Organizational Profiles as the cycle repeats.\n\n## 5.2. Improving Integration with Other Risk Management Programs\n\n\nEvery organization faces numerous types of ICT risk (e.g., privacy, supply chain, artificial\nintelligence) and may use frameworks and management tools that are specific to each risk.\nSome organizations integrate ICT and all other risk management efforts at a high level by using\nERM, while others keep the efforts separate to ensure adequate attention on each. Small\n\n\n### Page 17\n\norganizations by their nature may monitor risk at the enterprise level, while larger companies\nmay maintain separate risk management efforts integrated into the ERM.\n\n\nOrganizations can employ an ERM approach to balance a portfolio of risk considerations,\nincluding cybersecurity, and make informed decisions. Executives receive significant input\nabout current and planned risk activities as they integrate governance and risk strategies with\nresults from previous uses of the CSF. The CSF helps organizations to translate their\nterminology for cybersecurity and cybersecurity risk management into general risk\nmanagement language that executives will understand.\n\n\nNIST resources that describe the mutual relationship between cybersecurity risk management\nand ERM include:\n\n\n- • NIST Cybersecurity Framework 2.0 –\n\n- • NIST Interagency Report (IR) 8286,\n\n- • IR 8286A,\n\n- • IR 8286B,\n\n- • IR 8286C,\n\n- • IR 8286D,\n\n- • SP 800-221,\n\n- • SP 800-221A,\n\n\nAn organization may also find the CSF beneficial for integrating cybersecurity risk management\nwith individual ICT risk management programs, such as:\n\n\n- • Cybersecurity risk management and assessment: The CSF can be integrated with\nestablished cybersecurity risk management and assessment programs, such as, and from the NIST Risk ManagementFramework (RMF). For an organization using,the CSF can be used to complement the RMF’s approach to selecting and prioritizing\ncontrols from.\n\n- • Privacy risks: While cybersecurity and privacy are independent disciplines, their\nobjectives overlap in certain circumstances, as illustrated in.\n\n\n### Page 18\n\nFig. 6. Cybersecurity and privacy risk relationship\n\n\n![This figure is a Venn diagram showing the overlap between cybersecurity risks and privacy risks, with cybersecurity-related privacy events in the area of overlap.\u0000]()\n\n\nCybersecurity risk management is essential for addressing privacy risks related to the\nloss of the confidentiality, integrity, and availability of individuals’ data. For example,\ndata breaches could lead to identity theft. However, privacy risks can also arise by\nmeans that are unrelated to cybersecurity incidents.\n\n\nAn organization processes data to achieve mission or business purposes, which can\nsometimes give rise to privacy events whereby individuals may experience problems as\na result of the data processing. These problems can be expressed in various ways, but\nNIST describes them as ranging from dignity-type effects (e.g., embarrassment or\nstigma) to more tangible harms (e.g., discrimination, economic loss, or physical harm).\nThe and Cybersecurity Framework can be used together toaddress the different aspects of cybersecurity and privacy risks. Additionally, NIST’s has a catalog of example problems foruse in privacy risk assessments.\n\n\n- • Supply chain risks: An organization can use the CSF to foster cybersecurity risk oversight\nand communications with stakeholders across supply chains. All types of technology rely\non a complex, globally distributed, extensive, and interconnected supply chain\necosystem with geographically diverse routes and multiple levels of outsourcing. This\necosystem is composed of public- and private-sector entities (e.g., acquirers, suppliers,\ndevelopers, system integrators, external system service providers, and other\ntechnology-related service providers) that interact to research, develop, design,\nmanufacture, acquire, deliver, integrate, operate, maintain, dispose of, and otherwise\nutilize or manage technology products and services. These interactions are shaped and\ninfluenced by technologies, laws, policies, procedures, and practices.\n\n\nGiven the complex and interconnected relationships in this ecosystem, supply chain risk\nmanagement (SCRM) is critical for organizations. Cybersecurity SCRM (C-SCRM) is a\nsystematic process for managing exposure to cybersecurity risk throughout supply\nchains and developing appropriate response strategies, policies, processes, and\nprocedures. The Subcategories within the CSF C-SCRM Category [GV.SC] provide a\nconnection between outcomes that focus purely on cybersecurity and those that focus\n\n\n### Page 19\n\non C-SCRM. SP 800-161r1 (Revision 1),on C-SCRM. SP 800-161r1 (Revision 1),on C-SCRM. SP 800-161r1 (Revision 1),\n\n\n- • Risks from emerging technologies: As new technologies and new applications of\ntechnology become available, new risks become clear. A contemporary example is\nartificial intelligence (AI), which has cybersecurity and privacy risks, as well as many\nother types of risk. The was developed to help address these risks. Treating AI risks alongside otherenterprise risks (e.g., financial, cybersecurity, reputational, and privacy) will yield a more\nintegrated outcome and organizational efficiencies. Cybersecurity and privacy risk\nmanagement considerations and approaches are applicable to the design, development,\ndeployment, evaluation, and use of AI systems. The AI RMF Core uses Functions,\nCategories, and Subcategories to describe AI outcomes and help manage risks related to\nAI.\n\n\n### Page 20\n# Appendix A. CSF Core\n\n\nThis appendix describes the Functions, Categories, and Subcategories of the CSF Core.lists the CSF 2.0 Core Function and Category names and unique alphabetic identifiers. Each\nFunction name in the table is linked to its portion of the appendix. The order of Functions,\nCategories, and Subcategories of the Core is not alphabetical; it is intended to resonate most\nwith those charged with operationalizing risk management within an organization. The\nnumbering of the Subcategories is intentionally not sequential; gaps in numbering indicate CSF\n1.1 Subcategories that were relocated in CSF 2.0.\n\n\nTable 1. CSF 2.0 Core Function and Category names and identifiers\n\n| Function | Category | Category Identifier |\n| - | - | - |\n| Organizational Context | GV.OC |\n| Risk Management Strategy | GV.RM |\n| Roles, Responsibilities, and Authorities | GV.RR |\n| Policy | GV.PO |\n| Oversight | GV.OV |\n| Cybersecurity Supply Chain Risk Management | GV.SC |\n| Asset Management | ID.AM |\n| Risk Assessment | ID.RA |\n| Improvement | ID.IM |\n| Identity Management, Authentication, and Access Control | PR.AA |\n| Awareness and Training | PR.AT |\n| Data Security | PR.DS |\n| Platform Security | PR.PS |\n| Technology Infrastructure Resilience | PR.IR |\n| Continuous Monitoring | DE.CM |\n| Adverse Event Analysis | DE.AE |\n| Incident Management | RS.MA |\n| Incident Analysis | RS.AN |\n| Incident Response Reporting and Communication | RS.CO |\n| Incident Mitigation | RS.MI |\n| Incident Recovery Plan Execution | RC.RP |\n| Incident Recovery Communication | RC.CO |\n\nThe CSF Core, Informative References, and Implementation Examples are available on the and through the, which allows users to explore them andexport them in human- and machine-readable formats. The CSF 2.0 Core is also available in a similar to that of CSF 1.1.\n\n\n### Page 21\n\nGOVERN (GV): The organization’s cybersecurity risk management strategy, expectations, andpolicy are established, communicated, and monitored\n\n\n- • Organizational Context (GV.OC): The circumstances — mission, stakeholder expectations,\ndependencies, and legal, regulatory, and contractual requirements — surrounding the\norganization’s cybersecurity risk management decisions are understood\n- - o GV.OC-01: The organizational mission is understood and informs cybersecurity risk\nmanagement\n\n- - o GV.OC-02: Internal and external stakeholders are understood, and their needs and\nexpectations regarding cybersecurity risk management are understood and considered\n\n- - o GV.OC-03: Legal, regulatory, and contractual requirements regarding cybersecurity —\nincluding privacy and civil liberties obligations — are understood and managed\n\n- - o GV.OC-04: Critical objectives, capabilities, and services that external stakeholders\ndepend on or expect from the organization are understood and communicated\n\n- - o GV.OC-05: Outcomes, capabilities, and services that the organization depends on are\nunderstood and communicated\n\n\n- • Risk Management Strategy (GV.RM): The organization’s priorities, constraints, risktolerance and appetite statements, and assumptions are established, communicated, and\nused to support operational risk decisions\n- - o GV.RM-01: Risk management objectives are established and agreed to by organizational\nstakeholders\n\n- - o GV.RM-02: Risk appetite and risk tolerance statements are established, communicated,\nand maintained\n\n- - o GV.RM-03: Cybersecurity risk management activities and outcomes are included in\nenterprise risk management processes\n\n- - o GV.RM-04: Strategic direction that describes appropriate risk response options is\nestablished and communicated\n\n- - o GV.RM-05: Lines of communication across the organization are established for\ncybersecurity risks, including risks from suppliers and other third parties\n\n- - o GV.RM-06: A standardized method for calculating, documenting, categorizing, and\nprioritizing cybersecurity risks is established and communicated\n\n- - o GV.RM-07: Strategic opportunities (i.e., positive risks) are characterized and are\nincluded in organizational cybersecurity risk discussions\n\n\n### Page 22\n\n- • Roles, Responsibilities, and Authorities (GV.RR): Cybersecurity roles, responsibilities, andauthorities to foster accountability, performance assessment, and continuous improvement\nare established and communicated\n- - o GV.RR-01: Organizational leadership is responsible and accountable for cybersecurity\nrisk and fosters a culture that is risk-aware, ethical, and continually improving\n\n- - o GV.RR-02: Roles, responsibilities, and authorities related to cybersecurity risk\nmanagement are established, communicated, understood, and enforced\n\n- - o GV.RR-03: Adequate resources are allocated commensurate with the cybersecurity risk\nstrategy, roles, responsibilities, and policies\n\n- - o GV.RR-04: Cybersecurity is included in human resources practices\n\n\n- • Policy (GV.PO): Organizational cybersecurity policy is established, communicated, andenforced\n- - o GV.PO-01: Policy for managing cybersecurity risks is established based on organizational\ncontext, cybersecurity strategy, and priorities and is communicated and enforced\n\n- - o GV.PO-02: Policy for managing cybersecurity risks is reviewed, updated, communicated,\nand enforced to reflect changes in requirements, threats, technology, and\norganizational mission\n\n\n- • Oversight (GV.OV): Results of organization-wide cybersecurity risk management activitiesand performance are used to inform, improve, and adjust the risk management strategy\n- - o GV.OV-01: Cybersecurity risk management strategy outcomes are reviewed to inform\nand adjust strategy and direction\n\n- - o GV.OV-02: The cybersecurity risk management strategy is reviewed and adjusted to\nensure coverage of organizational requirements and risks\n\n- - o GV.OV-03: Organizational cybersecurity risk management performance is evaluated and\nreviewed for adjustments needed\n\n\n- • Cybersecurity Supply Chain Risk Management (GV.SC): Cyber supply chain riskmanagement processes are identified, established, managed, monitored, and improved by\norganizational stakeholders\n- - o GV.SC-01: A cybersecurity supply chain risk management program, strategy, objectives,\npolicies, and processes are established and agreed to by organizational stakeholders\n\n- - o GV.SC-02: Cybersecurity roles and responsibilities for suppliers, customers, and partners\nare established, communicated, and coordinated internally and externally\n\n- - o GV.SC-03: Cybersecurity supply chain risk management is integrated into cybersecurity\nand enterprise risk management, risk assessment, and improvement processes\n\n- - o GV.SC-04: Suppliers are known and prioritized by criticality\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n\n### Page 23\n\n-\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n- -\n\n- - o GV.SC-05: Requirements to address cybersecurity risks in supply chains are established,\nprioritized, and integrated into contracts and other types of agreements with suppliers\nand other relevant third parties\n\n- - o GV.SC-06: Planning and due diligence are performed to reduce risks before entering into\nformal supplier or other third-party relationships\n\n- - o GV.SC-07: The risks posed by a supplier, their products and services, and other third\nparties are understood, recorded, prioritized, assessed, responded to, and monitored\nover the course of the relationship\n\n- - o GV.SC-08: Relevant suppliers and other third parties are included in incident planning,\nresponse, and recovery activities\n\n- - o GV.SC-09: Supply chain security practices are integrated into cybersecurity and\nenterprise risk management programs, and their performance is monitored throughout\nthe technology product and service life cycle\n\n- - o GV.SC-10: Cybersecurity supply chain risk management plans include provisions for\nactivities that occur after the conclusion of a partnership or service agreement\n\n\nIDENTIFY (ID): The organization’s current cybersecurity risks are understood\n\n\n- • Asset Management (ID.AM): Assets (e.g., data, hardware, software, systems, facilities,\nservices, people) that enable the organization to achieve business purposes are identified\nand managed consistent with their relative importance to organizational objectives and the\norganization’s risk strategy\n- - o ID.AM-01: Inventories of hardware managed by the organization are maintained\n\n- - o ID.AM-02: Inventories of software, services, and systems managed by the organization\nare maintained\n\n- - o ID.AM-03: Representations of the organization’s authorized network communication\nand internal and external network data flows are maintained\n\n- - o ID.AM-04: Inventories of services provided by suppliers are maintained\n\n- - o ID.AM-05: Assets are prioritized based on classification, criticality, resources, and\nimpact on the mission\n\n- - o ID.AM-07: Inventories of data and corresponding metadata for designated data types\nare maintained\n\n- - o ID.AM-08: Systems, hardware, software, services, and data are managed throughout\ntheir life cycles\n\n\n- • Risk Assessment (ID.RA): The cybersecurity risk to the organization, assets, and individualsis understood by the organization\n- - o ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n- -\n\n- -\n\n\n### Page 24\n\n-\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- - o ID.RA-02: Cyber threat intelligence is received from information sharing forums and\nsources\n\n- - o ID.RA-03: Internal and external threats to the organization are identified and recorded\n\n- - o ID.RA-04: Potential impacts and likelihoods of threats exploiting vulnerabilities are\nidentified and recorded\n\n- - o ID.RA-05: Threats, vulnerabilities, likelihoods, and impacts are used to understand\ninherent risk and inform risk response prioritization\n\n- - o ID.RA-06: Risk responses are chosen, prioritized, planned, tracked, and communicated\n\n- - o ID.RA-07: Changes and exceptions are managed, assessed for risk impact, recorded, and\ntracked\n\n- - o ID.RA-08: Processes for receiving, analyzing, and responding to vulnerability disclosures\nare established\n\n- - o ID.RA-09: The authenticity and integrity of hardware and software are assessed prior to\nacquisition and use\n\n- - o ID.RA-10: Critical suppliers are assessed prior to acquisition\n\n\n- • Improvement (ID.IM): Improvements to organizational cybersecurity risk managementprocesses, procedures and activities are identified across all CSF Functions\n- - o ID.IM-01: Improvements are identified from evaluations\n\n- - o ID.IM-02: Improvements are identified from security tests and exercises, including those\ndone in coordination with suppliers and relevant third parties\n\n- - o ID.IM-03: Improvements are identified from execution of operational processes,\nprocedures, and activities\n\n- - o ID.IM-04: Incident response plans and other cybersecurity plans that affect operations\nare established, communicated, maintained, and improved\n\n\nPROTECT (PR): Safeguards to manage the organization’s cybersecurity risks are used\n\n\n- • Identity Management, Authentication, and Access Control (PR.AA): Access to physical and\nlogical assets is limited to authorized users, services, and hardware and managed\ncommensurate with the assessed risk of unauthorized access\n- - o PR.AA-01: Identities and credentials for authorized users, services, and hardware are\nmanaged by the organization\n\n- - o PR.AA-02: Identities are proofed and bound to credentials based on the context of\ninteractions\n\n- - o PR.AA-03: Users, services, and hardware are authenticated\n\n- - o PR.AA-04: Identity assertions are protected, conveyed, and verified\n\n- -\n\n\n-\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n- -\n\n\n### Page 25\n\n-\n- -\n\n- -\n\n- -\n\n- - o PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy,\nmanaged, enforced, and reviewed, and incorporate the principles of least privilege and\nseparation of duties\n\n- - o PR.AA-06: Physical access to assets is managed, monitored, and enforced\ncommensurate with risk\n\n\n- • Awareness and Training (PR.AT): The organization’s personnel are provided withcybersecurity awareness and training so that they can perform their cybersecurity-related\ntasks\n- - o PR.AT-01: Personnel are provided with awareness and training so that they possess the\nknowledge and skills to perform general tasks with cybersecurity risks in mind\n\n- - o PR.AT-02: Individuals in specialized roles are provided with awareness and training so\nthat they possess the knowledge and skills to perform relevant tasks with cybersecurity\nrisks in mind\n\n\n- • Data Security (PR.DS): Data are managed consistent with the organization’s risk strategy toprotect the confidentiality, integrity, and availability of information\n- - o PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected\n\n- - o PR.DS-02: The confidentiality, integrity, and availability of data-in-transit are protected\n\n- - o PR.DS-10: The confidentiality, integrity, and availability of data-in-use are protected\n\n- - o PR.DS-11: Backups of data are created, protected, maintained, and tested\n\n\n- • Platform Security (PR.PS): The hardware, software (e.g., firmware, operating systems,applications), and services of physical and virtual platforms are managed consistent with\nthe organization’s risk strategy to protect their confidentiality, integrity, and availability\n- - o PR.PS-01: Configuration management practices are established and applied\n\n- - o PR.PS-02: Software is maintained, replaced, and removed commensurate with risk\n\n- - o PR.PS-03: Hardware is maintained, replaced, and removed commensurate with risk\n\n- - o PR.PS-04: Log records are generated and made available for continuous monitoring\n\n- - o PR.PS-05: Installation and execution of unauthorized software are prevented\n\n- - o PR.PS-06: Secure software development practices are integrated, and their performance\nis monitored throughout the software development life cycle\n\n\n- • Technology Infrastructure Resilience (PR.IR): Security architectures are managed with theorganization’s risk strategy to protect asset confidentiality, integrity, and availability, and\norganizational resilience\n- - o PR.IR-01: Networks and environments are protected from unauthorized logical access\nand usage\n\n- -\n\n- -\n\n\n### Page 26\n\n-\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- - o PR.IR-02: The organization’s technology assets are protected from environmental\nthreats\n\n- - o PR.IR-03: Mechanisms are implemented to achieve resilience requirements in normal\nand adverse situations\n\n- - o PR.IR-04: Adequate resource capacity to ensure availability is maintained\n\n\nDETECT (DE): Possible cybersecurity attacks and compromises are found and analyzed\n\n\n- • Continuous Monitoring (DE.CM): Assets are monitored to find anomalies, indicators of\ncompromise, and other potentially adverse events\n- - o DE.CM-01: Networks and network services are monitored to find potentially adverse\nevents\n\n- - o DE.CM-02: The physical environment is monitored to find potentially adverse events\n\n- - o DE.CM-03: Personnel activity and technology usage are monitored to find potentially\nadverse events\n\n- - o DE.CM-06: External service provider activities and services are monitored to find\npotentially adverse events\n\n- - o DE.CM-09: Computing hardware and software, runtime environments, and their data\nare monitored to find potentially adverse events\n\n\n- • Adverse Event Analysis (DE.AE): Anomalies, indicators of compromise, and otherpotentially adverse events are analyzed to characterize the events and detect cybersecurity\nincidents\n- - o DE.AE-02: Potentially adverse events are analyzed to better understand associated\nactivities\n\n- - o DE.AE-03: Information is correlated from multiple sources\n\n- - o DE.AE-04: The estimated impact and scope of adverse events are understood\n\n- - o DE.AE-06: Information on adverse events is provided to authorized staff and tools\n\n- - o DE.AE-07: Cyber threat intelligence and other contextual information are integrated into\nthe analysis\n\n- - o DE.AE-08: Incidents are declared when adverse events meet the defined incident\ncriteria\n\n\n### Page 27\n\nRESPOND (RS): Actions regarding a detected cybersecurity incident are taken\n\n\n- • Incident Management (RS.MA): Responses to detected cybersecurity incidents are\nmanaged\n- - o RS.MA-01: The incident response plan is executed in coordination with relevant third\nparties once an incident is declared\n\n- - o RS.MA-02: Incident reports are triaged and validated\n\n- - o RS.MA-03: Incidents are categorized and prioritized\n\n- - o RS.MA-04: Incidents are escalated or elevated as needed\n\n- - o RS.MA-05: The criteria for initiating incident recovery are applied\n\n\n- • Incident Analysis (RS.AN): Investigations are conducted to ensure effective response andsupport forensics and recovery activities\n- - o RS.AN-03: Analysis is performed to establish what has taken place during an incident\nand the root cause of the incident\n\n- - o RS.AN-06: Actions performed during an investigation are recorded, and the records’\nintegrity and provenance are preserved\n\n- - o RS.AN-07: Incident data and metadata are collected, and their integrity and provenance\nare preserved\n\n- - o RS.AN-08: An incident’s magnitude is estimated and validated\n\n\n- • Incident Response Reporting and Communication (RS.CO): Response activities arecoordinated with internal and external stakeholders as required by laws, regulations, or\npolicies\n- - o RS.CO-02: Internal and external stakeholders are notified of incidents\n\n- - o RS.CO-03: Information is shared with designated internal and external stakeholders\n\n\n- • Incident Mitigation (RS.MI): Activities are performed to prevent expansion of an event andmitigate its effects\n- - o RS.MI-01: Incidents are contained\n\n- - o RS.MI-02: Incidents are eradicated\n\n\nRECOVER (RC): Assets and operations affected by a cybersecurity incident are restored\n\n\n- • Incident Recovery Plan Execution (RC.RP): Restoration activities are performed to ensure\noperational availability of systems and services affected by cybersecurity incidents\n- - o RC.RP-01: The recovery portion of the incident response plan is executed once initiated\nfrom the incident response process\n\n- -\n\n- -\n\n- -\n\n- -\n\n\n-\n- -\n\n- -\n\n\n### Page 28\n\n-\n- - o RC.RP-02: Recovery actions are selected, scoped, prioritized, and performed\n\n- - o RC.RP-03: The integrity of backups and other restoration assets is verified before using\nthem for restoration\n\n- - o RC.RP-04: Critical mission functions and cybersecurity risk management are considered\nto establish post-incident operational norms\n\n- - o RC.RP-05: The integrity of restored assets is verified, systems and services are restored,\nand normal operating status is confirmed\n\n- - o RC.RP-06: The end of incident recovery is declared based on criteria, and incident-\nrelated documentation is completed\n\n\n- • Incident Recovery Communication (RC.CO): Restoration activities are coordinated withinternal and external parties\n- - o RC.CO-03: Recovery activities and progress in restoring operational capabilities are\ncommunicated to designated internal and external stakeholders\n\n- - o RC.CO-04: Public updates on incident recovery are shared using approved methods and\nmessaging\n\n\n### Page 29\n# Appendix B. CSF Tiers\n\n\ncontains a notional illustration of the CSF Tiers discussed in Sec.. The Tiers\ncharacterize the rigor of an organization’s cybersecurity risk governance practices (GOVERN) and\ncybersecurity risk management practices (IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER).\n\n\nTable 2. Notional Illustration of the CSF Tiers\n\n| Tier | Cybersecurity Risk Governance | Cybersecurity Risk Management |\n| - | - | - |\n| Tier 1:\nPartial | Application of the organizational\ncybersecurity risk strategy is managed\nin an ad hoc manner.Prioritization is ad hoc and not\nformally based on objectives or threat\nenvironment. | There is limited awareness of cybersecurity risks at the\norganizational level.The organization implements cybersecurity risk\nmanagement on an irregular, case-by-case basis.The organization may not have processes that enable\ncybersecurity information to be shared within the\norganization.The organization is generally unaware of the\ncybersecurity risks associated with its suppliers and the\nproducts and services it acquires and uses. |\n| Tier 2: Risk\nInformed | Risk management practices are\napproved by management but may\nnot be established as organization-\nwide policy.The prioritization of cybersecurity\nactivities and protection needs is\ndirectly informed by organizational\nrisk objectives, the threat\nenvironment, or business/mission\nrequirements. | There is an awareness of cybersecurity risks at the\norganizational level, but an organization-wide approach\nto managing cybersecurity risks has not been\nestablished.Consideration of cybersecurity in organizational\nobjectives and programs may occur at some but not all\nlevels of the organization. Cyber risk assessment of\norganizational and external assets occurs but is not\ntypically repeatable or reoccurring.Cybersecurity information is shared within the\norganization on an informal basis.The organization is aware of the cybersecurity risks\nassociated with its suppliers and the products and\nservices it acquires and uses, but it does not act\nconsistently or formally in response to those risks. |\n| Tier 3:\nRepeatable | The organization’s risk management\npractices are formally approved and\nexpressed as policy.Risk-informed policies, processes, and\nprocedures are defined, implemented\nas intended, and reviewed.Organizational cybersecurity practices\nare regularly updated based on the\napplication of risk management\nprocesses to changes in\nbusiness/mission requirements,\nthreats, and technological landscape. | There is an organization-wide approach to managing\ncybersecurity risks. Cybersecurity information is\nroutinely shared throughout the organization.Consistent methods are in place to respond effectively\nto changes in risk. Personnel possess the knowledge and\nskills to perform their appointed roles and\nresponsibilities.The organization consistently and accurately monitors\nthe cybersecurity risks of assets. Senior cybersecurity\nand non-cybersecurity executives communicate\nregularly regarding cybersecurity risks. Executives\nensure that cybersecurity is considered through all lines\nof operation in the organization. |\n|  |\n|  |\n|  |\n\n\n### Page 30\n|  |\n| - |\n|  |\n|  |\n|  |\n| Tier | Cybersecurity Risk Governance | Cybersecurity Risk Management |\n| The organization risk strategy is informed by the\ncybersecurity risks associated with its suppliers and the\nproducts and services it acquires and uses. Personnel\nformally act upon those risks through mechanisms such\nas written agreements to communicate baseline\nrequirements, governance structures (e.g., risk councils),\nand policy implementation and monitoring. These\nactions are implemented consistently and as intended\nand are continuously monitored and reviewed. |\n| Tier 4:\nAdaptive | There is an organization-wide\napproach to managing cybersecurity\nrisks that uses risk-informed policies,\nprocesses, and procedures to address\npotential cybersecurity events. The\nrelationship between cybersecurity\nrisks and organizational objectives is\nclearly understood and considered\nwhen making decisions. Executives\nmonitor cybersecurity risks in the\nsame context as financial and other\norganizational risks. The organizational\nbudget is based on an understanding\nof the current and predicted risk\nenvironment and risk tolerance.\nBusiness units implement executive\nvision and analyze system-level risks in\nthe context of the organizational risk\ntolerances.Cybersecurity risk management is part\nof the organizational culture. It\nevolves from an awareness of previous\nactivities and continuous awareness of\nactivities on organizational systems\nand networks. The organization can\nquickly and efficiently account for\nchanges to business/mission\nobjectives in how risk is approached\nand communicated. | The organization adapts its cybersecurity practices\nbased on previous and current cybersecurity activities,\nincluding lessons learned and predictive indicators.\nThrough a process of continuous improvement that\nincorporates advanced cybersecurity technologies and\npractices, the organization actively adapts to a changing\ntechnological landscape and responds in a timely and\neffective manner to evolving, sophisticated threats.The organization uses real-time or near real-time\ninformation to understand and consistently act upon the\ncybersecurity risks associated with its suppliers and the\nproducts and services it acquires and uses.Cybersecurity information is constantly shared\nthroughout the organization and with authorized third\nparties. |\n\n\n### Page 31\n# Appendix C. Glossary\n\n\nCSF Category\n\n\nA group of related cybersecurity outcomes that collectively comprise a CSF Function.\n\n\nCSF Community Profile\n\n\nA baseline of CSF outcomes that is created and published to address shared interests and goals among a number of\norganizations. A Community Profile is typically developed for a particular sector, subsector, technology, threat\ntype, or other use case. An organization can use a Community Profile as the basis for its own Target Profile.\n\n\nCSF Core\n\n\nA taxonomy of high-level cybersecurity outcomes that can help any organization manage its cybersecurity risks. Its\ncomponents are a hierarchy of Functions, Categories, and Subcategories that detail each outcome.\n\n\nCSF Current Profile\n\n\nA part of an Organizational Profile that specifies the Core outcomes that an organization is currently achieving (or\nattempting to achieve) and characterizes how or to what extent each outcome is being achieved.\n\n\nCSF Function\n\n\nThe highest level of organization for cybersecurity outcomes. There are six CSF Functions: Govern, Identify,\nProtect, Detect, Respond, and Recover.\n\n\nCSF Implementation Example\n\n\nA concise, action-oriented, notional illustration of a way to help achieve a CSF Core outcome.\n\n\nCSF Informative Reference\n\n\nA mapping that indicates a relationship between a CSF Core outcome and an existing standard, guideline,\nregulation, or other content.\n\n\nCSF Organizational Profile\n\n\nA mechanism for describing an organization’s current and/or target cybersecurity posture in terms of the CSF\nCore’s outcomes.\n\n\nCSF Quick Start Guide\n\n\nA supplementary resource that gives brief, actionable guidance on specific CSF-related topics.\n\n\nCSF Subcategory\n\n\nA group of more specific outcomes of technical and management cybersecurity activities that comprise a CSF\nCategory.\n\n\nCSF Target Profile\n\n\nA part of an Organizational Profile that specifies the desired Core outcomes that an organization has selected and\nprioritized for achieving its cybersecurity risk management objectives.\n\n\nCSF Tier\n\n\nA characterization of the rigor of an organization’s cybersecurity risk governance and management practices.\nThere are four Tiers: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4).\n\n\n### Page 32\n\nCertain commercial equipment, instruments, software, or materials, commercial or non-commercial, are identified\nin this paper in order to specify the experimental procedure adequately. Such identification does not imply\nrecommendation or endorsement of any product or service by NIST, nor does it imply that the materials or\nequipment identified are necessarily the best available for the purpose.\n\n## NIST Technical Series Policies\n\n## How to Cite this NIST Technical Series Publication:\n\n\nNational Institute of Standards and Technology (2024) The NIST Cybersecurity Framework (CSF) 2.0. (National\nInstitute of Standards and Technology, Gaithersburg, MD), NIST Cybersecurity White Paper (CSWP) NIST CSWP 29.\nhttps://doi.org/10.6028/NIST.CSWP.29\n\n## Contact Information\n\n\nNational Institute of Standards and Technology\n\n\nAttn: Applied Cybersecurity Division, Information Technology Laboratory\n\n\n100 Bureau Drive (Mail Stop 2000) Gaithersburg, MD 20899-2000\n\n## All comments are subject to release under the Freedom of Information Act (FOIA)."
    }
  ],
  "limits": {
    "requestsPerMinutePerIp": 10,
    "documentsPerCall": 5,
    "maxMegabytesPerDocument": 10,
    "timeoutSeconds": 25
  }
}