
From risk to resilience
A stronger, more secure and resilient organisation starts with a framework. The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, is the most widely adopted one — flexible enough for a 20-person startup and rigorous enough for a bank.
The basics
What is NIST? The National Institute of Standards and Technology is a U.S. government organisation that develops standards, guidelines, frameworks and best practices to help organisations improve technology, cybersecurity, privacy and risk management.
What is NIST CSF? A flexible framework that helps organisations manage and reduce cybersecurity risk. It provides a common language and structured approach to building organisational cyber resilience.
- Why was it created?
- Help organisations understand and manage cybersecurity risk
- Provide a common language across business and technical teams
- Prioritise security investments
- Improve detection, response and recovery capabilities
- Enhance resilience and build trust with customers and stakeholders
The six core functions of CSF 2.0
A continuous and adaptive approach to cybersecurity risk management:
- Govern — establish and monitor cybersecurity risk management. *New in 2.0*: it puts leadership accountability, roles, policy and oversight at the centre, recognising that cyber risk is a board-level business risk.
- Identify — understand assets, risks and the business environment
- Protect — implement safeguards to reduce cybersecurity risk
- Detect — identify and analyse potential cybersecurity events
- Respond — take action when a cybersecurity incident occurs
- Recover — restore affected capabilities and improve resilience
Who can use NIST CSF?
CSF is designed to be flexible — usable by organisations of all sizes across all industries: large enterprises, small and medium businesses, government bodies, financial organisations, healthcare, technology companies, cloud-based businesses and third-party supply-chain partners.
Benefits of using NIST CSF
- Structured cybersecurity risk management approach
- Identify and prioritise cybersecurity risks
- Improve security governance and oversight
- Strengthen security controls and capabilities
- Improve detection and response to cybersecurity events
- Communicate cybersecurity risk effectively to leadership
- Identify gaps between current and desired cybersecurity state
- Support continuous improvement and resilience
NIST CSF vs ISO/IEC 27001
| Aspect | NIST CSF | ISO/IEC 27001 |
|---|---|---|
| Nature | Cybersecurity risk management framework | Information Security Management System (ISMS) standard |
| Purpose | Helps manage and reduce cybersecurity risk | Defines requirements for establishing, implementing and maintaining an ISMS |
| Structure | Organised around 6 core functions (CSF 2.0) | Organised around ISMS requirements and Annex A controls |
| Flexibility | Flexible and adaptable to any organisation | Requirements-based and prescriptive |
| Certification | Not a certification standard | Certification is available |
| Focus | Focus on managing cybersecurity risk | Focus on establishing a formal ISMS |
| Best used for | Risk management, maturity assessment, gap analysis, alignment | ISMS implementation, compliance, continuous improvement |
Many organisations use both: CSF to assess and communicate maturity, ISO 27001 when customers or regulators demand a certificate. The controls overlap substantially, so work done on one feeds the other.
Key takeaway: NIST CSF is not just about controls — it is about building a culture of risk management, resilience and continuous improvement.
IcyberWave helps organisations assess against NIST CSF 2.0 and build the road from current state to target profile. See how CSF maps to certifiable controls in our [ISO 27001 audit checklist](/blog/iso-27001-audit-checklist), or [talk to us](/contact) about a CSF gap assessment.
