NIST CSF
NIST Cybersecurity Framework 2.0
What it is
NIST CSF 2.0 expanded the original five-function framework (Identify, Protect, Detect, Respond, Recover) with a sixth function — Govern — reflecting the elevation of cybersecurity to board-level accountability. Widely adopted globally as a flexible framework adaptable to any organisation regardless of sector.
What it requires
Voluntary, organisation-agnostic framework. The six functions decompose into 22 categories and approximately 100 subcategories. Used as a mapping layer to translate between regulatory regimes — NIS 2, ISO 27001, CRA, sector-specific frameworks — and as a board-reportable maturity instrument.
Key facts
- Supervisor
- Voluntary framework — no direct supervisor; widely referenced in US federal contracting, insurance underwriting, and board-level governance
- Official text
- https://www.nist.gov/cyberframework
DSI services for NIST CSF
DSI Advisory Services helps covered entities translate NIST CSF obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.
See the service →Related briefings
On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.
The concluding piece in a series that began with a cable ship declaring force majeure and ended with a question nobody in power has answered. The answer has to exist before the warzone, not inside it.
Read more on this
Other industry standard frameworks in the DSI registry: