Frameworks

NIST CSF 2.0: the six functions and what Govern changed

· 3 min read · Futture.ai

The NIST Cybersecurity Framework was born in 2014 aimed at United States critical infrastructure. Version 2.0 dropped that framing: it now addresses organisations of any size and sector, and it added an entirely new function at the top of the structure.

The six functions

The five original functions remain, with a sixth that now cuts across them:

  • Govern — the addition in 2.0. Establishes the cybersecurity risk management strategy, expectations and policy: roles and responsibilities, risk appetite, oversight, supply chain risk management.
  • Identify — understand context, assets and risks.
  • Protect — safeguards to limit or contain impact.
  • Detect — find and analyse events and compromises.
  • Respond — act on a detected incident.
  • Recover — restore affected operations.

Why Govern matters more than it looks

Before 2.0, the framework described activities without saying who was accountable for them. In practice that produced assessments where an organisation scored well on Protect and Detect — because it bought tooling — and could not explain who decides what risk is acceptable.

Govern puts that question at the centre. It covers defining risk appetite, formally assigning accountability, integrating cybersecurity into enterprise risk management and — the item that exposes the most gaps — third-party risk management.

Tiers and Profiles: where most people go wrong

Two CSF constructs are frequently misused:

Tiers (from Partial to Adaptive) describe the rigour of risk management practice, not a maturity score. Tier 4 is not everybody's target. A small organisation operating well at Tier 2 may be better matched to its risk than one that forced Tier 4 processes nobody follows.

Profiles are the genuinely useful instrument: you describe the current profile, describe the target profile in light of your business, and the distance between the two becomes the action plan — with priority and cost attached. This is where the CSF stops being vocabulary and becomes management.

NIST CSF or ISO 27001?

The question is badly framed, because the two do different things.

NIST CSF 2.0ISO/IEC 27001
NatureVoluntary frameworkCertifiable standard
FocusCybersecurity outcomesManagement system
CertificationDoes not existBy an accredited body
Best forDiagnosing, prioritising, talking to the boardProving it formally to third parties

Using both together is common and productive: the CSF organises the assessment and the board conversation — the six functions are intuitive to non-technical audiences — while ISO 27001 provides the auditable structure and the certificate customers ask for in contracts. Annex A controls map well onto CSF subcategories, and much of the evidence serves both.

Applying it outside the United States

The CSF carries no legal weight outside its home jurisdiction, but it has practical value in three situations: when an organisation has to present its security posture to a foreign parent company or investor; when it needs a common language across security, enterprise risk and the board; and when local regulatory requirements need organising into a structure that is more than a list of obligations.

In that last case, mapping regulatory requirements onto the six functions usually reveals quickly that effort is concentrated in Protect, and that Govern and Recover are the areas with the least available evidence.

Read next

← Back to the blog