Question
What is the NIST Cybersecurity Framework (CSF), and why has it become so influential?
Answer
The NIST CSF is a voluntary, risk-based framework for managing cybersecurity risk, built around outcomes rather than prescriptive controls — and it's free.

* Das NIST-CSF-2.0-Funktionsrad — die fünf klassischen Funktionen plus die 2024 ergänzte Funktion „Govern" im Zentrum. — NIST, Public domain, via Wikimedia Commons. *
NIST (the US National Institute of Standards and Technology) published the framework in 2014, originally to help critical infrastructure operators after US Executive Order 13636. It spread far beyond that audience because of three properties:
- Outcome-oriented: it describes what you should achieve ("anomalies are detected"), not how — so any organization, sector, or size can map its own controls to it
- Common language: executives, engineers, and auditors can all discuss security posture using the same five functions
- Free and vendor-neutral: unlike ISO 27001, no license fees and no certification machinery required
Many national adaptations are built directly on it — including the Swiss IKT Minimalstandard.
Tip: Don't confuse the NIST CSF with NIST SP 800-53 — the latter is a detailed control catalog; the CSF is a high-level framework that points to 800-53 (and ISO 27001, COBIT…) as references.
Go deeper:
NIST Cybersecurity Framework (offizielle Seite) — Die offizielle NIST-Quelle: kostenloser Rahmen, Quick-Start-Guides und das CSF-2.0-Tool.
NIST Cybersecurity Framework (Wikipedia) — Überblick zu Entstehung, Verbreitung und CSF vs. SP 800-53.
Note saved — thanks!
Question
What are the three components of the NIST Cybersecurity Framework?
Answer
Core, Implementation Tiers, and Profiles.
* The three CSF components — Core is the menu, Profiles are your order, Tiers rate how disciplined the practice is. *
| Component | What it is | Question it answers |
|---|---|---|
| Core | Hierarchy of functions, categories, subcategories + references | What security outcomes exist? |
| Implementation Tiers | 4-level scale describing how rigorously you manage risk | How mature is our risk practice? |
| Profiles | Your selection/prioritization of Core outcomes | Which outcomes matter to us, now vs. target? |
The three play together: the Core is the menu, the Profile is your order from that menu, and the Tier describes how disciplined your kitchen is.
Tip: Remember C-T-P: "Choose The Priorities" — Core lists everything, Tiers rate you, Profiles pick what applies.
Note saved — thanks!