LOGBOOK

HELP

1 / 27
Other keys: showSpace: good1-4: rate0: skip5: flag

Question

What is the NIST Cybersecurity Framework (CSF), and why has it become so influential?

Answer

The NIST CSF is a voluntary, risk-based framework for managing cybersecurity risk, built around outcomes rather than prescriptive controls — and it's free.

Kreisdiagramm der sechs NIST-CSF-2.0-Funktionen Govern, Identify, Protect, Detect, Respond, Recover.

* Das NIST-CSF-2.0-Funktionsrad — die fünf klassischen Funktionen plus die 2024 ergänzte Funktion „Govern" im Zentrum. — NIST, Public domain, via Wikimedia Commons. *

NIST (the US National Institute of Standards and Technology) published the framework in 2014, originally to help critical infrastructure operators after US Executive Order 13636. It spread far beyond that audience because of three properties:

  • Outcome-oriented: it describes what you should achieve ("anomalies are detected"), not how — so any organization, sector, or size can map its own controls to it
  • Common language: executives, engineers, and auditors can all discuss security posture using the same five functions
  • Free and vendor-neutral: unlike ISO 27001, no license fees and no certification machinery required

Many national adaptations are built directly on it — including the Swiss IKT Minimalstandard.

Tip: Don't confuse the NIST CSF with NIST SP 800-53 — the latter is a detailed control catalog; the CSF is a high-level framework that points to 800-53 (and ISO 27001, COBIT…) as references.

Go deeper:

or press any other key

Question

What are the three components of the NIST Cybersecurity Framework?

Answer

Core, Implementation Tiers, and Profiles.

NIST CSF centre with three spokes: Core, Implementation Tiers, Profiles.

* The three CSF components — Core is the menu, Profiles are your order, Tiers rate how disciplined the practice is. *

Component What it is Question it answers
Core Hierarchy of functions, categories, subcategories + references What security outcomes exist?
Implementation Tiers 4-level scale describing how rigorously you manage risk How mature is our risk practice?
Profiles Your selection/prioritization of Core outcomes Which outcomes matter to us, now vs. target?

The three play together: the Core is the menu, the Profile is your order from that menu, and the Tier describes how disciplined your kitchen is.

Tip: Remember C-T-P: "Choose The Priorities" — Core lists everything, Tiers rate you, Profiles pick what applies.

or press any other key