The NIST Cybersecurity Framework is the most widely spoken language in cyber risk. It is not a control catalogue and not certifiable; it is an organizing structure, and its 2.0 revision (2024) made two moves that matter: it dropped the critical-infrastructure framing to address every organization, and it promoted governance to the centre of the model.
The six functions
CSF 2.0 arranges cybersecurity outcomes into six functions. Govern: the 2.0 addition, covering strategy, roles, policy, and oversight, on the argument that unowned security programs fail regardless of tooling. Identify: know your assets, risks, and dependencies. Protect: the controls that prevent bad outcomes. Detect: know when something is happening anyway. Respond: act on it. Recover: restore and learn. Each function breaks into categories and subcategories of outcomes, deliberately written as what, not how, with the how delegated to informative references like the CIS Controls and NIST’s own SP 800-53.
What it is good for
Three uses dominate in practice. Structure: organizing an inherited mess of tools and habits into functions exposes the gaps (organizations discover they have bought Protect three times and Detect never). Communication: profiles and tiers give boards and executives an honest, jargon-light way to see current versus target state, which is why assessments so often deliver findings on a CSF skeleton. And procurement: Canadian public-sector and enterprise RFPs reference CSF alignment often enough that consultancies serving them need fluency, even though “aligned to CSF” is inherently a self-claim, since nothing about the framework is auditable in the certification sense.
Why the security trades should care
The convergence pitch writes itself: physical security firms are increasingly asked where cameras, controllers, and monitoring infrastructure sit in a client’s cyber posture. CSF gives that conversation a respectable frame. Surveillance and access systems are assets to Identify, hardening them is Protect, their logs feed Detect, and an OT-flavoured deployment can lean on IEC 62443 for depth. A consultant who can place physical security systems inside the client’s existing CSF profile speaks the language the client’s CISO already reports in.
What trips people up
Mistaking the framework for a program: CSF names outcomes, and an organization still needs actual controls, which is what catalogue standards are for. Treating tiers as a maturity scorecard to chase rather than a communication device. And skipping Govern because it feels like paperwork, which is precisely the failure 2.0 was revised to call out.
How it fits
Use CSF to structure and communicate, CIS Controls to act, and ISO 27001 when someone needs certified proof. The three stack rather than compete.
Related guides
- CIS Controls v8.1: CIS Critical Security Controls
- ISO/IEC 27001: ISO/IEC 27001: Information Security Management
- IEC 62443 series: IEC 62443: Industrial and OT Security
References
Last updated 2026-07-24.