Skip to content

NIST Cybersecurity Framework

What is NIST Cybersecurity Framework?

A voluntary framework published by the National Institute of Standards and Technology that provides a common language for understanding, managing, and expressing cybersecurity risk. The current version (CSF 2.0) includes six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

Compliance

Each of these is named in at least one of the same controls as nist cybersecurity framework. The number is how many controls name both.

What the standards actually require on nist cybersecurity framework

Requirements naming nist cybersecurity framework across 6 standards, quoted from the control text.

Incidents are contained. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

NIST-CSF-RS.MI-01 · Incidents are contained

Within the period specified by the Rules, the responsible entity must adopt and maintain compliance with one of the recognised cyber security frameworks for the cyber and information security hazard, such as the ACSC Essential Eight (Maturity Level One), ISO/I...

CIRMP-s8-FW · Adoption of a recognised cyber security framework
HITECH Act1 control

HITECH crosswalk to verified subordinate substantive rules + adjacent frameworks. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - primary substantive privacy controls;

HITECH-Crosswalk-HIPAA-NIST-CSF-405d-Sectoral · HITECH Crosswalk to HIPAA Privacy + Security + Breach Notification Rules + NIST CSF + HHS 405d + State Laws

HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains;

HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBER · HKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks
HKMA SPM1 control

HKMA SPM crosswalk to international + sectoral standards. (a) BASEL III - BCBS Basel III capital (Pillar 1/2/3) + liquidity (LCR + NSFR) + leverage + IRRBB + FRTB + SMA operational risk + IRB + standardised approaches;

HKMA-SPM-Crosswalk-Basel-FATF-FSB-Sectoral · HKMA SPM Crosswalk to Basel III, FATF, FSB Operational Resilience, IOSCO and Sectoral Frameworks

Questions people ask about nist cybersecurity framework

What is NIST Cybersecurity Framework?
A voluntary framework published by the National Institute of Standards and Technology that provides a common language for understanding, managing, and expressing cybersecurity risk. The current version (CSF 2.0) includes six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
Why is NIST Cybersecurity Framework important for compliance?
NIST Cybersecurity Framework is a key concept in Compliance. Understanding nist cybersecurity framework helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address NIST Cybersecurity Framework?
NIST Cybersecurity Framework appears in the requirement text of NIST Cybersecurity Framework 2.0, IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), Critical Infrastructure Risk Management Program (CIRMP) Rules 2023, HITECH Act, HKMA Cyber Resilience Assessment Framework (C-RAF). Across these standards we have identified 40 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about NIST Cybersecurity Framework?
Explore our compliance framework pages to see how nist cybersecurity framework applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how NIST Cybersecurity Framework applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.