Govern, Identify, Protect, Detect, Respond, Recover.
April 28, 2026
The NIST Cybersecurity Framework is the most widely used way to describe the shape of a security program. Version 1.0 arrived in 2014 for critical infrastructure. Version 2.0 was published in February 2024 and broadened it to organizations of every size and sector.
It is free, voluntary, and deliberately not a checklist. It is a way to organize and talk about security work.
Govern, which is new in 2.0. Establishing and monitoring the strategy, expectations, and policy, including roles, risk appetite, supply chain, and oversight.
Identify. Understanding the organization, its assets, its data, and its risks.
Protect. The safeguards: identity and access, awareness training, data security, platform security, and resilience.
Detect. Finding that something is happening. This is monitoring and analysis.
Respond. Acting on it: incident management, analysis, reporting, and mitigation.
Recover. Restoring what was affected and communicating during recovery.
The most important change in 2.0 is the addition of Govern as a function that wraps the other five rather than sitting beside them.
The reason is that the framework was consistently being used as a technical checklist while the actual failures were organizational: no clear ownership, no stated risk appetite, no board oversight, and no supply chain management.
Govern makes those explicit and reviewable, and it includes cyber supply chain risk management, which pulls third party risk into the core of the framework rather than leaving it as an afterthought.
Tiers describe how rigorous and integrated your risk management practices are, running from Partial through Risk Informed and Repeatable to Adaptive.
Tiers are not maturity levels and they are not a score to maximize. A small business operating sensibly at a lower tier is not failing.
Profiles are the more useful tool. A Current Profile describes where you are. A Target Profile describes where you intend to be. The gap between them, prioritized, is your roadmap.
NIST and various sectors also publish Community Profiles, which are pre-built target profiles for specific industries or problems. Starting from one saves a great deal of work.
The CIS Controls tell you what to do, in order, with specific safeguards. CSF tells you how to organize, assess, and communicate the program.
They are complementary rather than competing. A very common and sensible arrangement is to use CSF as the structure for reporting to leadership and CIS Controls as the implementation detail underneath.
NIST publishes informative references mapping CSF to other standards including CIS, ISO 27001, and NIST SP 800-53, which is what makes running one program against several standards practical.
Assess honestly at the subcategory level, and resist the urge to grade generously. A current profile that says you are good at everything is not a starting point for anything.
Pick a small number of gaps that matter, with owners and dates. A roadmap with forty priorities has none.
Report to leadership using the six functions, because they are intuitive to non technical people in a way that control numbers are not. Most executives can follow a conversation about whether we would detect this and whether we could recover.
Re-assess annually and show the trend. Movement matters more than the absolute position.
Treating it as a compliance checklist and generating documents that describe an imaginary program. CSF is not certifiable and nobody is auditing you against it directly.
Assessing everything at once, in enormous workshops, producing a spreadsheet nobody looks at again.
Ignoring Govern because it is the least technical function, which is the exact reason it was added.
And confusing the framework with the work. A mature profile with no asset inventory underneath it is a description of a program rather than a program.
Week 5 of the mentorship maps the framework landscape so you can tell which document answers which question, instead of learning them all at once.