{"id":1160,"date":"2026-09-11T05:16:03","date_gmt":"2026-09-11T05:16:03","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1160"},"modified":"2026-09-11T05:16:03","modified_gmt":"2026-09-11T05:16:03","slug":"nist-csf","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/nist-csf\/","title":{"rendered":"NIST CSF"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: NIST CSF\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">NIST CSF is the framework nobody audits you against and everybody borrows from. Version 2.0 added a governance function and dropped the critical infrastructure framing, which is why it started appearing in questionnaires aimed at startups.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>NIST CSF is the Cybersecurity Framework published by the US National Institute of Standards and Technology. It organises security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is voluntary and there is no certificate. Its value is as a common vocabulary for describing a security programme and measuring where it currently sits against where you want it to be.<\/p>\n<\/div>\n\n<p>That absence of an audit is the point people miss. NIST CSF is a way of thinking about coverage, not a bar to clear.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#functions\">The six NIST CSF functions<\/a><\/li>\n    <li><a href=\"#govern\">What changed in version 2.0<\/a><\/li>\n    <li><a href=\"#tiers\">Tiers and profiles<\/a><\/li>\n    <li><a href=\"#iso\">NIST CSF and ISO 27001<\/a><\/li>\n    <li><a href=\"#asked\">Where NIST CSF gets asked for<\/a><\/li>\n    <li><a href=\"#osto\">How Osto maps to NIST CSF<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"functions\">The six NIST CSF functions<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 212\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The six NIST CSF functions with Govern surrounding Identify, Protect, Detect, Respond and Recover.\">\n  <rect x=\"12\" y=\"16\" width=\"736\" height=\"126\" rx=\"16\" fill=\"#e9ecfa\"\/>\n  <text x=\"40\" y=\"42\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">GOVERN<\/text>\n  <text x=\"112\" y=\"42\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#4a52a8\">sets the strategy, roles and risk appetite the other five operate under<\/text>\n\n  <rect x=\"28\" y=\"56\" width=\"136\" height=\"70\" rx=\"12\" fill=\"#1c267a\"\/>\n  <text x=\"96\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">Identify<\/text>\n  <text x=\"96\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">Know what you have<\/text>\n\n  <rect x=\"174\" y=\"56\" width=\"136\" height=\"70\" rx=\"12\" fill=\"#3f4796\"\/>\n  <text x=\"242\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">Protect<\/text>\n  <text x=\"242\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#c7cceb\">Reduce the chance<\/text>\n\n  <rect x=\"320\" y=\"56\" width=\"136\" height=\"70\" rx=\"12\" fill=\"#6b4576\"\/>\n  <text x=\"388\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">Detect<\/text>\n  <text x=\"388\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#e3cbe6\">See it happening<\/text>\n\n  <rect x=\"466\" y=\"56\" width=\"136\" height=\"70\" rx=\"12\" fill=\"#a2603a\"\/>\n  <text x=\"534\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">Respond<\/text>\n  <text x=\"534\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#f6ddc9\">Contain and act<\/text>\n\n  <rect x=\"612\" y=\"56\" width=\"120\" height=\"70\" rx=\"12\" fill=\"#3a6f5d\"\/>\n  <text x=\"672\" y=\"83\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">Recover<\/text>\n  <text x=\"672\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#c9e5d8\">Return to service<\/text>\n\n  <rect x=\"12\" y=\"154\" width=\"736\" height=\"44\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"380\" y=\"174\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Govern is not a sixth step in a sequence. It wraps the other five.<\/text>\n  <text x=\"380\" y=\"190\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3a6f5d\">Adding it in version 2.0 is what made the framework readable to a board rather than only to a security team.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Function<\/th><th>What it covers<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Govern<\/strong><\/td><td>Strategy, roles, policy, risk appetite and supply chain oversight, which is largely the territory of <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a><\/td><\/tr>\n    <tr><td><strong>Identify<\/strong><\/td><td>Asset inventory, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a> and understanding what you actually run<\/td><\/tr>\n    <tr><td><strong>Protect<\/strong><\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">Access control<\/a>, data security, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">endpoint protection<\/a>, awareness training and platform hardening<\/td><\/tr>\n    <tr><td><strong>Detect<\/strong><\/td><td>Monitoring, logging and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">correlation<\/a> across the estate<\/td><\/tr>\n    <tr><td><strong>Respond<\/strong><\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident response<\/a>, analysis, containment and communication<\/td><\/tr>\n    <tr><td><strong>Recover<\/strong><\/td><td>Restoration, recovery planning and the improvements that follow an incident<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"govern\" class=\"c-sage\">What changed in version 2.0<\/h2>\n\n<p>Version 2.0 was published in February 2024 and made two changes that matter to anyone outside the United States government supply chain.<\/p>\n\n<p>The first is Govern. Version 1.1 had five functions, all operational. Adding governance moved accountability, roles and risk appetite into the framework itself, which is what lets a security programme be described to a board rather than only to engineers.<\/p>\n\n<p>The second is scope. Version 1.1 was framed around critical infrastructure. Version 2.0 dropped that framing and is written for organisations of any size or sector, which is a large part of why NIST CSF now shows up in vendor questionnaires sent to small companies that have nothing to do with power grids.<\/p>\n\n<h2 id=\"tiers\" class=\"c-plum\">Tiers and profiles<\/h2>\n\n<p>The functions describe what to cover. Tiers and profiles are how you say where you are and where you are going.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Concept<\/th><th>What it means<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Tier 1, Partial<\/td><td>Ad hoc, reactive, little organisational awareness of risk<\/td><\/tr>\n    <tr><td>Tier 2, Risk Informed<\/td><td>Risk is understood but practice is inconsistent and rarely documented<\/td><\/tr>\n    <tr><td>Tier 3, Repeatable<\/td><td>Formal policy, consistently applied and updated as things change<\/td><\/tr>\n    <tr><td>Tier 4, Adaptive<\/td><td>Practice adjusts continuously from lessons learned and threat intelligence<\/td><\/tr>\n    <tr><td>Current Profile<\/td><td>An honest description of what you do today, function by function<\/td><\/tr>\n    <tr><td>Target Profile<\/td><td>Where you intend to be, given your risk and your budget<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Tier 4 is not the goal<\/p>\n  <p>Tiers are not maturity grades to climb. NIST is explicit that the appropriate tier depends on your risk, your resources and your obligations, and that a small company operating well at Tier 2 or 3 may be exactly where it should be. Treating Tier 4 as a target is how teams end up buying tooling they cannot staff.<\/p>\n<\/div>\n\n<h2 id=\"iso\" class=\"c-sky\">NIST CSF and ISO 27001<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th><\/th><th>NIST CSF<\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Type<\/td><td>Voluntary framework<\/td><td>Certifiable standard<\/td><\/tr>\n    <tr><td>Outcome<\/td><td>A profile and a gap picture<\/td><td>A certificate from an accredited body<\/td><\/tr>\n    <tr><td>Structure<\/td><td>Six functions with outcome statements<\/td><td>An <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> plus <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A controls<\/a><\/td><\/tr>\n    <tr><td>Best used for<\/td><td>Organising and communicating a programme<\/td><td>Proving one to a buyer or regulator<\/td><\/tr>\n    <tr><td>Cost to reach<\/td><td>Time only<\/td><td>Audit fees and an ongoing surveillance cycle<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>They are complements rather than alternatives. A common pattern is to use NIST CSF to structure the programme and decide sequencing, then certify against ISO 27001 or report under <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> when a buyer needs evidence they can file.<\/p>\n\n<h2 id=\"asked\">Where NIST CSF gets asked for<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Context<\/th><th>What is expected<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>US enterprise vendor review<\/td><td>A self-assessment against the functions, often inside a larger <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">security questionnaire<\/a><\/td><\/tr>\n    <tr><td>Cyber insurance<\/td><td>Underwriters use the functions as a structure for assessing controls, particularly Detect and Respond<\/td><\/tr>\n    <tr><td>Board and investor reporting<\/td><td>A profile is easier to present than a control list, which is what Govern was added for<\/td><\/tr>\n    <tr><td>Indian regulatory frameworks<\/td><td>SEBI CSCRF uses the same functional vocabulary of identify, protect, detect, respond and recover<\/td><\/tr>\n    <tr><td>Internal planning<\/td><td>The most common honest use: deciding what to fix next when everything looks urgent<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto maps to NIST CSF<\/h2>\n\n<p>The six functions correspond closely to how the platform is built. Identify covers asset and API discovery plus <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture<\/a>. Protect covers <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">access<\/a>, endpoint, web and data controls. Detect is <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM and correlation<\/a> across those modules. Respond and Recover attach to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a>. Govern is where the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> layer sits.<\/p>\n\n<p>Because the controls run in one stack, a current profile is something you can read rather than assemble. That matters most when NIST CSF is being used the way it was designed to be used, as a coverage picture, since a gap in Detect is usually a gap in what you can see rather than a missing document. The same control set maps to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/gdpr\/\">GDPR<\/a> and over 200 other frameworks at the same time.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">A profile you can read, not assemble<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Identify, protect, detect, respond and recover running as live controls in one stack, mapped to SOC 2, ISO 27001 and 200+ frameworks from the same evidence base. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Coverage across all six functions &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is NIST CSF?<\/summary>\n  <p>The Cybersecurity Framework from the US National Institute of Standards and Technology. It organises security into six functions, Govern, Identify, Protect, Detect, Respond and Recover, and provides tiers and profiles for describing current and target state. It is voluntary.<\/p>\n<\/details>\n\n<details>\n  <summary>Can you get certified against NIST CSF?<\/summary>\n  <p>No. There is no certification scheme and no accredited body issuing NIST CSF certificates. Organisations self-assess, or engage an assessor for an independent view. When a buyer wants a certificate, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> or <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> is the answer.<\/p>\n<\/details>\n\n<details>\n  <summary>What changed in NIST CSF 2.0?<\/summary>\n  <p>Published in February 2024, it added Govern as a sixth function covering strategy, roles, risk appetite and supply chain, and removed the critical infrastructure framing so the framework applies to organisations of any size or sector.<\/p>\n<\/details>\n\n<details>\n  <summary>Should we use NIST CSF or ISO 27001?<\/summary>\n  <p>Usually both, for different jobs. NIST CSF structures the programme and shows where the gaps are. ISO 27001 produces a certificate a buyer or regulator can accept. Using the framework to plan and the standard to prove is the common sequence.<\/p>\n<\/details>\n\n<details>\n  <summary>Is NIST CSF relevant outside the United States?<\/summary>\n  <p>Yes. Version 2.0 is written for any organisation, and the functional vocabulary appears in insurance assessments, enterprise questionnaires and regulatory frameworks including SEBI CSCRF in India.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/gdpr\/\">GDPR<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>NIST CSF is the framework nobody audits you against and everybody borrows from. Version 2.0 added a governance function and\u2026<\/p>\n","protected":false},"author":8,"featured_media":1161,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[563,565,566,300,564],"class_list":["post-1160","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-nist-csf","tag-nist-csf-2-0","tag-nist-csf-functions","tag-nist-csf-vs-iso-27001","tag-nist-cybersecurity-framework"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1160","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1160"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1160\/revisions"}],"predecessor-version":[{"id":1162,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1160\/revisions\/1162"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1161"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}