This is a potential security issue, you are being redirected to https://csrc.nist.gov.
You have JavaScript disabled. This site requires JavaScript to be enabled for complete site functionality.
Date Published: February 26, 2024
Planning Note (09/24/2024):
Now available: a new spreadsheet, CSF 1.1 to 2.0 Core Transition Changes Overview. See other links to CSF 2.0 resources on this page. Send inquiries about this publication to [email protected].
The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes. This document describes CSF 2.0, its components, and some of the many ways that it can be used.
The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts. The CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes. This document describes CSF 2.0, its components, and some of the many ways that it can be used.
None selected
Publication:
https://doi.org/10.6028/NIST.CSWP.29
Download URL
Supplemental Material:
NIST news article
Blog post
NIST CSF Website
CSF 2.0 Quick-Start Guides
CSF 2.0 Reference Tool
CSF 2.0 Dataset on CPRT
CSF 1.1 to 2.0 Core Transition Changes Overview
Translations
Related NIST Publications:
Document History:
08/08/23: CSWP 29 (Draft)
02/26/24: CSWP 29 (Final)
cybersecurity supply chain risk management, privacy, risk management, security programs & operations
Applicationscybersecurity framework, enterprise, small & medium business