This is a potential security issue, you are being redirected to https://csrc.nist.gov.
You have JavaScript disabled. This site requires JavaScript to be enabled for complete site functionality.
Date Published: April 16, 2018
Planning Note (02/26/2024):
NIST has released The NIST Cybersecurity Framework (CSF) 2.0. See the CSF homepage, this blog post, and NIST news article for more details.
This publication describes a voluntary risk management framework ("the Framework") that consists of standards, guidelines, and best practices to manage cybersecurity-related risk. The Framework’s prioritized, flexible, and cost-effective approach helps to promote the protection and resilience of critical infrastructure and other sectors important to the economy and national security.
This release, Version 1.1, includes a number of updates from the original Version 1.0 (from February 2014), including: a new section on self-assessment; expanded explanation of using the Framework for cyber supply chain risk management purposes; refinements to better account for authentication, authorization, and identity proofing; explanation of the relationship between implementation tiers and profiles; and consideration of coordinated vulnerability disclosure. Complete information about the Framework is available at https://www.nist.gov/cyberframework.
This publication describes a voluntary risk management framework ("the Framework") that consists of standards, guidelines, and best practices to manage cybersecurity-related risk. The Framework’s prioritized, flexible, and cost-effective approach helps to promote the protection and resilience of critical infrastructure and other sectors important to the economy and national security.
This release, Version 1.1, includes a number of updates from the original Version 1.0 (from February 2014), including: a new section on self-assessment; expanded explanation of using the Framework for cyber supply chain risk management purposes; refinements to better account for authentication, authorization, and identity proofing; explanation of the relationship between implementation tiers and profiles; and consideration of coordinated vulnerability disclosure. Complete information about the Framework is available at https://www.nist.gov/cyberframework.
None selected
Publication:
https://doi.org/10.6028/NIST.CSWP.6
Download URL
Supplemental Material:
Press Release (04-16-2018)
Cybersecurity Framework homepage
Translations of the CSF 1.1
Related NIST Publications:
Document History:
01/10/17: Other (Draft)
12/05/17: Other (Draft)
04/16/18: CSWP 6 (Final)
audit & accountability, awareness training & education, contingency planning, maintenance, risk assessment, system authorization
Applications Laws and RegulationsComprehensive National Cybersecurity Initiative, Cybersecurity Enhancement Act, Executive Order 13636, Homeland Security Presidential Directive 7