What is the NIST Cybersecurity Framework?

D1 ยท General  ยท  CompTIA Security+ SY0-701
The NIST Cybersecurity Framework (CSF) is a voluntary framework developed by the National Institute of Standards and Technology that provides a common language and systematic approach to managing cybersecurity risk.

The framework core has 5 functions: Identify โ†’ Protect โ†’ Detect โ†’ Respond โ†’ Recover.

CSF 2.0 (2024) added a 6th function: Govern.
Know the 5 (or 6) NIST CSF functions in order: Identify, Protect, Detect, Respond, Recover (+ Govern in v2.0). The framework is voluntary but widely adopted. NIST SP 800-53 provides detailed security controls that align with the CSF.
โ† Back to Glossary Practice Questions โ†’