The NIST Cybersecurity Framework is a flexible, risk-based approach to managing cybersecurity risk developed by the U.S. National Institute of Standards and Technology. It provides a structured methodology organisations can use to manage and reduce cybersecurity risks.
Since CSF 2.0 the framework consists of six core functions: Govern (set and oversee the cybersecurity strategy), Identify (understand your assets and risks), Protect (implement safeguards), Detect (identify cybersecurity events), Respond (take action on incidents), and Recover (restore capabilities). Organisations map these functions to their specific context and maturity level, making it applicable across industries and organisation sizes.