Skip to content

CSF 2.0 Informative References

This book contains the NIST CSF 2.0 core: six Functions, their Categories, Subcategories, Implementation Examples, and Informative References (crosswalks to ISO/IEC 27001, NIST SP 800-53, PCI DSS, CIS Controls, and other frameworks).

Each Function below is its own page/chapter — paste each NN-*.md file into its own Bookstack page.

Function Categories Subcategories Description
GOVERN (GV) 6 31 The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored
IDENTIFY (ID) 7 39 The organization's current cybersecurity risks are understood
PROTECT (PR) 9 57 Safeguards to manage the organization's cybersecurity risks are used
DETECT (DE) 3 22 Possible cybersecurity attacks and compromises are found and analyzed
RESPOND (RS) 6 24 Actions regarding a detected cybersecurity incident are taken
RECOVER (RC) 3 12 Assets and operations affected by a cybersecurity incident are restored