Terminology Index

Glossary

2953 terms

Open concept maps
M
25
N
7

NIST CSF Structure

The high-level structure of the NIST Cybersecurity Framework, organized around core functions (Govern, Identify, Protect, Detect, Respond, Recover), categories, and subcategories, with profiles and tiers for risk-based management.

The NIST Cybersecurity Framework is structured around core functions that organize outcomes (Govern, Identify, Protect, Detect, Respond, Recover), each broken into categories and subcategories of specific outcomes. Implementation profiles tailor the framework to an organization's risks and goals, and tiers describe how rigorous risk-management practice is. Understanding the structure is foundational to using the CSF as a flexible, risk-based scaffold rather than a checklist.

Introduced in: Security Frameworks and Control Mapping

Examples

  • Organizing security activities under the CSF's six core functions.
  • Using CSF subcategories to specify outcomes the organization will achieve.
  • Tailoring a CSF profile to the organization's risk priorities.