NIST Cybersecurity Framework Security Controls

Version 2.0

The NIST Cybersecurity Framework 2.0 provides guidance for organizations to manage and reduce cybersecurity risk. It is organized around six core functions (Govern, Identify, Protect, Detect, Respond, and Recover) that apply to any organization regardless of size, sector, or maturity.

113

Total controls

29

Critical priority

514h

Est. implementation

6

Trust service categories

Public domain, published by the U.S. National Institute of Standards and Technology

Govern

31 controls

Establish and monitor the organization's cybersecurity risk management strategy, expectations, and policy.

Risk Management Strategy

Cybersecurity Supply Chain Risk Management

Identify

21 controls

Understand the organization's assets, suppliers, and related cybersecurity risks.

Risk Assessment

Protect

22 controls

Use safeguards to prevent or reduce cybersecurity risks.

Detect

17 controls

Find and analyze possible cybersecurity attacks and compromises.

Continuous Monitoring

Respond

14 controls

Take action regarding a detected cybersecurity incident.

Recover

8 controls

Restore assets and operations that were impacted by a cybersecurity incident.