Developed by the National Institute of Standards and Technology, the NIST CSF gives organizations a common structure for understanding cybersecurity risk, assessing where they stand and deciding what to improve next. It can be used by organizations of any size, industry or level of cybersecurity maturity. And importantly, NIST doesn’t prescribe a specific technology stack or tell organizations exactly how they must achieve each outcome.
That flexibility is one of the framework’s greatest strengths, but it can also leave IT and security leaders wondering where to begin.
Here’s what you need to know.
What Is the NIST Cybersecurity Framework?
At its core, NIST CSF is a risk management framework.
Rather than starting with products or individual security controls, it helps organizations answer broader questions:
- What cybersecurity risks matter most to our organization?
- How well are we managing those risks today?
- Where are our biggest gaps?
- What should we prioritize?
- How do we communicate cybersecurity risk to business leadership?
NIST released CSF 2.0 in February 2024, expanding the framework’s applicability beyond its original focus on critical infrastructure. The updated framework is intended for organizations across industries, regardless of size or cybersecurity sophistication.
The framework organizes cybersecurity outcomes into six core Functions: Govern. Identify. Protect. Detect. Respond. Recover. Together, they provide a structure for looking at cybersecurity across the organization rather than treating security as a collection of individual tools or projects.
The Six NIST Functions, Explained
1. Govern: How Are We Managing Cybersecurity Risk?
Govern was added as a distinct Function in CSF 2.0 and reflects a significant shift in how organizations should think about cybersecurity: security isn’t solely an IT responsibility. It is an organizational risk issue.
Govern addresses areas such as cybersecurity strategy, policies, roles and responsibilities, oversight and supply chain risk.
In practice, this means asking questions like: Who owns cybersecurity risk? How are security priorities established? Does leadership understand and participate in cybersecurity decisions? How are third-party and supply chain risks managed?
Govern creates the foundation for everything else in the framework.
2. Identify: What Do We Have, and What Could Put It at Risk?
You can’t protect what you don’t know exists.
Identify focuses on understanding the organization’s assets, systems, data, services, dependencies and cybersecurity risks.
That includes asset inventories, risk assessments, vulnerability identification and understanding the business impact if critical resources become unavailable or compromised.
For many organizations, this is where meaningful gaps first become visible. Unknown assets, unmanaged cloud resources, legacy infrastructure and unclear data ownership can all create risk long before an attacker enters the picture.
3. Protect: What Safeguards Are in Place?
Protect covers the controls and processes designed to reduce the likelihood or impact of a cybersecurity event.
Think identity and access management, authentication, data security, platform security, awareness and training, infrastructure resilience and other preventative measures.
This is often where security teams are most comfortable because it includes many familiar security technologies. But NIST encourages organizations to look beyond whether a tool has been purchased.
The more useful question is: Are the appropriate safeguards actually producing the outcomes we need?
4. Detect: Will We Know When Something Is Wrong?
Prevention alone isn’t enough.
Detect focuses on the organization’s ability to discover and analyze potential cybersecurity attacks and compromises.
That means having sufficient visibility across environments, monitoring for suspicious behavior and establishing processes for analyzing events.
For IT and security leaders, this is an important distinction. Having logs isn’t the same as having visibility. And having alerts isn’t the same as being able to recognize meaningful threats quickly.
5. Respond: What Happens When an Incident Occurs?
When a cybersecurity incident happens, speed and coordination matter.
Respond focuses on how an organization manages an incident once it has been detected. That includes incident management, analysis, communications, reporting and mitigation.
A documented incident response plan is a good start. A plan that has been tested with the people expected to execute it is much more valuable.
Organizations should know who makes decisions, who communicates with leadership, when legal or external resources become involved and how technical teams coordinate containment and remediation, before an actual incident forces those decisions.
Recover: How Do We Restore Operations?
Recovery is about getting the organization back to normal operations following an incident. Backups are part of that equation, but recovery goes much further.
Organizations need to understand which systems and services must be restored first, whether recovery processes have been tested, how long restoration realistically takes and how stakeholders will be kept informed.
The goal isn’t simply to have a backup. It’s to know that the organization can recover when it matters.
NIST Is Not a Checklist
One of the most common mistakes organizations can make with NIST is treating it like a massive compliance checklist. That’s not how the framework is intended to work.
NIST describes the CSF Core as a set of cybersecurity outcomes rather than a prescribed list of actions. The specific practices used to achieve those outcomes will vary based on the organization and its risks.
That distinction matters.
The goal isn’t necessarily to achieve the highest possible level everywhere. The goal is to understand your risk, determine the cybersecurity outcomes your organization needs and make informed decisions about where improvement matters most.
Current State vs. Target State
One of the most practical ways to use the NIST framework is to compare where you are today with where you need to be. NIST calls these Organizational Profiles.
- A Current Profile describes the cybersecurity outcomes your organization is achieving today.
- A Target Profile describes the outcomes you want to achieve based on business objectives, requirements, threats and risk tolerance.
Comparing the two gives you a gap analysis. Those gaps can then become the basis for a prioritized cybersecurity roadmap. NIST provides an Organizational Profile template specifically designed to support this side-by-side assessment.
This is where the framework becomes particularly useful for IT and security leaders. Instead of saying, “We need to improve security,” you can begin having much more specific conversations: Here’s where we are. Here’s where we need to be. Here are the most important gaps. And here’s what we recommend addressing first.
What About NIST Tiers?
NIST CSF also includes four Tiers that help organizations characterize the rigor of their cybersecurity risk governance and management practices:
- Tier 1 – Partial
- Tier 2 – Risk Informed
- Tier 3 – Repeatable
- Tier 4 – Adaptive
It’s tempting to treat these as a maturity score and assume every organization should race toward Tier 4. That’s not their purpose.
NIST recommends using Tiers to provide context around how an organization manages cybersecurity risk and to help identify appropriate improvements. They can be applied alongside Organizational Profiles to help evaluate current practices and desired outcomes. The right target depends on the organization’s risk environment, requirements and business priorities.
A Practical Way to Get Started
You don’t need to transform your entire cybersecurity program at once.
A practical NIST adoption process can begin with five steps:
- Define your scope. Don’t try to assess everything on day one. Start with a business unit, critical environment, specific risk area or set of high-value systems.
- Assess your current state. Use the six NIST Functions to evaluate what you’re doing today. Document existing processes, technologies, ownership and known gaps.
- Define your target state. Determine what “good” needs to look like for your organization based on business risk, not simply what is technically possible.
- Prioritize the gaps. Not every gap carries the same risk. Look at business impact, threat exposure, regulatory requirements, dependencies, effort and cost.
- Build and revisit the roadmap. Translate priority gaps into projects, assign ownership and establish measurable outcomes. Then reassess regularly as the business, technology environment and threat landscape change.
This closely follows NIST’s own guidance for using Organizational Profiles: scope the profile, gather information, establish current and target outcomes, analyze gaps, create an action plan and update the profile as improvements are made.
Don’t Start With the Tools
There’s another practical benefit to approaching cybersecurity through a framework like NIST: it changes the starting point of the conversation.
Instead of asking: What security product should we buy next? You can ask: What risk are we trying to reduce, where is our current capability falling short and what is the best way to close that gap?
Sometimes the answer will be new technology. Sometimes it will be better configuration of technology you already own. It may be a process issue, an identity problem, insufficient visibility, unclear ownership, missing expertise or a recovery plan that hasn’t been tested.
That is why a framework-based approach can also help organizations rationalize their cybersecurity investments. It creates a way to connect technologies and services to specific security outcomes instead of building a security architecture one product at a time.
NIST Is a Starting Point, Not the Finish Line
The real value of the NIST Cybersecurity Framework isn’t achieving a perfect score. It’s creating a repeatable way to understand and communicate cybersecurity risk.
For IT and security leaders, that means being able to move beyond isolated technical conversations and build a cybersecurity roadmap tied to business priorities, operational realities and measurable risk reduction.
And you don’t have to tackle all of it at once. Start with the systems and risks that matter most. Understand your current state. Define where you need to go. Prioritize the gaps. Then keep reassessing.
Cybersecurity maturity isn’t a destination. It’s the discipline of knowing where your risks are and making deliberate decisions about what to do next.
Need Help Turning NIST Into an Actionable Roadmap?
ANM helps organizations assess their cybersecurity environments, identify gaps and build practical roadmaps aligned to frameworks such as NIST.
Whether you’re establishing a baseline, validating an existing security strategy or trying to determine where to invest next, a cyber resilience workshop or a structured assessment can help turn a broad framework into clear priorities with achievable next steps.




