NIST Cybersecurity Framework 2.0 for IS Auditors
Six Functions now, not five. Govern was added in February 2024, after the DISA 3.0 material was written.
The NIST Cybersecurity Framework (CSF) is a set of cybersecurity outcomes published by the US National Institute of Standards and Technology. It is voluntary and technology-neutral, and it is widely used as a common language between boards, security teams and auditors. It describes what good looks like; it does not prescribe how to get there.
The current version is CSF 2.0, released on 26 February 2024. It added a sixth Function, Govern, and dropped the old title "Framework for Improving Critical Infrastructure Cybersecurity" because it is meant for every kind of organisation. ICAI's ISA 3.0 background material is dated August 2020, so any NIST CSF reference you meet in older notes describes version 1.1 with five Functions.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Six Functions of CSF 2.0
Govern (GV)
Outcome in plain words
Cybersecurity strategy, risk appetite, roles, policy and oversight are set and monitored; includes supply chain risk
Categories
Organisational Context; Risk Management Strategy; Roles, Responsibilities and Authorities; Policy; Oversight; Cybersecurity Supply Chain Risk Management
Identify (ID)
Outcome in plain words
Current cybersecurity risks are understood
Categories
Asset Management; Risk Assessment; Improvement
Protect (PR)
Outcome in plain words
Safeguards are used to manage the risks
Categories
Identity Management, Authentication and Access Control; Awareness and Training; Data Security; Platform Security; Technology Infrastructure Resilience
Detect (DE)
Outcome in plain words
Possible attacks and compromises are found and analysed
Categories
Continuous Monitoring; Adverse Event Analysis
Respond (RS)
Outcome in plain words
Action is taken on a detected incident
Categories
Incident Management; Incident Analysis; Incident Response Reporting and Communication; Incident Mitigation
Recover (RC)
Outcome in plain words
Affected assets and operations are restored
Categories
Incident Recovery Plan Execution; Incident Recovery Communication
| Function | Outcome in plain words | Categories |
|---|---|---|
| Govern (GV) | Cybersecurity strategy, risk appetite, roles, policy and oversight are set and monitored; includes supply chain risk | Organisational Context; Risk Management Strategy; Roles, Responsibilities and Authorities; Policy; Oversight; Cybersecurity Supply Chain Risk Management |
| Identify (ID) | Current cybersecurity risks are understood | Asset Management; Risk Assessment; Improvement |
| Protect (PR) | Safeguards are used to manage the risks | Identity Management, Authentication and Access Control; Awareness and Training; Data Security; Platform Security; Technology Infrastructure Resilience |
| Detect (DE) | Possible attacks and compromises are found and analysed | Continuous Monitoring; Adverse Event Analysis |
| Respond (RS) | Action is taken on a detected incident | Incident Management; Incident Analysis; Incident Response Reporting and Communication; Incident Mitigation |
| Recover (RC) | Affected assets and operations are restored | Incident Recovery Plan Execution; Incident Recovery Communication |
Profiles and Tiers
The two tools that turn the outcome list into something an organisation can measure itself against.
- Current Profile
- The CSF outcomes the organisation is achieving now.
- Target Profile
- The outcomes it has chosen and prioritised to achieve. The gap between Current and Target becomes the action plan.
- Community Profile
- A baseline published for a sector or use case that organisations can adopt as their Target Profile. NIST's incident response guidance (SP 800-61 Rev. 3, April 2025) is itself written as a CSF 2.0 Community Profile.
- Tiers
- Four levels describing how rigorous risk governance and management are: Partial (1), Risk Informed (2), Repeatable (3) and Adaptive (4). They describe maturity of practice, not a score of controls.
Quick practice on audit concepts. No signup.
How an IS Auditor Uses the CSF
- check_circleAs a benchmark to scope a cybersecurity review: map the client's controls to each Function and see which outcomes nobody owns
- check_circleTo read the client's own Current and Target Profiles, and test whether the gap-closing plan is funded and tracked
- check_circleTo check that cyber risk reaches the board: Govern now makes oversight, risk appetite and supplier risk explicit outcomes
- check_circleAlongside other frameworks, not instead of them. The CSF points to informative references in other standards and guidelines, such as NIST SP 800-53, for the detailed controls; ISO/IEC 27001 can be mapped to it the same way
How the DISA Assessment Test Tests This
Expect MCQs that ask which Function an activity belongs to (asset inventory is Identify; log monitoring is Detect; containment is Respond; supply chain risk and policy are Govern) and what Profiles and Tiers mean. The trap is version: if you learned "five Functions" from 2020-era notes, you will miss Govern. Questions may still be written to the older version, so read the options: if Govern is not offered, the question is using CSF 1.1. Another trap is treating Tiers as maturity levels for each control; they describe the organisation's overall risk-management practice.
FAQs
What are the six functions of the NIST Cybersecurity Framework 2.0?expand_more
Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in CSF 2.0 in February 2024; version 1.1 had the other five.
What is the difference between NIST CSF 1.1 and 2.0?expand_more
CSF 2.0 adds the Govern Function, moves supply chain risk and policy under it, reorganises the Categories, and widens the scope from critical infrastructure to all organisations.
What are NIST CSF Tiers?expand_more
Four levels describing the rigour of an organisation's cybersecurity risk practices: Partial, Risk Informed, Repeatable and Adaptive.
Is NIST CSF mandatory in India?expand_more
No. It is a voluntary US framework. Indian organisations follow their own regulators' rules and often use the CSF or ISO/IEC 27001 as a reference structure.
Next steps
- Incident Responsearrow_forward
- ISO 27001arrow_forward
- COBIT vs ISO vs ITILarrow_forward
- IT Risk Managementarrow_forward
Assessment Test format, timed and scored.
