No history yet

Modern Cybersecurity Frameworks

From Principles to Practice

Understanding the CIA triad is essential, but it doesn't provide a roadmap for building a security programme. To move from abstract principles to a concrete, professional operation, we need a framework. The most widely adopted guide for this is the (CSF), particularly its latest version, CSF 2.0.

The framework isn't a checklist of tools to buy or software to install. It's a structured way of thinking about risk. It helps organisations answer fundamental questions: What are our most critical assets? What are the biggest threats to them? And how do we align our security efforts with our overall business goals?

The Six Core Functions

At the heart of CSF 2.0 are six core functions. These represent the complete lifecycle of managing cybersecurity risk. They provide a high-level, strategic view of an organisation's security activities.

Lesson image

The newest and most foundational function is Govern. This is the strategic layer that oversees all other security activities. It's where an organisation establishes its cybersecurity strategy, defines roles and responsibilities, and understands its risk tolerance. A key part of Govern is Supply Chain Risk Management (SCRM), acknowledging that an organisation's security is only as strong as its partners'.

With governance in place, the other five functions follow a logical progression:

  1. Identify: Understand what you have and what risks it faces. This involves cataloguing assets (hardware, software, data), identifying threats, and assessing vulnerabilities.
  2. Protect: Implement safeguards to prevent or limit the impact of a potential cybersecurity event. This includes access control, awareness training, and data security measures.
  3. Detect: Put systems in place to find cybersecurity events as they happen. This means continuous monitoring, anomaly detection, and security analysis.
  4. Respond: Develop and implement the actions to take once a cybersecurity incident is detected. This involves response planning, communication, and mitigation.
  5. Recover: Create plans for resilience and to restore any capabilities or services that were impaired due to an incident. This includes recovery planning and improvements.

Profiles and Tiers

The framework becomes truly practical through the use of Profiles and Tiers. These tools help an organisation measure its performance and plan for the future.

A Profile is a snapshot of an organisation's cybersecurity posture. You create two:

  • Current Profile: An honest assessment of where the organisation is today, mapping its current activities to the framework's functions and categories.
  • Target Profile: A description of the desired security posture, based on business objectives, risk appetite, and regulatory requirements.

The gap between the Current and Target profiles creates a clear action plan for improvement. It helps prioritise security investments based on what matters most to the business, rather than just chasing the latest technology.

A Profile isn't just about what you do, but how you do it. It aligns security activities with the mission of the business.

Tiers describe the maturity of an organisation's cybersecurity risk management practices. They aren't a simple grading system. Instead, they characterise how formalised, integrated, and adaptive the security programme is. An organisation doesn't necessarily need to be at the highest tier; the appropriate tier depends on its specific goals and risk environment.

TierDescriptionCharacteristics
Tier 1: PartialAd-hoc and reactive cybersecurity.Limited awareness of risk; no formal processes; response is often chaotic.
Tier 2: Risk-InformedRisk management processes are approved but not fully integrated.Awareness of risk exists; some processes are in place, but they are not organisation-wide.
Tier 3: RepeatableFormal policies and procedures are in place and consistently followed.Organisation-wide security policies are implemented; staff are trained and aware.
Tier 4: AdaptiveThe organisation actively adapts based on lessons learned and predictive indicators.Continuous improvement is ingrained; the organisation anticipates future threats.

By combining Profiles and Tiers, an organisation gains a powerful tool for communication. It can explain its security posture to leadership, regulators, and partners in a clear, standardised way. This moves the conversation from technical jargon to strategic risk management, which is the core purpose of and the NIST CSF.

Now that you have a grasp of the NIST CSF's structure, let's test your knowledge.

Quiz Questions 1/6

What is the primary purpose of the NIST Cybersecurity Framework (CSF)?

Quiz Questions 2/6

Which function was newly introduced in CSF 2.0 to establish an organisation's overall cybersecurity strategy and oversee all other security activities?

Using a framework like NIST CSF transforms cybersecurity from a purely technical defence into a strategic business function, enabling smarter, risk-informed decisions.