Slide background
Slide background




The NIST Cybersecurity Framework (CSF) 2.0

ID 23906 | | Visite: 1583 | CybersicurezzaPermalink: https://www.certifico.com/id/23906

The NIST Cybersecurity Framework  CSF  2 0

The NIST Cybersecurity Framework (CSF) 2.0 - NIST Feb. 2024

ID 23906 | 30.04.2025 / In allegato

The Cybersecurity Framework (CSF) 2.0 is designed to help organizations of all sizes and sectors — including industry, government, academia, and nonprofit — to manage and reduce their cybersecurity risks. It is useful regardless of the maturity level and technical sophistication of an organization’s cybersecurity programs. Nevertheless, the CSF does not embrace a one-size-fitsall approach.

Each organization has both common and unique risks, as well as varying risk appetites and tolerances, specific missions, and objectives to achieve those missions. By necessity, the way organizations implement the CSF will vary.

Ideally, the CSF will be used to address cybersecurity risks alongside other risks of the enterprise, including those that are financial, privacy, supply chain, reputational, technological, or physical in nature.

The CSF describes desired outcomes that are intended to be understood by a broad audience, including executives, managers, and practitioners, regardless of their cybersecurity expertise. Because these outcomes are sector-, country-, and technology-neutral, they provide an organization with the flexibility needed to address their unique risks, technologies, and mission considerations.

Outcomes are mapped directly to a list of potential security controls for immediate consideration to mitigate cybersecurity risks. Although not prescriptive, the CSF assists its users in learning about and selecting specific outcomes.

Suggestions for how specific outcomes may be achieved are provided in an expanding suite of online resources that complement the CSF, including a series of Quick Start Guides (QSGs). Also, various tools offer downloadable formats to help organizations that choose to automate some of their processes.

The QSGs suggest initial ways to use the CSF and invite the reader to explore the CSF and related resources in greater depth. Available through the NIST CSF website, the CSF and these supplementary resources from NIST and others should be viewed as a “CSF portfolio” to help manage and reduce risks.

Regardless of how it is applied, the CSF prompts its users to consider their cybersecurity posture in context and then adapt the CSF to their specific needs. 

Building on previous versions, CSF 2.0 contains new features that highlight the importance of governance and supply chains. Special attention is paid to the QSGs to ensure that the CSF is relevant and readily accessible by smaller organizations as well as their larger counterparts.

NIST now provides Implementation Examples and Informative References, which are available online and updated regularly. Creating current and target state Organizational Profiles helps organizations to compare where they are versus where they want or need to be and allows them to implement and assess security controls more quickly.

Cybersecurity risks are expanding constantly, and managing those risks must be a continuous process. This is true regardless of whether an organization is just beginning to confront its cybersecurity challenges or whether it has been active for many years with a sophisticated, well-resourced cybersecurity team.

The CSF is designed to be valuable for any type of organization and is expected to provide appropriate guidance over a long time. 

National Institute of Standards and Technology NIST.CSWP.29 February 26, 2024  

Collegati

Descrizione Livello Dimensione Downloads
Allegato riservato The NIST Cybersecurity Framework (CSF) 2.0.pdf
NIST 2024
1493 kB 31

Tags: Abbonati Full Plus Cybersecurity

Ultimi archiviati Chemicals

ECHA 2025   Key Areas of Regulatory Challenge
Giu 11, 2025 430

ECHA 2025 - Key Areas of Regulatory Challenge

ECHA 2025 - Key Areas of Regulatory Challenge ID 24098 | 11.06.2025 / Attached The report introduces new topics to reflect ECHA’s growing responsibilities. It also covers emerging topics in waste and recycling that aim to support circularity and enhance Europe’s industrial competitiveness. For… Leggi tutto
REACH Authorisation List
Giu 09, 2025 481

REACH Authorisation Decisions List / Last update: 23.05.2025

REACH Authorisation Decisions List / Last update: 23.05.2025 ID 24091 | Last update: 09.06.2025 REACH Authorisation Decisions List of authorisation decisions adopted on the basis of Article 64 of Regulation (EC) No 1907/2006 (REACH). The list also includes reference to related documentation… Leggi tutto
In situ generated active substances and their products
Giu 07, 2025 551

In situ generated active substances and their products

In situ generated active substances and their products / ECHA Aprile 2025 ID 24087 | 07.06.2025 / Version 2 April 2025 Information requirements and risk assessment for approval and authorisation Recommendations of the BPC Working Groups.________ Il presente documento ha lo scopo di assistere gli… Leggi tutto
Giu 06, 2025 733

Rettifica regolamento (UE) 2023/2055 - 06.06.2025

Rettifica regolamento (UE) 2023/2055 - 06.06.2025 ID 24080 | 06.06.2025 Rettifica del regolamento (UE) 2023/2055 della Commissione, del 25 settembre 2023, recante modifica dell’allegato XVII del regolamento (CE) n. 1907/2006 del Parlamento europeo e del Consiglio concernente la registrazione, la… Leggi tutto
Documento di orientamento CE condizioni d uso simili in tutta l Unione biocidi
Giu 04, 2025 702

Documento di orientamento CE condizioni d'uso simili in tutta l’Unione biocidi

Documento di orientamento CE condizioni d'uso simili in tutta l’Unione biocidi ID 24073 | 04.06.2025 / In allegato Comunicazione della Commissione - Documento di orientamento sulla definizione di condizioni d'uso simili in tutta l'Unione conformemente all'articolo 42, paragrafo 2, del regolamento… Leggi tutto
Decisione di esecuzione  UE  2025 1074
Giu 03, 2025 736

Decisione di esecuzione (UE) 2025/1074

Decisione di esecuzione (UE) 2025/1074 / Non approvazione ossido di etilene uso nei biocidi tipo di prodotto 2 ID 24066 | 03.06.2025 Decisione di esecuzione (UE) 2025/1074 della Commissione, del 2 giugno 2025, che non approva l’ossido di etilene come principio attivo esistente ai fini del suo uso… Leggi tutto
How to prepare a Drinking Water Directive Notification of intention
Mag 30, 2025 851

How to prepare a Drinking Water Directive Notification of intention

How to prepare a Drinking Water Directive Notification of intention / ECHA June 2025 ID 24047 | 30.05.2025 / Attached The purpose of this manual is to assist in the preparation of DWD notification of intention dossiers using IUCLID. The manual provides you with detailed and practical instructions… Leggi tutto

Più letti Chemicals

Notifica HACCP
Apr 05, 2022 102278

Notifica ai fini registrazione Regolamento CE n. 852/2004

Notifica ai fini della registrazione (Reg. CE n. 852/2004) - Ex notifica sanitaria alimentare ID 7901 | 06.03.2019 / Modello notifica allegato [panel]Regolamento (CE) 852/2004...Articolo 6 Controlli ufficiali, registrazione e riconoscimento 1. Gli operatori del settore alimentare collaborano con le… Leggi tutto