The NIST CSF 2.0 provides a common structure for cybersecurity outcomes across organisations of different sizes and sectors. Its six Functions are Govern, Identify, Protect, Detect, Respond and Recover. Govern is part of version 2.0 and must be included. See the NIST CSF 2.0 overview.
Use in a programme
Use the Core's outcomes to describe the organisation's current and intended cybersecurity posture and prioritise work in its business context. Profiles and Tiers support communication and understanding of risk-management practices.
The framework describes outcomes rather than prescribing one implementation for every organisation. Select practices and evidence appropriate to the actual risks and scope. Consult the CSF 2.0 publication.
Use in CSFaaS
The reviewed library offers CSF 2.0 in English, French and Spanish. Verify the selected entry and its hierarchy before assessment.
Use applicability, policy links, evidence and ownership to record how requirements are addressed. CSF Tiers and the app's maturity scale are different constructs; do not label an internal 0–5 maturity score as an official CSF Tier.