// Reference · Frameworks
NIST Cybersecurity
Framework 2.0
The world's most-used security framework, decoded. CSF 2.0 organizes everything a program should do into six Functions — with the new Govern function now wrapping the original five. Explore every outcome in plain English, then rate your own posture as you go.
No outcomes match. Refine the filter ▓▓░
Govern
In plain terms: Govern is where leadership decides how much cyber risk the organization will accept, who is responsible, and what the rules are. It is the steering wheel that keeps every other function pointed in the right direction.
GV.OC Organizational Context 5
GV.RM Risk Management Strategy 7
GV.RR Roles, Responsibilities, and Authorities 4
GV.PO Policy 2
GV.OV Oversight 3
GV.SC Cybersecurity Supply Chain Risk Management 10
Identify
In plain terms: you can't protect what you don't know you own. Identify is the inventory-and-understand step — cataloguing your assets, mapping your suppliers, sizing up your risks, and spotting where your defenses need to get better.
ID.AM Asset Management 7
ID.RA Risk Assessment 10
ID.IM Improvement 4
Protect
In plain terms: this is where you actually put up defenses — logins, access rules, encryption, training, patching, backups — so the risks you found in Identify can't easily turn into incidents.
PR.AA Identity Management, Authentication, and Access Control 6
PR.AT Awareness and Training 2
PR.DS Data Security 4
PR.PS Platform Security 6
PR.IR Technology Infrastructure Resilience 4
Detect
In plain terms: this is your alarm system. Detect is about watching your systems closely and making sense of the weird signals fast, so a quiet break-in doesn't get the chance to become a disaster.
DE.CM Continuous Monitoring 5
DE.AE Adverse Event Analysis 6
Respond
In plain terms: once you've caught an attack in progress, Respond is your playbook for the messy hours that follow — running the incident, working out what actually happened, telling the people who need to know, and stopping the bleeding before it spreads.
RS.MA Incident Management 5
RS.AN Incident Analysis 4
RS.CO Incident Response Reporting and Communication 2
RS.MI Incident Mitigation 2
Recover
In plain terms: once the fire is out, Recover is how you rebuild without setting it alight again — restoring systems from clean backups, bringing services back in the right order, and telling everyone the coast is clear. It's the difference between limping back and walking back stronger.
RC.RP Incident Recovery Plan Execution 6
RC.CO Incident Recovery Communication 2
Implementation examples
Maturity — CMMI level
Source: NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (February 2024), a U.S. Government work in the public domain. Official outcome and category text is reproduced from NIST; plain-English translations, examples, and the self-assessment tool are the Messink Academy's study aids and are not part of, nor endorsed by, NIST. Always consult the official framework for authoritative guidance.