The public draft of the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 was released in August and represents an upcoming significant update to the original CSF, published in 2014. The draft is a response to the continually evolving and ever-more-dangerous cybersecurity landscape, designed to provide enterprises with a complete and flexible approach to managing cybersecurity risk.

NIST is seeking feedback on this draft and the final version of CSF 2.0 is expected to be published in early 2024.

The CSF 2.0 draft provides a common language approach to managing cybersecurity risk, so enterprises can adapt it to their specific needs.

"The overall message of CSF 2.0 is that risk management needs to be elevated to an enterprise-level, with key leadership involvement," Gartner Distinguished VP Analyst Katell Thielemann told SDxCentral. "Instead of focusing on security controls, security teams need to understand what role security plays in the overall lifecycle of risk management, to include ecosystems like supply chains.”

"It also sends the message that governance is a continuous discipline that needs to be present at all stages of security management, not a few steps that take place at the beginning of the 'identify' function," Thielemann said.

The CSF 2.0 is based on six core functions, including the new Govern function. They are the following:

  • Identify: This function is to develop the organizational understanding to manage cybersecurity risk to systems, assets, data and capabilities.
  • Protect: This function is to develop and implement the appropriate safeguards to ensure the delivery of critical infrastructure services.
  • Detect: This function is to develop and implement the appropriate activities to identify the occurrence of a cybersecurity event.
  • Respond: This function is to develop and implement the appropriate activities to take action regarding a detected cybersecurity event.
  • Recover This function is to develop and implement the appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event.
  • Govern: This new function focuses on the importance of governance in managing cybersecurity risk.
What Govern provides

Govern provides enterprises with a framework for developing and implementing a cybersecurity governance program. Governance is the system of rules, policies and processes that an organization uses to make decisions and manage its operations. This is important for ensuring that cybersecurity is a priority for the organization and that cybersecurity risks are managed effectively.

The new function includes a set of activities that enterprises can use to improve their cybersecurity governance, such as developing a strategy and aligning it with the organization's overall business strategy; establishing a separate cybersecurity risk management program; implementing and maintaining controls; and monitoring and evaluating the entire process.

Govern also offers enterprises a way to measure and improve their cybersecurity governance maturity. The framework includes a set of guidelines that enterprises can use to assess their current maturity level and then identify areas for improvement.

"The addition of the governance feature will further help enterprises adopt it as a comprehensive framework with leadership buy-in and continuous management," Thielemann said.

Important updates in CSF 2.0

Besides the new Govern function, other updates in the draft include these three items:

  • Increased flexibility: The CSF 2.0 provides enterprises with more flexibility in how they implement the framework. For example, enterprises can choose to focus on specific functions or categories that are most relevant to their needs.
  • Expanded scope: The CSF 2.0 is no longer limited to critical infrastructure enterprises. It can be used by enterprises of all sizes and industries.
  • Improved guidance: The CSF 2.0 includes improved guidance on how to implement the framework based on best practices and lessons learned from the cybersecurity community.

"Because CSF 2.0 is more inclusive, agile and adaptable, it is a more valuable tool for enterprises of all sizes," says Carl Herberger, program VP of security research at IDC. "The CSF 2.0 can help enterprises to improve their cybersecurity posture, reduce their risk of cyberattacks, increase their compliance with cybersecurity regulations, reduce costs, and improve customer confidence."

CSF 2.0 can be deployed for use cases such as a small business developing a basic cybersecurity plan; a large enterprise implementing a full-fledged cybersecurity program, and a government agency needing to comply with cybersecurity regulations.

"The NIST CSF is a voluntary framework, but it is one of the most leveraged globally because it provides flexibility," Thielemann said. "Even though CSF 2.0 explicitly expands the CSF’s scope beyond critical infrastructure to enterprises of any size or sector, that was in actuality already done. Many enterprises globally use the NIST CSF as an organizing framework whether they align to critical infrastructure or not."

How CSF 2.0 stirs AI into the security mix

Draft CSF 2.0 recognizes the potential of artificial intelligence (AI) to improve cybersecurity and provides guidance on how enterprises can use it to manage cybersecurity risk. The guidance includes:

  • Identifying and assessing cybersecurity risks: AI can be used to identify and assess cybersecurity risks more quickly and effectively than traditional methods. For example, AI can be used to analyze large amounts of data to identify patterns and trends that may indicate a cybersecurity risk.
  • Detecting and responding to cybersecurity incidents: AI can be used to find and respond to cybersecurity incidents more quickly and effectively than traditional methods. AI can be used to monitor network traffic for anomalous activity that may indicate a cybersecurity attack.
  • Improving the effectiveness of cybersecurity controls: AI can be used to improve the effectiveness of cybersecurity controls, such as those that can automatically adjust to changes in the threat landscape.

CSF 2.0 also provides guidance on how enterprises can use AI responsibly and ethically to manage cybersecurity risk. For example, it recommends that enterprises develop and implement policies and procedures for the use of AI in cybersecurity. The draft also recommends that enterprises monitor and evaluate the use of AI in cybersecurity to ensure that it is consistent with the organization's values and ethical principles.

How CSF 2.0 is expected to impact cybersecurity practices

In summarizing the expected impact of CSF 2.0, Thielemann told SDxCentral: "I would expect organizations that already use the CSF to expand the maturity of their governance models and update risk assessments to take into account their supply chains. And I would expect organizations that are not using the CSF to take another look, as the more comprehensive framework might help them organize risk at the enterprise level.

"But we should also note that the flexibility built into the CSF originally, and kept under this revision, also means that the guidance for managing cyber risks is high level. Each organization’s implementation of the framework will be different because everyone’s risks are unique, whether we’re talking about different threats, different vulnerabilities, different risk tolerances, different ranges of impacts, etc,” she said.

"Because the revised guidance improves risk assessment, governance and scope (notably across supply chains), security teams will have to develop strategic leadership skills in addition to the more traditional tactical security controls skills they are known for," Thielemann added.