Cyber Assurance
NIST CSF 2.0 Explained: The Six Functions and How to Use Them
NIST CSF 2.0 explained: the new Govern function, all six functions, categories, profiles and tiers, and how Australian organisations can use it with the ISM.
The NIST CSF 2.0 (Cybersecurity Framework version 2.0) is one of the most widely used cyber security frameworks in the world, and for good reason. It is free, it is written for executives as much as for engineers, and it gives organisations of any size a common language for describing where they are and where they need to be. Version 2.0, released in February 2024, was the first major update since 2014.
This guide explains what changed, how the framework is structured and how to use it in practice, including alongside the Australian ISM.
What changed in version 2.0
Three changes matter most:
- A new Govern function. Governance now sits at the centre of the framework rather than being scattered through it. It covers strategy, risk appetite, roles, policy, oversight and supply chain risk management.
- A broader audience. The original framework was aimed at critical infrastructure. Version 2.0 is explicitly for organisations of every size and sector.
- More practical guidance. NIST added implementation examples, quick-start guides and an online reference tool that maps the framework to other standards.
You can explore the full framework and its resources on the NIST Cybersecurity Framework site.
The six functions
NIST CSF 2.0 organises outcomes into six functions:
- Govern (GV): set and monitor the organisation’s cyber security strategy, expectations and policy. Who decides, on what basis, and how is it overseen?
- Identify (ID): understand your assets, suppliers and risks so you can prioritise.
- Protect (PR): put safeguards in place, from identity management and training to data security and platform hardening.
- Detect (DE): find and analyse possible attacks and compromises.
- Respond (RS): take action on a detected incident: manage, analyse, communicate and contain it.
- Recover (RC): restore assets and operations, and communicate during recovery.
Govern wraps around the other five. Identify, Protect, Detect, Respond and Recover describe the lifecycle of managing risk and incidents; Govern makes sure that work is directed, resourced and accountable.
Categories, subcategories, profiles and tiers
Each function breaks down into categories (22 in total) and subcategories (106 specific outcomes). For example, the Govern function includes categories for organisational context, risk management strategy, roles and responsibilities, policy, oversight and cyber security supply chain risk management.
Two tools turn those outcomes into a plan:
- Profiles. A current profile describes the outcomes you achieve today; a target profile describes the outcomes you need. The gap between them is your roadmap.
- Tiers. Four tiers describe how rigorous your risk management practices are: Partial (1), Risk Informed (2), Repeatable (3) and Adaptive (4). Tiers are not a maturity score to maximise; they describe the level that suits your risk.
How to use NIST CSF 2.0 in practice
A practical sequence I use with leadership teams:
- Agree scope and drivers. Which business units, systems and obligations are in scope?
- Build the current profile. Assess each relevant subcategory honestly, with evidence.
- Set the target profile. Base it on risk, obligations and appetite, not on an ambition to be perfect everywhere.
- Prioritise the gaps using a cyber security risk assessment, so that effort goes to the risks that matter most.
- Build a roadmap with owners, budgets and dates.
- Report progress to the board using a small set of indicators. See cyber risk reporting for boards.
NIST CSF 2.0, NIST SP 800-53 and the ISM
People often confuse the CSF with SP 800-53. They work at different levels:
- NIST CSF 2.0 describes outcomes and is ideal for strategy, governance and board communication.
- SP 800-53 is a detailed control catalogue used to design and assess systems.
The two map to each other, and SP 800-53 maps closely to the Australian ISM. In practice, many Australian organisations use the CSF to set direction and talk to the board, and the ISM or SP 800-53 to implement and evidence controls. I explain the mapping in NIST SP 800-53 and the ISM.
Common mistakes
- Treating it as a checklist. The CSF describes outcomes; it does not prescribe controls. Use a control framework underneath it.
- Chasing Tier 4 everywhere. The right tier depends on your risk. Adaptive practices cost real money.
- Skipping Govern. Without clear ownership, appetite and oversight, the other functions drift.
- No evidence. A current profile based on opinion rather than evidence produces a roadmap that solves the wrong problems.
Frequently asked questions
What are the six functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond and Recover. Govern is new in version 2.0 and sits at the centre of the other five.
Is NIST CSF 2.0 mandatory?
It is voluntary for most organisations, although some regulators and contracts reference it. Its value is as a common language and planning tool, which is why it is widely adopted internationally, including in Australia.
What is the difference between NIST CSF and NIST SP 800-53?
NIST CSF 2.0 describes high-level cyber security outcomes for strategy and governance. NIST SP 800-53 is a detailed catalogue of security and privacy controls used to design, implement and assess systems.
Can Australian organisations use NIST CSF 2.0 with the ISM?
Yes. Many use the CSF to set strategy and report to the board, and the ISM or NIST SP 800-53 to implement and evidence controls. The frameworks map well to each other.
Want a NIST CSF 2.0 current and target profile for your organisation? See services or talk to my AI agent.