Framework library · Risk management and assessment

Cyber risk framework (NIST CSF 2.0)

The NIST Cybersecurity Framework 2.0 organises cyber security into six functions: govern, identify, protect, detect, respond and recover. It describes outcomes rather than prescribing controls, and uses four tiers, from partial to adaptive, to describe how rigorous an organisation's practices are. Rating each function today and setting a target shows where the gaps are, and which of them matter most for the business.

LevelIntermediate
TimeHalf a day with the security lead and the people who run the network, or a day if evidence has to be gathered
Who to involveThe executive accountable for cyber security, the heads of network operations and IT, a board or audit committee member for the governance questions, and the incident response lead.
Also calledNIST Cybersecurity Framework, NIST CSF, Cybersecurity Framework 2.0, CSF implementation tiers, cyber security maturity assessment

Use it when

  • The board asks how good the company's cyber security is and wants an answer it can compare year on year.
  • A customer, insurer or regulator asks you to describe your cyber security against a recognised framework.
  • You need to decide where next year's security budget goes.
  • After an incident, you want to know whether the weakness was isolated or a sign of a gap across a whole function.

Avoid it when

  • You need certification. The CSF is voluntary and not certifiable. Use ISO/IEC 27001 or the scheme your customer requires.
  • You need to assess one system or supplier in detail. Use a control-level assessment, such as NIST SP 800-53 or your own control set.
  • You want to rank specific cyber risks by likelihood and impact. Put them on a risk register. This assessment measures capability, not individual risks.
  • Nobody will provide evidence. Self-ratings without evidence drift upwards. Agree what evidence each rating needs before you start.

How to run it

  1. Set the scope

    The whole company, or one business such as the network. Note which services are outsourced: a managed service provider's work is still your outcome.

  2. Rate each statement on the four-step scale

    1 is ad hoc, 2 is done but not consistently, 3 is formal and applied everywhere, 4 is improved continuously from experience. Note the evidence for each function.

  3. Read the tier for each function

    A tier is reached only when the average reaches it, so 2.8 is still tier 2. CSF 2.0 applies tiers to cyber risk governance and management as a whole. Rating each function on the same scale shows where the gaps sit.

  4. Set a target for each function

    Where the business needs to be in 12 to 24 months, given its customers, its regulators and the threats it faces. Not every function needs tier 4.

  5. Rank the gaps

    The largest gaps in functions that protect revenue, customer data or safety come first. A gap in detect matters more if you cannot recover quickly.

  6. Turn the gaps into a plan with owners

    Each gap becomes two or three actions with an owner and a date, and the next assessment checks them.

Work through it

Answer the questions below, or load the worked example to see a finished one. The drawing updates as you type. Export the result as a PowerPoint deck, a Word document, an Excel workbook, a PDF or plain text.

What you type stays in this browser, so you can close the page and come back to it. It is not sent to Blue Prysm or anyone else, and the exports are made here, on your device. Privacy policy.

Mistakes to avoid

  • Rating by policy rather than practice. A policy approved last year scores 2 until it is shown to be followed everywhere.
  • Setting tier 4 as the target everywhere. It is expensive and rarely needed. Targets should follow the risk.
  • Skipping Govern because it feels like paperwork. Most failures in the other five functions trace back to unclear ownership and unfunded decisions.
  • Copying the framework's outcome statements into a questionnaire and calling it an assessment. Translate them into what they mean for your own network and customers.

Where it comes from

US National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, published 26 February 2024. Version 2.0 added the Govern function to the five functions of the original framework (version 1.0, 2014; version 1.1, April 2018) and widened its intended audience from critical infrastructure to organisations of every size and sector. Source.

The NIST Cybersecurity Framework is a publication of the US National Institute of Standards and Technology. This page describes the framework independently. The statements in the workbench are not NIST's, and NIST does not endorse this page.

Use it with

Further reading

Work through it with us

The frameworks here are free to use as they stand. If you would rather work through the question behind this one with us, these are the ways an engagement starts.