NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using the CSF Tiers

Quick-start guides are supplemental resources for the NIST Cybersecurity Framework (CSF) 2.0. See more information on CSF 2.0 quick-start guides.

NIST seeks comments on this initial public draft by May 3, 2024. Submit comments to cyberframework@nist.gov.

Abstract

This Quick-Start Guide describes how to apply the CSF 2.0 Tiers. CSF Tiers can be applied to CSF Organizational Profiles to characterize the rigor of an organization’s cybersecurity risk governance and management outcomes. This can help provide context on how an organization views cybersecurity risks and the processes in place to manage those risks.​ The Tiers can also be valuable when reviewing processes and practices to determine needed improvements and monitor progress made through those improvements.

This Quick-Start Guide describes how to apply the CSF 2.0 Tiers. CSF Tiers can be applied to CSF Organizational Profiles to characterize the rigor of an organization’s cybersecurity risk governance and management outcomes. This can help provide context on how an organization views cybersecurity. See full abstract

This Quick-Start Guide describes how to apply the CSF 2.0 Tiers. CSF Tiers can be applied to CSF Organizational Profiles to characterize the rigor of an organization’s cybersecurity risk governance and management outcomes. This can help provide context on how an organization views cybersecurity risks and the processes in place to manage those risks.​ The Tiers can also be valuable when reviewing processes and practices to determine needed improvements and monitor progress made through those improvements.