NIST Cybersecurity Framework (CSF)

View as Markdown

What is the NIST Cybersecurity Framework?

The Framework for Improving Critical Infrastructure Cybersecurity, better known as the Cybersecurity Framework (CSF), was first published by the National Institute for Standards and Technology (NIST) in February 2014, in response to Executive Order 13636, Improving Critical Infrastructure Cybersecurity. The NIST CSF is an evolving framework for improving cybersecurity risk management in critical infrastructure. The framework itself is voluntary, but regulators are increasingly pressing critical infrastructure operators to improve cybersecurity, and NIST CSF shows them how.

Who is the intended audience?

Although NIST CSF was developed to improve cybersecurity risk management in critical infrastructure, organizations of any size in any industry can use it.

Where can I find more information?

The National Institute for Standards and Technology website publishes these resources:

How can runZero help me with these controls?

For the latest on how runZero can help with NIST CSF, see runZero’s NIST CSF compliance page.

Updated