Glossary

NIST CSF

The NIST Cybersecurity Framework is a voluntary structure for organizing a security program, built around six functions in CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover. It isn’t certifiable and isn’t a control catalog — it’s the taxonomy everyone maps everything else onto, which is precisely its value.

Where it shows up

Security questionnaires (“describe your posture using CSF functions”), board reporting (the six functions make legible slides), cyber-insurance underwriting, and US enterprise reviews. Regulated sectors meet it indirectly: many US regulators anchor their expectations to CSF’s structure.

CSF vs the frameworks you certify against

SOC 2 and ISO 27001 produce artifacts — reports, certificates. CSF produces orientation: a current-state and target-state profile that tells you where your program is thin. Teams commonly run an ISO/SOC 2 control set and express it in CSF terms when a counterparty asks — the mappings are published and mechanical.

The 2.0 change that matters

CSF 2.0 added Govern as a first-class function — accountability, strategy, supply-chain oversight — codifying what regulators like MAS already probe: that security is directed from the top, not delegated to tooling. If your program can’t evidence the Govern function, that’s the gap to close first; it’s also the one platforms alone can’t fill.

Related Terms

ISMS — An ISMS is the management system ISO 27001 certifies — the loop of risk assessment, controls, internal audit, and review that runs your security program.

NIST 800-53 — NIST 800-53 is the US government's control catalog — hundreds of controls across 20 families — underlying FedRAMP, FISMA, and federal procurement.

Risk Register — A risk register is the living record of identified risks, their scores, owners, and treatments — sampled in every SOC 2 and ISO 27001 audit.