O Oluma Cyber Security Framework Files · No. 02 Framework · Risk Management The NIST Cybersecurity Framework A common language for cyber risk — six functions that turn “are we secure?” into a conversation everyone from the server room to the boardroom can actually have. v2.0 · Feb 20246 Functions22 Categories106 Subcategories CSF 6 FN22 CT106 How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem Security couldn’t talk to the business For years, security teams and the people who funded them spoke different languages. Engineers talked in firewalls and CVEs; executives asked, “Are we okay?” and got an answer they couldn’t evaluate. There was no shared way to describe where an organization stood, or to explain cyber risk to a board, a regulator, or an insurer. Every organization was also inventing its own vocabulary. Two companies could have identical gaps and describe them in completely different words — which made it nearly impossible to compare, benchmark, or communicate risk across an industry. 02 Why It Was Created To give everyone the same words After a 2013 executive order on critical infrastructure, NIST was asked to build something unusual: not a rulebook, but a common language. Something a power utility, a hospital, and a small manufacturer could all use to describe their cybersecurity posture in the same terms. The core ideaDon’t tell people exactly which tools to buy. Describe the outcomes good security produces, organize them so anyone can follow, and let each organization map its own controls underneath. The result is outcome-based: the framework says what should be true, not how you must achieve it — which is why it scales from a five-person shop to a federal agency. 03 The Story Behind It From critical infrastructure to a global default 2014 · v1.0Born for critical infrastructureReleased under Executive Order 13636 with five core functions — Identify, Protect, Detect, Respond, Recover — aimed at power, water, finance, and other essential sectors. 2018 · v1.1Supply chain & self-assessmentAdded guidance on supply-chain risk and on measuring your own program, as adoption spread far beyond the original infrastructure audience. 2024 · v2.0Governance joins, scope goes globalPublished February 26, 2024. A sixth function — Govern — was added, and the framework was explicitly rewritten for any organization, in any sector, in any country. It is now used in 185+ nations. 04 How It Works 6 functions, 22 categories, 106 outcomes The framework nests in three layers. Six Functions break into 22 Categories, which break into 106 Subcategories — the specific outcomes you actually work toward. Version 2.0’s headline change is the new Govern function, which pulls governance, supply chain, and enterprise risk up to sit as a peer beside the rest. Govern ★ newIdentifyProtectDetectRespondRecover Two more tools make it usable. Implementation Tiers (Partial → Risk-Informed → Repeatable → Adaptive) describe how mature your practices are. Profiles capture where you are today (Current) versus where you want to be (Target) — and the gap between them is your roadmap. The CoreFunctions → outcomesGovern, Identify, Protect, Detect, Respond, Recover — broken into 22 categories and 106 outcome statements. TiersHow mature you areFour tiers from Partial to Adaptive describe how consistently and deliberately you manage cyber risk. ProfilesCurrent vs. TargetTwo snapshots — what you do now and what you intend to do — that turn the framework into a prioritized improvement plan and a board-ready story. Framework vs. ControlsCSF tells you what outcomes to reach; it deliberately doesn’t hand you the exact settings. For the how, you map its outcomes to a control catalog like CIS Controls, ISO 27001, or NIST 800-53. CSF is the map; those are the terrain. 05 Real-World Example A regional hospital briefs its board A mid-sized hospital can’t recite firewall rules to its board — but it can speak in functions. Using CSF, the security lead builds a Current Profile, sets a Target Profile, and turns the distance between them into three budget priorities. Their CSF conversationSix words the whole room understands Govern — name who owns cyber risk and how it’s reported Identify — know every system, vendor, and data store Protect — access control, training, safeguards in place Detect — monitoring that catches trouble early Respond & Recover — a tested plan for the bad day Now the board isn’t staring at jargon — they’re looking at six plain outcomes and one honest gap chart, and they can fund it. 06 Who Uses It The most widely adopted framework in the world 🏢Every sectorFinance, healthcare, energy, education, manufacturing — the original critical-infrastructure focus has gone fully cross-industry. 🌎Global & governmentUsed in 185+ countries and referenced across U.S. federal expectations, from the SEC to sector regulators. 🧭Boards & insurersA shared vocabulary that leadership, auditors, and cyber-insurance underwriters all recognize. Its reach comes from translation: CSF maps to almost everything else, so one profile can drive many obligations at once. maps to ISO 27001NIST 800-53CIS ControlsHIPAAPCI DSSSOC 2 07 Career Relevance The lingua franca of GRC If CIS teaches you to do, CSF teaches you to communicate — and communication is what gets GRC professionals into the room where decisions happen. Knowing CSF means you can run a gap assessment and then explain it to executives without losing them. GRC analystProfiles & gapsBuild current/target profiles, score maturity by tier, and produce the roadmap leadership signs off on. vCISO / managerBoard reportingTurn technical posture into six functions and a risk narrative any executive can act on. Auditor / consultantA universal crosswalkBecause CSF maps to nearly every other framework, it’s the hub you translate between ISO, 800-53, and CIS engagements. “Fluent in NIST CSF” signals you can carry security from the console to the boardroom — a rare and well-paid skill. 08 Strengths & Challenges Honest trade-offs ✦ Strengths A shared language leadership actually understands Flexible and outcome-based — scales to any size Maps cleanly to nearly every other framework Free, voluntary, and globally recognized Profiles turn assessment into a real roadmap ⚠ Challenges Not prescriptive — it won’t hand you exact controls Needs a control catalog (CIS, ISO, 800-53) underneath Voluntary, so rigor depends on your discipline Tiers and profiles take judgment to apply well 09 Final Takeaway If CIS is where you start doing, CSF is where you start talking.It gives a scattered, technical topic one calm structure and a shared vocabulary — six functions that let a whole organization see its risk the same way. Master the profiles, and you can walk into any boardroom and make cybersecurity a business conversation instead of a fire alarm.