Skip to content
Oluma Cyber Security Awareness
Framework · Risk Management

The NIST Cybersecurity Framework

A common language for cyber risk — six functions that turn “are we secure?” into a conversation everyone from the server room to the boardroom can actually have.

v2.0 · Feb 20246 Functions22 Categories106 Subcategories
01 The Problem

Security couldn’t talk to the business

For years, security teams and the people who funded them spoke different languages. Engineers talked in firewalls and CVEs; executives asked, “Are we okay?” and got an answer they couldn’t evaluate. There was no shared way to describe where an organization stood, or to explain cyber risk to a board, a regulator, or an insurer.

Every organization was also inventing its own vocabulary. Two companies could have identical gaps and describe them in completely different words — which made it nearly impossible to compare, benchmark, or communicate risk across an industry.

03 The Story Behind It

From critical infrastructure to a global default

2014 · v1.0
Born for critical infrastructure
Released under Executive Order 13636 with five core functions — Identify, Protect, Detect, Respond, Recover — aimed at power, water, finance, and other essential sectors.
2018 · v1.1
Supply chain & self-assessment
Added guidance on supply-chain risk and on measuring your own program, as adoption spread far beyond the original infrastructure audience.
2024 · v2.0
Governance joins, scope goes global
Published February 26, 2024. A sixth function — Govern — was added, and the framework was explicitly rewritten for any organization, in any sector, in any country. It is now used in 185+ nations.
04 How It Works

6 functions, 22 categories, 106 outcomes

The framework nests in three layers. Six Functions break into 22 Categories, which break into 106 Subcategories — the specific outcomes you actually work toward. Version 2.0’s headline change is the new Govern function, which pulls governance, supply chain, and enterprise risk up to sit as a peer beside the rest.

Govern ★ newIdentifyProtectDetectRespondRecover

Two more tools make it usable. Implementation Tiers (Partial → Risk-Informed → Repeatable → Adaptive) describe how mature your practices are. Profiles capture where you are today (Current) versus where you want to be (Target) — and the gap between them is your roadmap.

The Core
Functions → outcomes
Govern, Identify, Protect, Detect, Respond, Recover — broken into 22 categories and 106 outcome statements.
Tiers
How mature you are
Four tiers from Partial to Adaptive describe how consistently and deliberately you manage cyber risk.
Profiles
Current vs. Target
Two snapshots — what you do now and what you intend to do — that turn the framework into a prioritized improvement plan and a board-ready story.
Framework vs. Controls

CSF tells you what outcomes to reach; it deliberately doesn’t hand you the exact settings. For the how, you map its outcomes to a control catalog like CIS Controls, ISO 27001, or NIST 800-53. CSF is the map; those are the terrain.

06 Who Uses It

The most widely adopted framework in the world

🏢
Every sector
Finance, healthcare, energy, education, manufacturing — the original critical-infrastructure focus has gone fully cross-industry.
🌎
Global & government
Used in 185+ countries and referenced across U.S. federal expectations, from the SEC to sector regulators.
🧭
Boards & insurers
A shared vocabulary that leadership, auditors, and cyber-insurance underwriters all recognize.

Its reach comes from translation: CSF maps to almost everything else, so one profile can drive many obligations at once.

maps to ISO 27001NIST 800-53CIS ControlsHIPAAPCI DSSSOC 2
07 Career Relevance

The lingua franca of GRC

If CIS teaches you to do, CSF teaches you to communicate — and communication is what gets GRC professionals into the room where decisions happen. Knowing CSF means you can run a gap assessment and then explain it to executives without losing them.

GRC analyst
Profiles & gaps
Build current/target profiles, score maturity by tier, and produce the roadmap leadership signs off on.
vCISO / manager
Board reporting
Turn technical posture into six functions and a risk narrative any executive can act on.
Auditor / consultant
A universal crosswalk
Because CSF maps to nearly every other framework, it’s the hub you translate between ISO, 800-53, and CIS engagements.

“Fluent in NIST CSF” signals you can carry security from the console to the boardroom — a rare and well-paid skill.

09 Final Takeaway

If CIS is where you start doing, CSF is where you start talking.

It gives a scattered, technical topic one calm structure and a shared vocabulary — six functions that let a whole organization see its risk the same way. Master the profiles, and you can walk into any boardroom and make cybersecurity a business conversation instead of a fire alarm.