NIST CSF 2.0.
Released in 2024, NIST CSF 2.0 is the updated U.S. National Institute of Standards and Technology cybersecurity framework. Adds the Govern function to the original five (Identify, Protect, Detect, Respond, Recover) and covers 106 subcategories.
NIST CSF 2.0 is the assessment framework most U.S. federal contractors and many regulated industries (financial services, healthcare, critical infrastructure) align to. The 2.0 revision added a sixth function — Govern — recognizing that the previous five (Identify, Protect, Detect, Respond, Recover) skipped over the executive oversight and risk-management practices that determine whether a security program is sustained. Each of the 106 subcategories has informative references that map to other frameworks (ISO 27001, COBIT, CIS Controls), making CSF 2.0 a useful Rosetta Stone when you have to satisfy multiple frameworks at once.
Connected concepts.
ISO 27001:2022
International information security standardThe 2022 revision of ISO’s information security management system (ISMS) standard. Widely used outside North America and increasingly required by European and Asian enterprise buyers. Includes 93 controls across 4 themes.
SOC 2
Service Organization Control 2A security framework developed by the AICPA that defines how service organizations should handle customer data based on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. Most enterprise buyers require vendors to be SOC 2 compliant.
Need help with NIST CSF 2.0?
We do this work every day for Canadian teams. Book a free 30-minute consultation.
Talk to MALTO Cyber →