Framework · US

NIST CSF 2.0, without the spreadsheets.

Measure and improve your security programme against a common language.

What is NIST CSF 2.0?

The NIST Cybersecurity Framework is a voluntary framework for managing cybersecurity risk, used well beyond the US. Version 2.0, released in February 2024, added a Govern function and broadened the framework from critical infrastructure to organisations of any size.

Who needs it

  • Organisations that want a maturity model to report to their board
  • US companies whose customers or insurers reference NIST
  • Teams that want a neutral framework to map other standards onto

What NIST CSF 2.0 looks at

Govern

Strategy, roles, policy and supply chain risk management — new in 2.0.

Identify and Protect

Asset management, risk assessment, access control, data security and platform security.

Detect

Continuous monitoring and analysis of adverse events.

Respond and Recover

Incident management, analysis, communication and restoring normal operations.

How Beviso gets you there

  • CSF outcomes pre-loaded and evaluated against evidence from your tools
  • Readiness score per function to track maturity over time
  • Cross-mapping to ISO 27001 and SOC 2 so the same evidence counts everywhere

13 NIST CSF 2.0 controls, ready on day one

These controls are loaded when you enable NIST CSF 2.0, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

GV.OC-01

Organizational Mission and Cybersecurity Context

The organizational mission is understood and informs cybersecurity risk management decisions.

Evidence from

  • Notion
  • Ironclad

ID.AM-01

Asset Inventory — Hardware

Inventories of hardware managed by the organization are maintained.

Evidence from

  • Jamf
  • Kandji
  • Mosyle
  • SentinelOne
  • DigitalOcean
  • Hetzner
  • AWS

ID.AM-02

Asset Inventory — Software

Inventories of software, services, and systems managed by the organization are maintained.

Evidence from

  • Snyk
  • GitHub
  • GitLab
  • Bitbucket
  • Heroku
  • Render
  • Vercel

ID.RA-01

Vulnerability Identification

Vulnerabilities in assets are identified, validated, and recorded.

Evidence from

  • Snyk
  • Wiz
  • Qualys
  • Rapid7
  • CrowdStrike
  • GitHub
  • SonarCloud

PR.AA-01

Identities and Credentials Management

Identities and credentials for authorized users, services, and hardware are managed.

Evidence from

  • Okta
  • Google Workspace
  • Microsoft Azure
  • JumpCloud
  • OneLogin
  • Auth0
  • AWS

PR.AA-05

Access Rights Management

Access permissions, entitlements, and authorizations are managed, incorporating the principles of least privilege and separation of duties.

Evidence from

  • Okta
  • AWS
  • HashiCorp Vault
  • GitHub
  • Microsoft Azure

PR.AA-06

Authentication — MFA

Physical and logical assets are protected through identity management and access control, with MFA for privileged users.

Evidence from

  • Okta
  • Duo
  • Microsoft Azure
  • JumpCloud
  • 1Password

PR.PS-01

Configuration Management

Configuration management practices are established and applied.

Evidence from

  • Terraform Cloud
  • Doppler
  • GitHub
  • AWS
  • Microsoft Azure

PR.IR-01

Network Integrity Protection

Networks and environments are protected from unauthorized logical access.

Evidence from

  • Cloudflare
  • DigitalOcean
  • Hetzner
  • AWS

DE.CM-01

Networks and Network Services Monitoring

Networks and network services are monitored to find potentially adverse events.

Evidence from

  • Datadog
  • Grafana
  • New Relic
  • Dynatrace
  • Splunk
  • AWS

DE.CM-09

Computing Hardware and Software Monitoring

Computing hardware and software are monitored to find potentially adverse events.

Evidence from

  • CrowdStrike
  • SentinelOne
  • Datadog
  • AWS
  • Okta

RS.MA-01

Incident Management

The incident response plan is executed in coordination with relevant third parties.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira

RC.RP-01

Recovery Plan Execution

The recovery portion of the incident response plan is executed.

Evidence from

  • PagerDuty
  • ServiceNow

NIST CSF 2.0 questions

Can we be NIST CSF certified?
No, CSF is voluntary and has no certification. Organisations use it to assess and communicate their maturity, often alongside a certifiable standard such as ISO 27001.

Start your NIST CSF 2.0 programme today.

Free while Beviso is in beta. No credit card required.

Get started free