NIST CSF 2.0, without the spreadsheets.
Measure and improve your security programme against a common language.
What is NIST CSF 2.0?
The NIST Cybersecurity Framework is a voluntary framework for managing cybersecurity risk, used well beyond the US. Version 2.0, released in February 2024, added a Govern function and broadened the framework from critical infrastructure to organisations of any size.
Who needs it
- Organisations that want a maturity model to report to their board
- US companies whose customers or insurers reference NIST
- Teams that want a neutral framework to map other standards onto
What NIST CSF 2.0 looks at
Govern
Strategy, roles, policy and supply chain risk management — new in 2.0.
Identify and Protect
Asset management, risk assessment, access control, data security and platform security.
Detect
Continuous monitoring and analysis of adverse events.
Respond and Recover
Incident management, analysis, communication and restoring normal operations.
How Beviso gets you there
- CSF outcomes pre-loaded and evaluated against evidence from your tools
- Readiness score per function to track maturity over time
- Cross-mapping to ISO 27001 and SOC 2 so the same evidence counts everywhere
13 NIST CSF 2.0 controls, ready on day one
These controls are loaded when you enable NIST CSF 2.0, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
GV.OC-01
Organizational Mission and Cybersecurity Context
The organizational mission is understood and informs cybersecurity risk management decisions.
Evidence from
- Notion
- Ironclad
ID.AM-01
Asset Inventory — Hardware
Inventories of hardware managed by the organization are maintained.
Evidence from
- Jamf
- Kandji
- Mosyle
- SentinelOne
- DigitalOcean
- Hetzner
- AWS
ID.AM-02
Asset Inventory — Software
Inventories of software, services, and systems managed by the organization are maintained.
Evidence from
- Snyk
- GitHub
- GitLab
- Bitbucket
- Heroku
- Render
- Vercel
ID.RA-01
Vulnerability Identification
Vulnerabilities in assets are identified, validated, and recorded.
Evidence from
- Snyk
- Wiz
- Qualys
- Rapid7
- CrowdStrike
- GitHub
- SonarCloud
PR.AA-01
Identities and Credentials Management
Identities and credentials for authorized users, services, and hardware are managed.
Evidence from
- Okta
- Google Workspace
- Microsoft Azure
- JumpCloud
- OneLogin
- Auth0
- AWS
PR.AA-05
Access Rights Management
Access permissions, entitlements, and authorizations are managed, incorporating the principles of least privilege and separation of duties.
Evidence from
- Okta
- AWS
- HashiCorp Vault
- GitHub
- Microsoft Azure
PR.AA-06
Authentication — MFA
Physical and logical assets are protected through identity management and access control, with MFA for privileged users.
Evidence from
- Okta
- Duo
- Microsoft Azure
- JumpCloud
- 1Password
PR.PS-01
Configuration Management
Configuration management practices are established and applied.
Evidence from
- Terraform Cloud
- Doppler
- GitHub
- AWS
- Microsoft Azure
PR.IR-01
Network Integrity Protection
Networks and environments are protected from unauthorized logical access.
Evidence from
- Cloudflare
- DigitalOcean
- Hetzner
- AWS
DE.CM-01
Networks and Network Services Monitoring
Networks and network services are monitored to find potentially adverse events.
Evidence from
- Datadog
- Grafana
- New Relic
- Dynatrace
- Splunk
- AWS
DE.CM-09
Computing Hardware and Software Monitoring
Computing hardware and software are monitored to find potentially adverse events.
Evidence from
- CrowdStrike
- SentinelOne
- Datadog
- AWS
- Okta
RS.MA-01
Incident Management
The incident response plan is executed in coordination with relevant third parties.
Evidence from
- PagerDuty
- ServiceNow
- Jira
RC.RP-01
Recovery Plan Execution
The recovery portion of the incident response plan is executed.
Evidence from
- PagerDuty
- ServiceNow
NIST CSF 2.0 questions
- Can we be NIST CSF certified?
- No, CSF is voluntary and has no certification. Organisations use it to assess and communicate their maturity, often alongside a certifiable standard such as ISO 27001.
Often run alongside NIST CSF 2.0
Start your NIST CSF 2.0 programme today.
Free while Beviso is in beta. No credit card required.
Get started free