Security · Tech Notes

NIST updates its Cybersecurity Framework

NIST released version 2.0 of its Cybersecurity Framework. Here's what changed and how Macktez uses it to assess risk and guide security work for clients.

June 6, 2024

The National Institute of Standards and Technology (NIST) has set standards for weights, measurements, material composition, and other benchmarks in science, technology, and industry since the start of the 20th century. Today, some of its most important work is in artificial intelligence, cryptography, and cybersecurity.

NIST recently published version 2.0 of its Cybersecurity Framework (CSF). Originally released in 2014 and aimed primarily at critical infrastructure facilities like airports, dams, and nuclear power plants, the CSF now applies more broadly to organizations of all sizes and functions.

What CSF 2.0 sets out to do

The main goals of CSF 2.0 are:

  • Give organizations a framework for reviewing their appetite and tolerance for risk, and for managing risk in the context of cybersecurity.
  • Provide examples of best practices so organizations can evaluate their current cybersecurity controls and set a target for improvement.
  • Promote continuous improvement by encouraging organizations to regularly assess cybersecurity risks and update their plans.

How to use the Cybersecurity Framework

The framework helps any organization understand its own cybersecurity resources and goals. Macktez uses it as the foundation for our cybersecurity assessment and to guide the security recommendations we make for clients.

We also use the framework to measure the managed services tools we rely on to support many of our clients, and to bundle new services that fulfill specific cybersecurity goals.

For example, the most important CSF categories can be covered by our Core Suite of tools, including Identity Management and Workstation Management. Others are addressed by projects we regularly recommend and manage, such as Password Management, Disaster Recovery Plan Development, and Access Control Solutions. More generally, engaging Macktez as a Virtual CIO/CTO gives any organization the experience to evaluate individual cybersecurity metrics and address them as needed.

Our Cybersecurity Assessment

We've boiled NIST's framework down to a series of yes / no questions that clients can answer themselves to start assessing risk tolerance and reviewing current controls. There are no right or wrong answers — in fact, we expect most organizations going through this process for the first time to answer "no" or "I don't know" to many or even most questions. That's fine. These answers start an important process: highlighting an organization's current cybersecurity profile, identifying goals, and prompting Macktez for recommendations to meet them.

Learn more about our Cybersecurity Assessment.

Work With Us

Have a project like this on the horizon?

If something here maps to what your organization is facing, let's talk it through — no pitch deck, just a senior technical perspective on your situation.