GOVERN
New in 2.0: anchors cyber risk in corporate governance – organizational context, risk management strategy, roles and responsibilities, policies, oversight and cybersecurity supply chain risk management.
With version 2.0, the NIST Cybersecurity Framework explicitly addresses organizations of every size and sector for the first time – and makes governance a function in its own right. VamiSec uses the CSF as a steering framework that brings ISO/IEC 27001, NIS2 and DORA together in one language.
The NIST Cybersecurity Framework (CSF) is the world's most widely used framework for structuring and communicating cyber risk. With version 2.0 (NIST CSWP 29), published on 26 February 2024, the US National Institute of Standards and Technology delivered the first full revision since the framework's inception – and expanded its scope from critical infrastructure to organizations of every size and sector.
The CSF Core is organized into six functions, 22 categories and around 106 subcategories. Organizational Profiles (current/target), Implementation Tiers (1–4) and Informative References – including mappings to ISO/IEC 27001, the CIS Controls and NIST SP 800-53 – turn it into a management instrument: free of charge, not certifiable, yet ideal for communicating maturity and priorities to boards and supervisory bodies.
GOVERN is new in version 2.0 – it wraps around the five operational functions as the governance layer.
New in 2.0: anchors cyber risk in corporate governance – organizational context, risk management strategy, roles and responsibilities, policies, oversight and cybersecurity supply chain risk management.
Creates transparency about assets, business processes and risks: what are we protecting, and which vulnerabilities and improvement opportunities exist?
Covers safeguards such as identity and access management, awareness and training, data security, platform hardening and a resilient technology infrastructure.
Ensures attacks and anomalies are found and analyzed in time – from continuous monitoring to adverse event analysis.
Structures the response to detected incidents: incident management, analysis, reporting and communication, and mitigation.
Restores systems and services after an incident – including recovery planning and transparent crisis communication with internal and external stakeholders.
The CSF does not replace regulation – it translates between regulations.
The Informative References link CSF subcategories directly to ISO/IEC 27001 controls. Your ISMS provides the evidence, the CSF the management view – ideal where certification and steering need to work together.
GOVERN mirrors the management-body accountability of NIS2 Article 20, while the operational functions cover the measures catalogue of Article 21 – from risk management to supply chain security.
For financial entities, the CSF structures ICT risk management under DORA: IDENTIFY/PROTECT for protection and prevention, DETECT/RESPOND/RECOVER for detection, response and recovery.
The CIS Controls translate CSF subcategories into prioritized technical safeguards – the fastest route from framework logic to actionable hardening.
Our approach using Organizational Profiles and Implementation Tiers.
We capture the status quo across the six functions and 22 categories – based on existing evidence, interviews and technical spot checks.
Together with management, we define the Target Profile and the intended Implementation Tier (1–4) – risk-based and aligned with your business model.
The gap between current and target profile becomes a prioritized roadmap with measures, responsibilities, budgets and quick wins.
KPIs per function, regular re-assessments and management reporting make progress visible – and keep cyber risk permanently manageable.
1GOVERN: Is cyber risk firmly anchored in your corporate governance, with clear roles and responsibilities up to executive level?
2IDENTIFY & PROTECT: Do you know all of your assets, and is baseline protection (access, patching, backups, awareness) in place across the organization?
3DETECT & RESPOND: Can you reliably detect attacks, and is your response process documented and tested in practice?
4RECOVER: Have you tested the recovery of critical systems – including well-managed communication with customers, partners and authorities?
This self-check does not replace an assessment; it provides an initial positioning along the CSF functions.
NIST primary sources and matching VamiSec services.
Concise answers for decision-makers and security leaders.
No. The CSF is a voluntary, free framework with no certification scheme. It works as a steering and communication instrument – formal evidence continues to come from standards such as ISO/IEC 27001 or regulatory audits.
The most important addition is the sixth function GOVERN, which bundles governance, strategy, roles, policies and cybersecurity supply chain risk management. The framework now also explicitly addresses all organizations – no longer just critical infrastructure – and is accompanied by Quick-Start Guides, Organizational Profiles and the CSF 2.0 Reference Tool.
A certified ISMS and the CSF complement each other: ISO/IEC 27001 provides the management system and the evidence, the CSF the function-oriented view for prioritization and board communication. The Informative References connect both worlds without duplicating work.
The CSF offers a common language: GOVERN addresses management accountability (NIS2 Article 20), while the operational functions structure the measures of NIS2 Article 21 and ICT risk management under DORA. This lets you steer multiple regulations through one consistent target picture.
We establish your Current Profile along the six functions, jointly define the Target Profile and Tier, and derive a prioritized gap roadmap. The effort depends on scope, locations and existing documentation – we scope it together in an initial consultation.
We establish your Current Profile, define targets and deliver the roadmap – pragmatic, prioritized and board-ready.