The National Institute of Standards and Technology ([[National Institute of Standards and Technology|NIST]]) is a U.S.-based agency that develops multiple voluntary compliance [[Security Frameworks|framework]] that organisations worldwide can use to help manage risk. The more aligned an organisation is with compliance, the lower the risk.
The framework consists of three main components: the **core**, **tiers**, and **profiles**
#### Core
![[CSF.png|500]]
There are 5 core functions:
- **Identify** - The management of cybersecurity risk and its effect on an organisation's people and assets
- **Protect** - The strategy used to protect an organisation through the implementation of policies, procedures, training, and tools that help mitigate cybersecurity threats.
- **Detect** - Identifying potential security incidents and improving monitoring capabilities to increase the speed and efficiency of detections.
- **Respond** - Making sure that the proper procedures are used to contain, neutralise, and analyse security incidents, and implement improvements to the security process.
- **Recovery** - The process of returning affected systems back to normal operation.
#### Tiers
The CSF tiers are a way of measuring the sophistication of an organisation's cybersecurity program. CSF tiers are measured on a **scale of 1 to 4**. Tier *1 is the lowest score*, indicating that a limited set of security controls have been implemented. Overall, CSF tiers are used to assess an organisation's security posture and identify areas for improvement.
#### Profiles
The CSF profiles are pre-made templates of the NIST CSF that are developed by a team of industry experts. CSF profiles are tailored to address the specific risks of an organisation or industry. They are used to help organisations develop a baseline for their cybersecurity plans, or as a way of comparing their current cybersecurity posture to a specific industry standard.
### Implementing the CSF
In any scenario, the U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) provides detailed guidance that any organisation can use to implement the CSF. This is a quick overview and summary of their recommendations:
- *Create a current profile* of the security operations and outline the specific needs of your business.
- *Perform a risk assessment* to identify which of your current operations are meeting business and regulatory standards.
- *Analyse and prioritise existing gaps* in security operations that place the businesses assets at risk.
- *Implement a plan of action* to achieve your organisation’s goals and objectives.