The National Institute of Standards and Technology ([[National Institute of Standards and Technology|NIST]]) is a U.S.-based agency that develops multiple voluntary compliance [[Security Frameworks|framework]] that organisations worldwide can use to help manage risk. The more aligned an organisation is with compliance, the lower the risk. The framework consists of three main components: the **core**, **tiers**, and **profiles** #### Core ![[CSF.png|500]] There are 5 core functions: - **Identify** - The management of cybersecurity risk and its effect on an organisation's people and assets - **Protect** - The strategy used to protect an organisation through the implementation of policies, procedures, training, and tools that help mitigate cybersecurity threats. - **Detect** - Identifying potential security incidents and improving monitoring capabilities to increase the speed and efficiency of detections. - **Respond** - Making sure that the proper procedures are used to contain, neutralise, and analyse security incidents, and implement improvements to the security process. - **Recovery** - The process of returning affected systems back to normal operation. #### Tiers The CSF tiers are a way of measuring the sophistication of an organisation's cybersecurity program. CSF tiers are measured on a **scale of 1 to 4**. Tier *1 is the lowest score*, indicating that a limited set of security controls have been implemented. Overall, CSF tiers are used to assess an organisation's security posture and identify areas for improvement. #### Profiles The CSF profiles are pre-made templates of the NIST CSF that are developed by a team of industry experts. CSF profiles are tailored to address the specific risks of an organisation or industry. They are used to help organisations develop a baseline for their cybersecurity plans, or as a way of comparing their current cybersecurity posture to a specific industry standard. ### Implementing the CSF In any scenario, the U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) provides detailed guidance that any organisation can use to implement the CSF. This is a quick overview and summary of their recommendations: - *Create a current profile* of the security operations and outline the specific needs of your business. - *Perform a risk assessment* to identify which of your current operations are meeting business and regulatory standards. - *Analyse and prioritise existing gaps* in security operations that place the businesses assets at risk. - *Implement a plan of action* to achieve your organisation’s goals and objectives.