Onwyn › Standards › NIST Cybersecurity Framework 2.0

Scheme / framework · 2.0

NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework 2.0, published February 2024, organises cybersecurity outcomes into six functions, 22 categories and 106 subcategories. It is not a certifiable standard and there is no NIST audit: it is a way of describing where you are and where you intend to be, and it is increasingly what a US or international customer means when they ask for your security posture. Version 2.0 added GOVERN as a sixth function, moving governance and supply-chain risk from an afterthought to the frame everything else sits in. This pack works at category level, which is the granularity at which most organisations actually make decisions; the 106 subcategories sit underneath and are referenced where they carry weight. Use it to build a Current Profile and a Target Profile — the gap between them is the plan.

24
Requirements
7
Areas
14
Recommended documents
0
Mapped frameworks
Start NIST Cybersecurity Framework 2.0 free Have us do it instead

What this standard asks for

Every requirement in NIST Cybersecurity Framework 2.0, grouped the way the standard groups them. In the Semantic Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

GOVERN — strategy, expectations and policy

6 requirements

  • GV.OCOrganizational Context
  • GV.RMRisk Management Strategy
  • GV.RRRoles, Responsibilities and Authorities
  • GV.POPolicy
  • GV.OVOversight
  • GV.SCCybersecurity Supply Chain Risk Management

IDENTIFY — understand the risk

3 requirements

  • ID.AMAsset Management
  • ID.RARisk Assessment
  • ID.IMImprovement

PROTECT — safeguards

5 requirements

  • PR.AAIdentity Management, Authentication and Access Control
  • PR.ATAwareness and Training
  • PR.DSData Security
  • PR.PSPlatform Security
  • PR.IRTechnology Infrastructure Resilience

DETECT — find what is happening

2 requirements

  • DE.CMContinuous Monitoring
  • DE.AEAdverse Event Analysis

RESPOND — act on it

4 requirements

  • RS.MAIncident Management
  • RS.ANIncident Analysis
  • RS.COIncident Response Reporting and Communication
  • RS.MIIncident Mitigation

RECOVER — restore

2 requirements

  • RC.RPIncident Recovery Plan Execution
  • RC.COIncident Recovery Communication

Profiles and tiers

2 requirements

  • PROF.1Establish the Current Profile
  • PROF.2Set the Target Profile and the tier

The documents you will end up with

The recommended document set for NIST Cybersecurity Framework 2.0 — 14 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

Cybersecurity Policy

The organisational policy the GOVERN function expects, establishing expectations and authority.

Cybersecurity Risk Management Strategy

Risk appetite, tolerance statements and how cybersecurity risk is weighed against other enterprise risk.

Roles and Responsibilities Matrix

Who is accountable for what, from the board to the operator.

Cybersecurity Supply Chain Risk Management Policy

How supplier risk is assessed, contracted for, monitored and ended — the GV.SC category in full.

Asset and Data Inventory

Hardware, software, services, data and their criticality — the base every other function depends on.

Identity and Access Control Policy

Identity lifecycle, authentication strength and authorisation.

Security Awareness and Training Programme

Role-based training and the awareness cycle.

Data Security Standard

Protection of data at rest, in transit and in use, matched to classification.

Platform Security Standard

Configuration, maintenance and hardening of hardware, software and services.

Resilience Architecture Standard

How infrastructure is designed to withstand and adapt to adverse events.

Monitoring and Detection Standard

What is monitored, how events are analysed, and what constitutes an incident.

Incident Response Plan

Management, analysis, communication and mitigation of incidents.

Incident Recovery Plan

Restoration of assets and operations, and the communication that goes with it.

Current and Target Profile

Where you are, where you intend to be, and the prioritised gap between them.

Start NIST Cybersecurity Framework 2.0 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.