NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover
NIST CSF is not a control checklist, and treating it like one misses most of its value. It is a governance and maturity language that lets very different teams -- engineering, IT, legal, executive leadership -- talk about the same cybersecurity program using a shared vocabulary.
Version 2.0 added Govern as an explicit function sitting above the original five (Identify, Protect, Detect, Respond, Recover), reflecting a hard-won lesson from a decade of incidents: programs that had good technical controls but no real governance -- no clear roles, no risk appetite statement, no supply chain oversight -- still failed. Govern covers organizational context, risk management strategy, roles and responsibilities, policy, and oversight of third-party and supply chain risk.
Identify is about knowing what you have and what matters -- asset inventories, business context, and risk assessment. Protect is the safeguards that limit or contain a potential incident. Detect is your ability to notice that something is happening. Respond is your capability to act once you know. Recover is your ability to restore normal operations and capture lessons learned.
For a critical infrastructure operator, the practical value of CSF is as a maturity lens: it lets you say, honestly, "we are strong in Protect but weak in Detect," and prioritize investment accordingly, rather than spreading effort evenly across a function list without ever asking which function is actually the current bottleneck.
Reading
6 minutes