May 20265 min read
GOVERNANCE

NIST CSF 2.0 put security on the leadership agenda. Here is how to use it there

The 2024 update added a sixth function, Govern. It is the most useful change for smaller organisations, because it answers the question boards actually ask: who owns this?

Boards ask a simple question — how secure are we? — and usually receive an answer in somebody else’s vocabulary. A managed service provider’s dashboard, an insurer’s questionnaire, a vendor’s maturity score. None of them line up, and none of them can be compared year on year.

What changed in version 2.0

NIST published the Cybersecurity Framework 2.0 in February 2024. It kept the five familiar functions — Identify, Protect, Detect, Respond, Recover — and added a sixth, Govern, which covers strategy, roles and responsibilities, policy, oversight and supply-chain risk. It also widened its intended audience from critical infrastructure to organisations of every size.

“Govern answers the question every board is really asking: who owns this, and how would we know if it was going wrong?”

Profiles and tiers, in plain terms

A current profile describes what you do today against each outcome in the framework. A target profile describes what you want to do. The gap between them is your roadmap. Tiers describe how rigorous your approach is overall, from partial to adaptive. None of this requires a big programme; for a smaller organisation, it can fit on one page.

Related engagement A maturity baseline the board could actually read →

How to report it

Show the six functions, current and target tier for each, and the three things that will move the most in the next quarter, each with an owner. Repeat it every quarter in the same format. The value is not the score; it is the comparison.

For the technical detail underneath, the CIS Controls v8.1 give concrete safeguards that map onto CSF outcomes. Implementation Group 1 is a practical first target for most smaller organisations.

TL;DR

The short version

CSF 2.0 added Govern

Strategy, roles, policy, oversight and supply-chain risk are now an explicit function.

It is for every size

Version 2.0 widened its audience well beyond critical infrastructure.

Profiles show the gap

Current versus target profile is your roadmap, and it can fit on one page.

Report the same way every quarter

Six functions, two tiers each, three priorities with owners.

Comparison is the point

A repeatable picture beats a single impressive score.

CIS Controls fill in the detail

Implementation Group 1 is a practical first target underneath CSF.

Written by

The Penspy team

Testers and auditors · Penspy Cyber Security

Written by the people who do the testing and the audits, from what we actually find in the work. No vendor sponsorship, no product to sell you at the end.

Send us a note