NIST Cybersecurity Framework

NIST Cybersecurity Framework

NIST Cybersecurity Framework

The framework organizes cybersecurity activities into functions covering governance, identification, protection, detection, response, and recovery. It provides a common vocabulary and maturity model rather than prescriptive requirements.

Version 2.0 added an explicit governance function.

Alternative Names:

NIST CSF, Cybersecurity Framework

Why it Matters?

The framework's value for legal organizations is as an assessment structure rather than a certification, since it is voluntary and produces no credential. Its function-based organization is useful for identifying gaps, particularly in detection and recovery where firms frequently invest less than in prevention. Client security questionnaires increasingly reference it, which makes familiarity useful even without formal adoption.

Frequently Confused with

Related terms

Frequently asked questions

Does the framework provide certification?

Does the framework provide certification?

No. It is a voluntary assessment structure and maturity model rather than a certifiable standard like ISO 27001.

Where do legal organizations typically have gaps?

Where do legal organizations typically have gaps?

Detection and recovery, since security investment concentrates in prevention while response capability receives less attention.