The framework organizes cybersecurity activities into functions covering governance, identification, protection, detection, response, and recovery. It provides a common vocabulary and maturity model rather than prescriptive requirements.
Version 2.0 added an explicit governance function.
Alternative Names:
NIST CSF, Cybersecurity Framework
Why it Matters?
The framework's value for legal organizations is as an assessment structure rather than a certification, since it is voluntary and produces no credential. Its function-based organization is useful for identifying gaps, particularly in detection and recovery where firms frequently invest less than in prevention. Client security questionnaires increasingly reference it, which makes familiarity useful even without formal adoption.
Frequently Confused with
Related terms
Frequently asked questions
Does the framework provide certification?
Where do legal organizations typically have gaps?





