◦ Reference · Framework
NIST CSF
NIST Cybersecurity Framework, currently 2.0 with the new Govern function. A voluntary framework that nonetheless becomes de-facto compliance language across many regulators and contract reviewers. Any organization that adopts it is on the hook for the control catalogue (Identify, Protect, Detect, Respond, Recover, plus Govern), and most revised regs (SEC cyber disclosure, NYDFS, HHS HPH proposed rule) now map directly into its subcategories. Attention lands on control gaps in PR.AC access control, DE.CM continuous monitoring, and RS.RP response planning.
/nist-csf