Purpose
The framework provides common language for cybersecurity outcomes without requiring one technology stack, organization size, or implementation method.
Core functions
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
Profiles and priorities
Organizations can use profiles to describe current and target outcomes, compare gaps, assign ownership, and connect cybersecurity work to mission and business needs.
Use with other sources
The framework can organize outcomes while standards, control catalogs, technical guidance, laws, contracts, and sector requirements provide more detailed expectations.
BMC v0.2.2 cornerstone expansion
Start analysis of NIST Cybersecurity Framework with the mission or business outcome, then identify assets, identities, data, trust boundaries, dependencies, expected behavior, and credible failure or abuse cases.
Translate those observations into preventive, detective, responsive, and recovery controls. A mature explanation states not only what the concept is, but also how a practitioner demonstrates that it is working under normal, abnormal, and recovery conditions.
Evidence of effective implementation
- Documented ownership, scope, decision criteria, and permitted exceptions.
- Configuration or architectural evidence tied to a clear control objective.
- Operational telemetry showing expected and unexpected behavior.
- Testing that covers normal use, abuse cases, failure, rollback, and recovery.
- Exceptions that are approved, time bounded, monitored, and revisited.
- Lessons learned that result in updated designs, procedures, detections, or training.
Questions for learners
- Which security properties and business outcomes does NIST Cybersecurity Framework support?
- What assumptions must remain true for the control or process to work safely?
- What could an attacker, insider, failure, or design error do at each trust boundary?
- Which evidence would prove that controls work continuously rather than only on paper?
- How would the organization respond, restore service, and re-establish trust after failure?
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: