Skip to Content
NIST CSF 2.0 - Your essential introduction to managing cybersecurity risks
book

NIST CSF 2.0 - Your essential introduction to managing cybersecurity risks

by Andrew Pattison
February 2025
Beginner to intermediate content levelBeginner to intermediate
94 pages
1h 27m
English
IT Governance Publishing
Content preview from NIST CSF 2.0 - Your essential introduction to managing cybersecurity risks

CHAPTER 5: RISK MANAGEMENT

The CSF is a risk-based cybersecurity framework. It does not expect organizations to invest in defenses they do not need, or to have sophisticated and expensive defenses for low-level risks.

The core also respects general risk management processes, which are:

1. Identifying risks

2. Determining the level of risk in terms of impact and likelihood/frequency

3. Comparing those risks to the organization’s risk appetite (risk tolerance)

4. Determining an appropriate response to the level and type of risk

Methodologies

There are several methodologies an organization can apply in assessing and managing its risks, which generally fall into two schools:

1. Asset-based assessments: An asset-based risk assessment examines the ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

The Cyber Security Handbook – Prepare for, respond to and recover from cyber attacks

The Cyber Security Handbook – Prepare for, respond to and recover from cyber attacks

Alan Calder

Publisher Resources

ISBN: 9781787785687Publisher Website