Skip to Content
NIST CSF 2.0 - Your essential introduction to managing cybersecurity risks
book

NIST CSF 2.0 - Your essential introduction to managing cybersecurity risks

by Andrew Pattison
February 2025
Beginner to intermediate content levelBeginner to intermediate
94 pages
1h 27m
English
IT Governance Publishing
Content preview from NIST CSF 2.0 - Your essential introduction to managing cybersecurity risks

CHAPTER 6: IMPLEMENTING THE FRAMEWORK

Version 2.0 of the CSF does not provide a formal implementation process, preferring instead to let the implementing organization decide how best to approach the project. However, the seven-step process provided in CSF version 1.1 remains a valid and appropriate way of implementing the framework for organizations that are not sure where to begin.

The seven-step implementation process is:

1. Determine objectives, priorities, and scope

2. Identify assets and risks

3. Create a current profile

4. Conduct a risk assessment

5. Create a target profile

6. Perform a gap analysis and develop an action plan

7. Implement the action plan

Step 1: Determine objectives, priorities, and scope

First, the organization identifies ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

The Cyber Security Handbook – Prepare for, respond to and recover from cyber attacks

The Cyber Security Handbook – Prepare for, respond to and recover from cyber attacks

Alan Calder

Publisher Resources

ISBN: 9781787785687Publisher Website