Week 2: Understanding the NIST Cybersecurity Framework
This week I focused on one of the most important cybersecurity frameworks used around the world: the NIST Cybersecurity Framework (CSF).
Week 2: Understanding the NIST Cybersecurity Framework
This week I focused on one of the most important cybersecurity frameworks used around the world: the NIST Cybersecurity Framework (CSF).
The goal of NIST CSF is to help organizations understand, manage, and improve cybersecurity risk.
What I Learned
NIST CSF Functions
The framework is built around six core functions:
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
These functions help organizations structure their cybersecurity programs.
Outcomes
One of the most interesting concepts in NIST is that it focuses on outcomes rather than specific tools.
For example:
Protect → Access is controlled.
Organizations can achieve this outcome using MFA, access controls, or other security measures.
Categories and Subcategories
I learned how NIST breaks each function into categories and subcategories.
This allows organizations to move from high-level goals to specific security activities.
Profiles
NIST Profiles help organizations understand:
- Current Profile (where we are today)
- Target Profile (where we want to be)
The difference between them is called a Gap.
Assessments
Organizations use assessments to identify strengths and weaknesses.
An assessment helps answer questions such as:
- Do we have MFA?
- Do we have logging?
- Do we have an Incident Response Plan?
Cybersecurity Maturity
I also learned how organizations measure cybersecurity maturity.
A mature organization not only has controls but continuously improves them over time.
Key Takeaway
The most important lesson this week is that cybersecurity frameworks provide structure.
They help organizations understand risks, prioritize improvements, and build stronger security programs.
As I continue my journey in GRC and cybersecurity governance, NIST CSF is becoming one of the most valuable frameworks I have studied so far.
Cybersecurity #NIST #GRC #Governance #RiskManagement #Compliance
메타데이터
- post_id
- 79f47f615152
- slug
- week-2-understanding-the-nist-cybersecurity-framework-79f47f615152
- url
- https://medium.com/@asadgulyamov09/week-2-understanding-the-nist-cybersecurity-framework-79f47f615152
- canonical_url
- https://medium.com/@asadgulyamov09/week-2-understanding-the-nist-cybersecurity-framework-79f47f615152
- author_url
- https://medium.com/@asadgulyamov09
- status
- ok
- fetched_at
- 2026-06-20 20:29:01