The 6 CSF functions — Govern, Identify, Protect, Detect, Respond, Recover — and how to run a maturity self-assessment against them.
The NIST Cybersecurity Framework (CSF) 2.0 is the most widely adopted voluntary framework for organizing a cybersecurity program, structured around six functions: Govern (new in 2.0, covering strategy and oversight), Identify, Protect, Detect, Respond, and Recover. This module covers what each function actually requires in practice, how CSF profiles let an organization compare its current state to a target state, and how the four-tier maturity model (Partial through Adaptive) is scored.
By the end of this module you should be able to run a basic CSF self-assessment for an organization and identify its weakest function — the exact exercise the studio's live NIST CSF 2.0 Assessment Tool automates, and the framework Module 15's documentation kit includes a checklist template for.