The NIST Cybersecurity Framework (CSF) is a risk-based methodology organized around five core functions, Identify, Protect, Detect, Respond, Recover (*Identifier, Protéger, Détecter, Répondre, Récupére…
The NIST Cybersecurity Framework (CSF) is a risk-based methodology organized around five core functions, Identify, Protect, Detect, Respond, Recover (Identifier, Protéger, Détecter, Répondre, Récupérer in Francophone practice), that provide a comprehensive lifecycle for managing cybersecurity risk, from governance to operational resilience. Originally released as the Framework for Improving Critical Infrastructure Cybersecurity Version 1.1 (NIST, April 2018) and referenced within COBIT 2019, it integrates confidentiality, integrity, availability, and situational awareness into a common language for business and technical stakeholders. Its layered, defense-in-depth structure ensures that if one safeguard fails, redundant controls preserve the security posture.
In Short
The Five Functions of the NIST CSF
Identify (Identifier)
This function develops an organizational understanding to manage cybersecurity risk. It covers asset management, risk assessment, governance, and strategy. Without a complete inventory of systems, data, and business dependencies, organizations cannot achieve situational awareness or prioritize defenses against advanced persistent threats (APTs). Effective identification answers the question: “What business assets and risks must we protect?”Protect (Protéger)
Protect implements safeguards to ensure the delivery of critical services. Categories include access control, awareness training, data security, information protection processes, and protective technology. Drawing on the defense-in-depth principle, often called the “castle approach”, it layers redundant defenses: if an attacker bypasses the moat, they still face ramparts, drawbridges, and battlements. Each layer independently contributes to confidentiality, integrity, and availability.Detect (Détecter)
Detect defines the activities needed to identify the occurrence of a cybersecurity event. It encompasses anomalies and events, continuous monitoring, and detection processes. Rapid detection reduces dwell time and feeds real-time situational awareness, enabling a faster pivot to response.Respond (Répondre)
Respond supports the ability to contain the impact of a detected incident. It includes response planning, communications, analysis, mitigation, and lessons learned. This function translates detection into action through documented processes and tools, ensuring that security incidents are managed rather than merely observed.Recover (Récupérer)
Recover maintains plans for resilience and restores any capabilities or services impaired by an incident. It includes recovery planning, improvements, and communications. Consistent with COBIT 2019 continuity practices, recovery plans must be tested regularly and updated through formal change control to remain suitable, adequate, and effective against actual business requirements.How the NIST CSF Aligns with Enterprise Governance
The framework does not operate in isolation. The table below maps its functions to related standards and concepts cited in COBIT 2019 and broader cybersecurity practice.
| Element | Source / Concept | Relationship to the NIST CSF |
|---|---|---|
| COBIT 2019 | Governance and management objectives (DSS04, DSS05, DSS06) | Provides process-level controls for continuity, risk, and incident management that map directly to Identify, Respond, and Recover. |
| NIST SP 800-37 Rev. 2 | Risk Management Framework (May 2018 draft) | Underpins the authorization and risk-assessment activities within the Identify function. |
| NIST SP 800-53 Rev. 5 | Security and Privacy Controls (August 2017 draft) | Supplies the control catalog used to operationalize the Protect and Detect categories. |
| CIS Controls v6.1 | Critical Security Controls (August 2016) | Offers prioritized technical safeguards, such as data recovery and penetration testing, that implement Protect and Detect requirements. |
| Defense in Depth | Layered defensive strategy (CMMI / industry practice) | A tactical pattern embedded in Protect; ensures no single point of failure by stacking moat, rampart, and battlements-style controls. |
| Business Continuity | Testing and plan maintenance (COBIT 2019 / CMMI) | Mandates regular review and change-managed updates to recovery plans, directly feeding the Recover function. |
Key Takeaways
Frequently Asked Questions
What is the difference between the NIST CSF and NIST SP 800-53?
The NIST Cybersecurity Framework provides a high-level, strategic taxonomy of five functions for managing cyber risk. NIST Special Publication 800-53 supplies a granular catalog of security and privacy controls, while SP 800-37 defines the Risk Management Framework for authorizing systems. Organizations typically use the CSF to communicate with leadership and map business risk, then use SP 800-53 and SP 800-37 to guide technical implementation.Is the NIST CSF only for critical infrastructure?
No. Although Version 1.1 (April 2018) was originally titled Framework for Improving Critical Infrastructure Cybersecurity, its risk-based structure is sector-agnostic. Private companies, government agencies, and non-profits worldwide adopt it to organize security programs, align with governance frameworks like COBIT 2019, and prioritize spending.How does “Protect” differ from “Defense in Depth”?
Protect is the CSF function that establishes safeguards. Defense in depth is the tactical principle of layering redundant mechanisms so that a single failure does not lead to compromise. Think of Protect as the organizational mandate and defense in depth as the architectural method used to fulfill it.What testing is required for the Recover function?
Resilience must be demonstrated, not assumed. Organizations should perform data-recovery drills, business-continuity tests, and penetration tests (red-team exercises). Results must feed back into plan updates managed through a formal change-control process, ensuring recovery capabilities remain aligned with actual business needs.Can the NIST CSF replace COBIT 2019?
No. COBIT 2019 provides a comprehensive system for enterprise governance and management of information and technology, including processes for continuity, risk, and security. The NIST CSF offers a cybersecurity-specific risk language. The two frameworks are complementary and frequently mapped together.How should an organization prioritize investment across the five functions?
Start with Identify. Without accurate asset inventories and risk assessments, protection spending is speculative. Next, close the highest residual-risk gaps in Protect and Detect, while maintaining minimum viable capabilities in Respond and Recover. Reassess continuously as the threat landscape and business requirements evolve.Conclusion
The NIST Cybersecurity Framework transforms cybersecurity from a static compliance exercise into a dynamic, risk-driven discipline anchored by five clear functions. By systematically working through Identify, Protect, Detect, Respond, and Recover, organizations build not just walls, but genuine resilience. To see where your organization stands and receive an AI-assisted, human-validated action plan tailored to your risk profile, take the free MaturaScore maturity diagnostic. You will leave with a concrete, prioritized roadmap grounded in your actual business context.