The Cybersecurity Framework - Version 1.1, released 2019
Cybersecurity Framework History
- February 2013 - Executive Order 13636: Improving Critical Infrastructure Cybersecurity
- December 2014 - Cybersecurity Enhancement Act of 2014 (P.L. 113-274)
- May 2017 - Executive Order 13800: Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure
Learn more at CSRC Topics - Cybersecurity Enhancement Act | CSRC (nist.gov)
The Cybersecurity Framework, Revision 1.1 is most recognized for its simple model, and the ease with which executives and nonfederal cloud providers have been able to grasp and implement its core functions:
Three Primary Components
- Core - Desired cybersecurity outcomes organized in a hierarchy and aligned to more detailed guidance and controls
- Profiles - Alignment of an organization’s requirements and objectives, risk appetite, and resources using the desired outcomes of the Framework Core
- Implementation Tiers - A qualitative measure of organizational cybersecurity risk management practices

As with NIST SP 800-53 rev 5, the framework is outcome-based and designed to connect many interoperable frameworks and standards.
There are 5 Functions (as compared to 20 in the 800-53), 23 Categories (as compared to 110 in 800-171, or 298 in 800-53) and leverages 6 Informative References (whereas the 800-53 has over 400).
It's smaller, easier to implement, lighter, and broadly implemented by nonfederal cloud providers.
Key Framework Attributes
Principles of Current and Future Versions of the Framework
- Common and accessible language
- Adaptable to many technologies, lifecycle phases, sectors, and uses
- Risk-based
- Based on international standards
- Living document
- Guided by many perspectives – private sector, academia, public sector

Implementation Tiers

Framework Updates
- Applicability for all system lifecycle phases
- Enhanced guidance for managing cybersecurity within supply chains and for buying decisions
- New guidance for self-assessment
- Better accounts for Authorization, Authentication, and Identity Proofing
- Incorporates emerging vulnerability information (a.k.a., Coordinated Vulnerability Disclosure)
- Administratively updates the Informative References
NIST provides continuous crosswalks that facilitate the mapping of the CSF. EnterpriseGRC Solutions participates with the Cloud Security Alliance to lead mapping between the CCM v4 and CSF v1.1. We also map the CSF to around 5 thousand CIS and DISA STIG Benchmark Rules. The CSF has known a great many success stories. Why not read a few - https://www.nist.gov/cyberframework/success-stories


A critical resource that connects to the Cybersecurity Framework is the CIS-CSC 8.1 Standard. Read More CIS Critical Security Controls Version 8


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics