Loading Vaultize
Skip to main content

Compliance/Security frameworks/NIST CSF 2.0

Six Functions. One question: what does the file prove?

NIST CSF 2.0 describes outcomes, not products. Vaultize adds the records that stay with the data.

GVIDPRDERSRC
GVGovern2 outcomes
Read againstThe NIST Cybersecurity Framework (CSF) 2.0NIST CSWP 29 · 26 February 2024
  • Voluntary framework
  • Capability mapping, not certification
  • NIST CSWP 29 · 26 Feb 2024
16of 106 CSF 2.0 outcomes

The answer in 30 seconds

Vaultize adds file-level records to 16 Subcategories across all six Functions. The other 90 belong to identity, network, endpoint, people and governance controls.

The framework in one view

Six Functions. One wheel. Where file evidence lands.

NIST draws the Functions as a wheel. Govern sits at the centre. Select a Function to see which outcomes a governed file can evidence.

IDIDENTIFYPRPROTECTDEDETECTRSRESPONDRCRECOVERGVGOVERN

“GOVERN is in the center of the wheel because it informs how an organization will implement the other five Functions.”

GV · CORE

Govern

“The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored”

NIST CSWP 29

Outcomes the file can evidence

How Vaultize contributes
One policy engine applies the organisation’s rules to each file. Rules come from user, organisation, context, discovery and classification. They keep applying to copies held by suppliers.
Evidence to retain
Policy definitions and changes. Classification triggers. Recipient and third-party access records.

Outcome by outcome

What each outcome asks. What the file can answer.

Subcategory wording is quoted from NIST CSWP 29. Each row is a capability mapping, not a certification. Every row sits inside the organisation’s wider programme.

Using this page

Where these rows fit in a CSF Organizational Profile.

NIST describes five steps for an Organizational Profile. This page is evidence for step three.

  1. 1

    Scope the Profile

    Document the facts and assumptions it rests on.

  2. 2

    Gather the information

    Policies, risk priorities, resources and the tools in use.

  3. 3

    Create the Profile

    Record the current state of each outcome. This page is the data-level part of that record.

    Bring the sixteen rows above as current-state evidence for data-level outcomes.

  4. 4

    Analyze the gaps

    Compare Current and Target Profiles. Create an action plan.

  5. 5

    Implement and update

    Follow the plan. Revise the Profile as the programme moves.

Responsibility boundary

Controls support outcomes. They do not certify them.

Vaultize contributes technical controls and evidence to a wider NIST CSF 2.0 programme. It does not certify or attest. It does not determine applicability, replace governance or policy, give legal advice, or guarantee compliance. Read the current framework and obtain qualified advice before relying on this page.

“The CSF does not prescribe how outcomes should be achieved.”

NIST CSWP 29, 26 February 2024

A practical next step

Bring one outcome and one sensitive workflow.

We will show which Subcategories the governed file can evidence today. We will name the control owner responsible for the rest.

Request a compliance mapping session