NIST CSF 2.0 Poster & Cheat-Sheet
One printable page — the six Functions, key Categories and the four Tiers. Open the interactive toolkit →
NIST Cybersecurity Framework 2.0
Six Functions · key Categories · four Implementation Tiers
PlayCISO
playciso.com
Govern (GV)
Set and monitor the strategy, expectations and policy for managing cyber risk.
- GV.OCOrganizational Context
- GV.RMRisk Management Strategy
- GV.RRRoles, Responsibilities & Authorities
- GV.POPolicy
- GV.OVOversight
- GV.SCSupply Chain Risk Management
Identify (ID)
Understand the assets, risks and improvements that matter to the organization.
- ID.AMAsset Management
- ID.RARisk Assessment
- ID.IMImprovement
Protect (PR)
Put safeguards in place to manage the organization’s cybersecurity risks.
- PR.AAIdentity, Authentication & Access Control
- PR.ATAwareness & Training
- PR.DSData Security
- PR.PSPlatform Security
- PR.IRTechnology Infrastructure Resilience
Detect (DE)
Find and analyze possible cyberattacks and compromises in a timely way.
- DE.CMContinuous Monitoring
- DE.AEAdverse Event Analysis
Respond (RS)
Take action once a cybersecurity incident is detected.
- RS.MAIncident Management
- RS.ANIncident Analysis
- RS.COResponse Reporting & Communication
- RS.MIIncident Mitigation
Recover (RC)
Restore assets and operations affected by a cybersecurity incident.
- RC.RPRecovery Plan Execution
- RC.CORecovery Communication
Implementation Tiers
Tier 1 · Partial
Ad hoc, reactive. Risk is managed inconsistently and awareness is limited.
Tier 2 · Risk Informed
Practices are approved but not organization-wide; risk awareness exists without a repeatable process.
Tier 3 · Repeatable
Formal policy, consistently applied and updated as risk and business change.
Tier 4 · Adaptive
Continuously improving, evidence-driven, and adapting to a changing threat landscape.
Govern (GV) sits at the centre — it informs and is informed by the other five Functions.Free tools at playciso.com/tools/nist-csf-toolkit