Skip to main content

Getting Started with NIST CSF and 800-53

The National Institute of Standards and Technology (NIST) publishes two of the most widely referenced cybersecurity frameworks in the world:
  • NIST Cybersecurity Framework (CSF) 2.0 - A voluntary framework for managing and reducing cybersecurity risk, organized around six core functions. Used by organizations of all sizes and sectors.
  • NIST SP 800-53 Rev. 5 - A comprehensive catalog of security and privacy controls, primarily used by US federal agencies and their contractors. Increasingly adopted by private sector organizations seeking a rigorous control baseline.
Matproof supports both frameworks. CSF provides the strategic risk management structure, while 800-53 provides the detailed control catalog. Many organizations use CSF for governance and communication, then map specific controls from 800-53 for implementation.
Activate NIST CSF and/or NIST 800-53 under Settings - Frameworks. You can activate both - Matproof automatically maps controls between them so you avoid duplicate work.

NIST CSF 2.0 - The Six Core Functions

CSF 2.0 (released February 2024) organizes cybersecurity activities into six functions:

Govern (GV)

Establish and monitor cybersecurity risk management strategy, expectations, and policy. New in CSF 2.0.

Identify (ID)

Understand your assets, business environment, risks, and supply chain to manage cybersecurity risk.

Protect (PR)

Implement safeguards to ensure delivery of critical services.

Detect (DE)

Identify the occurrence of cybersecurity events in a timely manner.

Respond (RS)

Take action regarding a detected cybersecurity incident.

Recover (RC)

Maintain plans for resilience and restore capabilities impaired by a cybersecurity incident.
CSF 2.0 added the Govern function to emphasize that cybersecurity risk management must be integrated into enterprise risk management and driven by leadership. Start with Govern if you are building a program from scratch.

NIST 800-53 - Control Families

NIST SP 800-53 Rev. 5 contains over 1,000 controls organized into 20 families:
You do not need to implement all 1,000+ controls. Select a baseline (Low, Moderate, or High) based on your system’s security categorization (FIPS 199), then tailor controls to your environment.

Which Framework Should I Use?



CSF 2.0 Profiles and Tiers

Profiles

CSF profiles describe your organization’s current and target cybersecurity posture. Create two profiles in Matproof:
  • Current Profile - where you are today (based on your control assessment results)
  • Target Profile - where you need to be (based on risk appetite, business requirements, and regulatory obligations)
The gap between the two profiles drives your implementation roadmap.

Tiers

CSF implementation tiers describe the degree of rigor in your cybersecurity risk management:

Next Steps

  • Risk Management - risk assessments aligned to NIST methodology
  • Controls - working through CSF and 800-53 control sets
  • Incidents - incident response workflow configuration
  • Audit Programs - security assessments and continuous monitoring