Getting Started with NIST CSF and 800-53
The National Institute of Standards and Technology (NIST) publishes two of the most widely referenced cybersecurity frameworks in the world:- NIST Cybersecurity Framework (CSF) 2.0 - A voluntary framework for managing and reducing cybersecurity risk, organized around six core functions. Used by organizations of all sizes and sectors.
- NIST SP 800-53 Rev. 5 - A comprehensive catalog of security and privacy controls, primarily used by US federal agencies and their contractors. Increasingly adopted by private sector organizations seeking a rigorous control baseline.
Activate NIST CSF and/or NIST 800-53 under Settings - Frameworks. You can activate both - Matproof automatically maps controls between them so you avoid duplicate work.
NIST CSF 2.0 - The Six Core Functions
CSF 2.0 (released February 2024) organizes cybersecurity activities into six functions:Govern (GV)
Establish and monitor cybersecurity risk management strategy, expectations, and policy. New in CSF 2.0.
Identify (ID)
Understand your assets, business environment, risks, and supply chain to manage cybersecurity risk.
Protect (PR)
Implement safeguards to ensure delivery of critical services.
Detect (DE)
Identify the occurrence of cybersecurity events in a timely manner.
Respond (RS)
Take action regarding a detected cybersecurity incident.
Recover (RC)
Maintain plans for resilience and restore capabilities impaired by a cybersecurity incident.
NIST 800-53 - Control Families
NIST SP 800-53 Rev. 5 contains over 1,000 controls organized into 20 families:You do not need to implement all 1,000+ controls. Select a baseline (Low, Moderate, or High) based on your system’s security categorization (FIPS 199), then tailor controls to your environment.
Which Framework Should I Use?
Recommended Implementation Plan
CSF 2.0 Profiles and Tiers
Profiles
CSF profiles describe your organization’s current and target cybersecurity posture. Create two profiles in Matproof:- Current Profile - where you are today (based on your control assessment results)
- Target Profile - where you need to be (based on risk appetite, business requirements, and regulatory obligations)
Tiers
CSF implementation tiers describe the degree of rigor in your cybersecurity risk management:Next Steps
- Risk Management - risk assessments aligned to NIST methodology
- Controls - working through CSF and 800-53 control sets
- Incidents - incident response workflow configuration
- Audit Programs - security assessments and continuous monitoring