Cybersecurity Glossary

NIST Cybersecurity Framework

A widely used structure that organises security work into six functions.

What NIST Cybersecurity Framework means

The framework groups activity under Govern, Identify, Protect, Detect, Respond and Recover. It is not a checklist and it certifies nothing. Its value is as a common structure for deciding what you have, what is missing and how to describe your position to somebody else.

Why NIST Cybersecurity Framework matters for small businesses and nonprofits

For a small organisation it provides a defensible way to prioritise without adopting a heavy certification. It is also the vocabulary many United States clients, insurers and public bodies expect you to use.

What to do about NIST Cybersecurity Framework

Three steps to deal with NIST Cybersecurity Framework

  • Score yourself honestly across the six functions and look for the weakest
  • Choose a realistic target level rather than aiming for the highest everywhere
  • Reassess annually and keep the evidence

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.