The NIST Cybersecurity Framework (CSF) is a voluntary framework from the US National Institute of Standards and Technology for organizing and improving cybersecurity work, structured in CSF 2.0 around six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is not a certification but a common language: boards, auditors and insurers worldwide use it to ask "where are you?" The framework is published by NIST.
Key facts:
- CSF 2.0 (2024) added Govern as a sixth function, elevating risk ownership and supply chain governance.
- The framework is descriptive, not prescriptive: it maps what good looks like and lets organizations choose controls (often from ISO 27001 or CIS) to get there.
- Its language dominates security questionnaires and cyber insurance applications even outside the US.
The six functions through the email lens
Email touches five of six directly: Identify (knowing which apps and OAuth grants exist, including shadow IT), Protect (blocking phishing and BEC at the top attack vector), Detect (anomalies in messages and account behavior), Respond (incident evidence: who, what, when, scope) and Recover (knowing blast radius). Govern is where the organization decides who owns all of it.
Where email security fits, honestly
Sentaro maps cleanly onto Protect and Detect for the email layer, feeds Identify with app and OAuth inventory, and gives Respond its evidence trail. The governance, risk decisions, recovery planning and everything beyond the mailbox remain organizational work. The CSF is a map; Sentaro covers a well-defined region of it. Organizations layering NIS2 obligations on top will find the same controls satisfy both.
This page is general guidance, not legal advice.