← Glossary

NIST Cybersecurity Framework

The voluntary US framework for organizing cybersecurity work, structured in CSF 2.0 around six functions from Govern to Recover.

Updated

The NIST Cybersecurity Framework (CSF) is a voluntary framework from the US National Institute of Standards and Technology for organizing and improving cybersecurity work, structured in CSF 2.0 around six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is not a certification but a common language: boards, auditors and insurers worldwide use it to ask "where are you?" The framework is published by NIST.

Key facts:

  • CSF 2.0 (2024) added Govern as a sixth function, elevating risk ownership and supply chain governance.
  • The framework is descriptive, not prescriptive: it maps what good looks like and lets organizations choose controls (often from ISO 27001 or CIS) to get there.
  • Its language dominates security questionnaires and cyber insurance applications even outside the US.

The six functions through the email lens

Email touches five of six directly: Identify (knowing which apps and OAuth grants exist, including shadow IT), Protect (blocking phishing and BEC at the top attack vector), Detect (anomalies in messages and account behavior), Respond (incident evidence: who, what, when, scope) and Recover (knowing blast radius). Govern is where the organization decides who owns all of it.

Where email security fits, honestly

Sentaro maps cleanly onto Protect and Detect for the email layer, feeds Identify with app and OAuth inventory, and gives Respond its evidence trail. The governance, risk decisions, recovery planning and everything beyond the mailbox remain organizational work. The CSF is a map; Sentaro covers a well-defined region of it. Organizations layering NIS2 obligations on top will find the same controls satisfy both.

This page is general guidance, not legal advice.

Questions we get asked.

What is the NIST CSF in simple terms?

A widely used framework that organizes cybersecurity into six functions (Govern, Identify, Protect, Detect, Respond, Recover) so organizations can assess and communicate their security posture.

Is NIST CSF a certification?

No. There is no NIST CSF certificate; organizations self-assess maturity against it and often evidence it through certifications like ISO 27001 or reports like SOC 2.

What changed in CSF 2.0?

The Govern function was added, broadening the framework from technical functions to explicit risk governance and supply chain oversight, and the scope widened beyond critical infrastructure to all organizations.

How does email security map to the CSF?

Directly onto Protect and Detect (phishing/BEC defense, anomaly detection), with contributions to Identify (app/OAuth inventory) and Respond (incident evidence).

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.