Case 1C97B6 · GRC · L1 Foundations
NIST Cybersecurity Framework 2.0
Practise as: Explain it · Interview
Interview questionWalk me through the NIST Cybersecurity Framework and how an organization would actually use it.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- CSF 2.0 (2024) has six Functions: Govern, Identify, Protect, Detect, Respond, Recover. Govern was added in 2.0.
- Functions break into Categories and Subcategories (outcomes), mapped via Informative References to 800-53, ISO, CIS.
- Profiles: build a Current Profile and a Target Profile, then prioritize the gap into a roadmap.
- Tiers 1-4 (Partial, Risk Informed, Repeatable, Adaptive) describe rigor of risk governance, not a maturity score.
- Voluntary and outcome-based: it says what to achieve, not which product or control to buy.
If the interviewer pushes back
- How would you use CSF Profiles to justify a security budget to a board that does not speak security?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.