Open cardosec

Case 1C97B6 · GRC · L1 Foundations

NIST Cybersecurity Framework 2.0

Practise as: Explain it · Interview

Interview questionWalk me through the NIST Cybersecurity Framework and how an organization would actually use it.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. CSF 2.0 (2024) has six Functions: Govern, Identify, Protect, Detect, Respond, Recover. Govern was added in 2.0.
  2. Functions break into Categories and Subcategories (outcomes), mapped via Informative References to 800-53, ISO, CIS.
  3. Profiles: build a Current Profile and a Target Profile, then prioritize the gap into a roadmap.
  4. Tiers 1-4 (Partial, Risk Informed, Repeatable, Adaptive) describe rigor of risk governance, not a maturity score.
  5. Voluntary and outcome-based: it says what to achieve, not which product or control to buy.

If the interviewer pushes back

  • How would you use CSF Profiles to justify a security budget to a board that does not speak security?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.