{"id":288,"date":"2025-09-28T21:24:19","date_gmt":"2025-09-28T21:24:19","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/aaronhermans\/?p=288"},"modified":"2025-09-28T21:24:19","modified_gmt":"2025-09-28T21:24:19","slug":"synopsis-nist-cybersecurity-framework-1-1-vs-2-0","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/aaronhermans\/2025\/09\/28\/synopsis-nist-cybersecurity-framework-1-1-vs-2-0\/","title":{"rendered":"Synopsis: NIST Cybersecurity Framework 1.1 vs. 2.0"},"content":{"rendered":"\n<p>The\u00a0National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)\u00a0is a widely used tool for managing cybersecurity risk. Version\u00a01.1\u00a0was released in 2018, and version\u00a02.0\u00a0(published in February 2024) reflects the evolving threat landscape, regulatory expectations, and the need for broader adoption beyond critical infrastructure.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><strong>Scope<\/strong><\/p>\n\n\n\n<ul>\n<li><strong>CSF 1.1 (2018):<\/strong> Originally designed for\u00a0critical infrastructure sectors\u00a0(e.g., energy, finance, transportation).<\/li>\n\n\n\n<li><strong>CSF 2.0 (2024):<\/strong>\u00a0Expanded to apply to\u00a0all organizations, regardless of size or sector, including small businesses, supply chains, and global stakeholders.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><strong>Structure and Functions<\/strong><\/p>\n\n\n\n<ul>\n<li><strong>CSF 1.1:<\/strong>\u00a0Built around\u00a0five core functions: Identify, Protect, Detect, Respond, Recover.<\/li>\n\n\n\n<li><strong>CSF 2.0:<\/strong>\u00a0Introduces a\u00a0sixth function, \u201cGovern,\u201d\u00a0which emphasizes organizational governance, risk management, roles, and accountability.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><strong>Governance and Risk Management<\/strong><\/p>\n\n\n\n<ul>\n<li><strong>CSF 1.1:<\/strong>&nbsp;Touched on governance but embedded it within other functions.<\/li>\n\n\n\n<li><strong>CSF 2.0:<\/strong>\u00a0Elevates governance to a\u00a0standalone pillar, reflecting the importance of executive oversight, board engagement, and regulatory compliance.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><strong>Supply Chain and Third-Party Risk<\/strong><\/p>\n\n\n\n<ul>\n<li><strong>CSF 1.0<\/strong>:\u00a0Mentioned supply chain risks but did not provide a detailed approach.<\/li>\n\n\n\n<li><strong>CSF 2.0:<\/strong>\u00a0Stronger emphasis on\u00a0supply chain cybersecurity, vendor risk management, and extended enterprise resilience.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><strong>Guidance and Resources<\/strong><\/p>\n\n\n\n<ul>\n<li><strong>CSF 1.1:<\/strong>\u00a0Relied primarily on the framework core, profiles, and implementation tiers.<\/li>\n\n\n\n<li><strong>CSF 2.0:<\/strong>\u00a0Provides\u00a0expanded implementation guidance, quick-start guides, and practical examples\u00a0to support adoption by organizations of varying maturity and resource levels.\u00a0<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><strong>Global Applicability<\/strong><\/p>\n\n\n\n<ul>\n<li><strong>CSF 1.1:\u00a0<\/strong>U.S.-centric, though widely adopted internationally.<\/li>\n\n\n\n<li><strong>CSF 2.0:<\/strong>\u00a0Written with\u00a0international harmonization\u00a0in mind, aligning with global standards to encourage worldwide adoption.\u00a0<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><strong>Summary<\/strong><\/p>\n\n\n\n<p>The shift from\u00a0NIST CSF <strong>1.1<\/strong> to <strong>2.0\u00a0<\/strong>represents more than an update\u2014it reflects a broader, more inclusive approach to cybersecurity risk management. By adding a\u00a0Govern function, emphasizing supply chain security, and expanding applicability to all organizations, CSF 2.0 provides a stronger foundation for resilience in today\u2019s interconnected global economy.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p>\u00a0When expanding your platform, the wider the basis you cover, the more efficient it is. If you\u2019re expecting growth, you often need to expand. By expanding its applicable capabilities, you\u2019re making it ultimately more useful<\/p>\n\n\n\n<p>\u00a0The govern function is what helps manage the other functions. What makes this function different is that instead of playing a specific role, its job is to ensure all the other roles are performing properly. Ultimately, the govern function is in a category of its own in regard to capability.<\/p>\n\n\n\n<p>\u00a0Properly securing the supply chain for your organization is arguably as crucial as any other form of security. Ensuring the product, you\u2019re receiving is both valid and safe is crucial for optimal operations. By gambling the risk of an infected product, you\u2019re accepting the risk of potential failure.<\/p>\n\n\n\n<p>\u00a0Having access to resources is one thing but ensuring everyone is trained on how to access those resources is even more important. It doesn\u2019t matter how important those resources are if the intended audience isn\u2019t properly informed of how to access them. Ultimately, communication is one of the most important things within the workplace and being unable to access certain data hurts everyone within the organization.<\/p>\n\n\n\n<p>\u00a0When seeking a bigger platform, you often reach a point where the next step is on the international level. When limiting yourself to one specific region, you\u2019re only hurting the true potential your platform might have. With how technologically advanced the world is becoming, essentially everywhere in the world has access to the internet and may benefit from your platform.<\/p>\n\n\n\n<p>\u00a0Overall, Version 2.0 seems to be looking at the bigger picture I comparison to Version 1.1. Version 1.1 had too specific of a base and was limited both digitally and geographically. With the introduction of Version 2.0, we now have a more internationally available and diverse platform<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The\u00a0National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)\u00a0is a widely used tool for managing cybersecurity risk. Version\u00a01.1\u00a0was released in 2018, and version\u00a02.0\u00a0(published in February 2024) reflects the evolving threat landscape, regulatory expectations, and the need for broader adoption beyond critical infrastructure. Scope Structure and Functions Governance and Risk Management Supply Chain and Third-Party&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/aaronhermans\/2025\/09\/28\/synopsis-nist-cybersecurity-framework-1-1-vs-2-0\/\">Read More<\/a><\/div>\n","protected":false},"author":31366,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/posts\/288"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/users\/31366"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/comments?post=288"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/posts\/288\/revisions"}],"predecessor-version":[{"id":289,"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/posts\/288\/revisions\/289"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/media?parent=288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/categories?post=288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/aaronhermans\/wp-json\/wp\/v2\/tags?post=288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}