{"id":317,"date":"2026-05-03T15:56:16","date_gmt":"2026-05-03T15:56:16","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/yoelmejia\/?p=317"},"modified":"2026-05-03T15:56:16","modified_gmt":"2026-05-03T15:56:16","slug":"understanding-the-differences-between-the-nist-cybersecurity-framework-1-1-and-2-0","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/yoelmejia\/2026\/05\/03\/understanding-the-differences-between-the-nist-cybersecurity-framework-1-1-and-2-0\/","title":{"rendered":"Understanding the Differences between the NIST Cybersecurity Framework 1.1 and 2.0"},"content":{"rendered":"\n<p>Prompt: I need a one-page synopsis of the differences between the NIST Cybersecurity<br>Framework 1.1 and 2.0<\/p>\n\n\n\n<p><br>The NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based approach to<br>managing cybersecurity risk. Version 1.1, released in 2018, refined the original 2014 framework.<br>In 2024, Version 2.0 introduced significant updates while preserving the framework\u2019s core<br>structure. The primary differences between Versions 1.1 and 2.0 include expanded applicability,<br>the addition of a governance function, updated risk priorities, and improved implementation<br>guidance.<br>One major change is scope. Version 1.1 was initially developed to support critical infrastructure<br>organizations, though it was widely adopted across industries. Version 2.0 broadens its intended<br>audience and is explicitly designed for organizations of all sizes and sectors. This shift reflects<br>the understanding that cybersecurity risk affects every organization, regardless of industry.<br>The most significant structural update in Version 2.0 is the addition of a sixth core function:<br>Govern. Version 1.1 consisted of five functions\u2014Identify, Protect, Detect, Respond, and<br>Recover\u2014representing the lifecycle of cybersecurity risk management. While governance<br>concepts were present, they were embedded within other functions. Version 2.0 elevates<br>governance to a standalone function, emphasizing leadership oversight, risk management<br>strategy, defined roles and responsibilities, and accountability. This change reinforces<br>cybersecurity as an enterprise-wide business risk rather than solely an IT responsibility.<br>Version 2.0 also updates categories and subcategories to reflect modern threats. It places stronger<br>emphasis on supply chain cybersecurity risk management, highlighting third-party and vendor<br>risks that have become increasingly significant. These refinements improve clarity and alignment<br>with current cybersecurity challenges.<br>Additionally, Version 2.0 enhances implementation support. While Version 1.1 introduced<br>Organizational Profiles and Implementation Tiers, Version 2.0 provides clearer guidance and<br>practical examples to help organizations assess and improve their cybersecurity posture.<br>Overall, CSF 2.0 builds upon Version 1.1 by expanding applicability, strengthening governance,<br>modernizing risk focus, and improving usability. The update reflects the evolving cybersecurity<br>landscape and the need for stronger strategic alignment between cybersecurity and enterprise risk<br>management.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Prompt: I need a one-page synopsis of the differences between the NIST CybersecurityFramework 1.1 and 2.0 The NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based approach tomanaging cybersecurity risk. Version 1.1, released in 2018, refined the original 2014 framework.In 2024, Version 2.0 introduced significant updates while preserving the framework\u2019s corestructure. The primary differences between Versions&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/yoelmejia\/2026\/05\/03\/understanding-the-differences-between-the-nist-cybersecurity-framework-1-1-and-2-0\/\">Read More<\/a><\/div>\n","protected":false},"author":32163,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/posts\/317"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/users\/32163"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/comments?post=317"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/posts\/317\/revisions"}],"predecessor-version":[{"id":318,"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/posts\/317\/revisions\/318"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/media?parent=317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/categories?post=317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/yoelmejia\/wp-json\/wp\/v2\/tags?post=317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}