Why the NIST CSF?
The NIST CSF is a wonderful cybersecurity framework to start off with. It was meant for organizations that are considered critical infrastructure to assist in implementing cybersecurity controls. Also, it is free to consume. Well, it is not necessarily free – I mean if you are a US citizen, then your tax dollars paid for it to be developed.
Though it was originally written for critical infrastructure businesses, the NIST CSF 2.0 is meant to be easily adopted and used for small to medium-sized, even larger, organizations. The framework was written in such a way that it can be customizable when implemented. As you will see later on in this chapter, organizations that adopted other frameworks migrated to the CSF because they were hard to implement.
As mentioned, the CSF is a framework that is easy to understand, easy to maintain, and easy to score and show progress of how your cybersecurity program is maturing. It also sets you and your organization up for...