The US Department of Commerce's National Institute of Standards and Technology (NIST) created the NIST Cybersecurity Framework in response to a Presidential Executive Order, Improving Critical Infrastructure Cybersecurity. The framework, developed in collaboration with the industry, provides guidance to organizations on ways to better manage and reduce cybersecurity risk. The NIST Cybersecurity Framework Core presents key cybersecurity outcomes identified by the industry as helpful in managing cybersecurity risk. The Core comprises four elements: functions, categories, subcategories, and informative references. The following diagram shows the five stages of the NIST cybersecurity framework:
The NIST Cybersecurity Framework