NIST CSF 2.0: the six functions without a second program
The framework published in February 2024 adds Govern to the five functions people already knew. It is not a certification. It is a way to describe where you are and where you are going.
NIST published the Cybersecurity Framework 2.0 on 26 February 2024. The previous version had five functions. Version 2.0 has six. The framework is for organizations of any size. It does not issue a certificate.
The six functions
1. Govern
Risk strategy, roles, policy, oversight and supplier risk. This function frames the other five. It was not a separate function in version 1.1.
2. Identify
Assets, risks and the improvements to prioritize. Without an inventory, the other functions sit on a vague scope.
3. Protect
The safeguards that prevent or limit an incident: access, awareness, data protection, maintenance.
4. Detect
The monitoring that shows an abnormal event while there is still time to act.
5. Respond
What the organization does once an incident is detected: analysis, containment, communication.
6. Recover
Restoring activities and systems, and what the incident changes in the plans.
Current profile and target profile
A profile describes the outcomes you want in your context. The current profile says what is in place. The target profile says what the risk and the customers require. The gap between them is the plan, not a score on a scale you are required to climb. NIST offers tiers to situate how rigorous the practices are. That is not a level you must reach in order to be compliant with NIST.
Map, do not duplicate
If ISO 27001 or a SOC 2 report is already in place, access, incident and supplier controls exist. Each control sits under one or more functions. Govern picks up policy, roles and management review. Identify picks up the asset inventory. Respond and Recover pick up the incident process and the recovery tests. A second register, with the same risks under another name, adds evidence work and does not change the posture.
The framework does not replace Law 25, PIPEDA, the AMF ICT guideline or OSFI Guidelines B-13 and B-10. It helps show a customer or a board how those obligations are spread.
The reference text is the NIST Cybersecurity Framework 2.0 of 26 February 2024.
The six functions on the register you already keep
CapCOM and CapRISK attach one control to ISO 27001, SOC 2 and the NIST CSF without copying the evidence.
