Cybersecurity
NIST Cybersecurity Framework 2.0
NIST Cybersecurity Framework 2.0 is a case interview framework for cybersecurity, governance, risk management. Use as overall framework for comprehensive cybersecurity program
When to use it
Use as overall framework for comprehensive cybersecurity program
Where it fits
Best for cybersecurity strategy, governance, and risk management cases
How to use it in a case
Structure security program around 6 functions (Govern, Identify, Protect, Detect, Respond, Recover) and 4 Implementation Tiers (Partial, Risk-informed, Repeatable, Adaptive). For each function, define practices and assess maturity.
- Govern. Oversight, accountability, strategy, governance structures, policies
- Identify. Understand assets, risks, vulnerabilities, threat landscape
- Protect. Access control, training, data security, maintenance, supply chain
- Detect. Monitoring, analytics, detection processes, incident assessment
- Respond. Incident planning, communications, mitigation, improvements
- Recover. Recovery planning, improvements, communication during recovery
Case types
Cybersecurity, Governance, Risk Management.
Source: NIST Cybersecurity Framework 2.0.