Cybersecurity

NIST Cybersecurity Framework 2.0

NIST Cybersecurity Framework 2.0 is a case interview framework for cybersecurity, governance, risk management. Use as overall framework for comprehensive cybersecurity program

When to use it

Use as overall framework for comprehensive cybersecurity program

Where it fits

Best for cybersecurity strategy, governance, and risk management cases

How to use it in a case

Structure security program around 6 functions (Govern, Identify, Protect, Detect, Respond, Recover) and 4 Implementation Tiers (Partial, Risk-informed, Repeatable, Adaptive). For each function, define practices and assess maturity.

  1. Govern. Oversight, accountability, strategy, governance structures, policies
  2. Identify. Understand assets, risks, vulnerabilities, threat landscape
  3. Protect. Access control, training, data security, maintenance, supply chain
  4. Detect. Monitoring, analytics, detection processes, incident assessment
  5. Respond. Incident planning, communications, mitigation, improvements
  6. Recover. Recovery planning, improvements, communication during recovery

Case types

Cybersecurity, Governance, Risk Management.

Source: NIST Cybersecurity Framework 2.0.

Related frameworks