Information Security Matters: NIST CSF 2.0 and the Cybersecurity Hierarchy

Graphic of blocks
Author: Steven J. Ross, CISA, CDPSE, AFBCI, MBCP
Date Published: 1 January 2025
Read Time: 7 minutes
Related: Cybersecurity Audit Program: Based on the NIST Cybersecurity Framework 2.0 | Digital | English

At the end of my previous column,1 I briefly discussed the fact that the NIST CSF 2.0 calls for “a hierarchy of executives, managers and practitioners not stated in the previous version.” This is not notable on its own. Organizations tend to develop hierarchies and those responsible for cybersecurity must fit within them somewhere...

 

Members, login to keep reading.

Not a member but want to read more?
Explore ISACA member benefits today.