Compliance/Security frameworks/NIST CSF 2.0
Six Functions. One question: what does the file prove?
NIST CSF 2.0 describes outcomes, not products. Vaultize adds the records that stay with the data.
- Voluntary framework
- Capability mapping, not certification
- NIST CSWP 29 · 26 Feb 2024
The answer in 30 seconds
Vaultize adds file-level records to 16 Subcategories across all six Functions. The other 90 belong to identity, network, endpoint, people and governance controls.
The framework in one view
Six Functions. One wheel. Where file evidence lands.
NIST draws the Functions as a wheel. Govern sits at the centre. Select a Function to see which outcomes a governed file can evidence.
“GOVERN is in the center of the wheel because it informs how an organization will implement the other five Functions.”
GV · CORE
Govern
“The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored”
NIST CSWP 29
Outcomes the file can evidence
- How Vaultize contributes
- One policy engine applies the organisation’s rules to each file. Rules come from user, organisation, context, discovery and classification. They keep applying to copies held by suppliers.
- Evidence to retain
- Policy definitions and changes. Classification triggers. Recipient and third-party access records.
Outcome by outcome
What each outcome asks. What the file can answer.
Subcategory wording is quoted from NIST CSWP 29. Each row is a capability mapping, not a certification. Every row sits inside the organisation’s wider programme.
Using this page
Where these rows fit in a CSF Organizational Profile.
NIST describes five steps for an Organizational Profile. This page is evidence for step three.
- 1
Scope the Profile
Document the facts and assumptions it rests on.
- 2
Gather the information
Policies, risk priorities, resources and the tools in use.
- 3
Create the Profile
Record the current state of each outcome. This page is the data-level part of that record.
Bring the sixteen rows above as current-state evidence for data-level outcomes.
- 4
Analyze the gaps
Compare Current and Target Profiles. Create an action plan.
- 5
Implement and update
Follow the plan. Revise the Profile as the programme moves.
Responsibility boundary
Controls support outcomes. They do not certify them.
Vaultize contributes technical controls and evidence to a wider NIST CSF 2.0 programme. It does not certify or attest. It does not determine applicability, replace governance or policy, give legal advice, or guarantee compliance. Read the current framework and obtain qualified advice before relying on this page.
“The CSF does not prescribe how outcomes should be achieved.”
NIST CSWP 29, 26 February 2024
Official references
Read the source before relying on the mapping.
Every quotation on this page comes from the first item. The others are NIST’s own tools.
- The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29)The framework document. Every Function, Category and Subcategory on this page is quoted from its Appendix A.
- CSF 2.0 Quick Start GuidesNIST’s guides for creating Organizational Profiles and getting started.
- CSF 2.0 Reference ToolBrowse and export the Core with Implementation Examples.
- Informative ReferencesNIST’s mappings from CSF outcomes to other standards and controls.
A practical next step
Bring one outcome and one sensitive workflow.
We will show which Subcategories the governed file can evidence today. We will name the control owner responsible for the rest.
