VISIONCYBERX / GRCVoluntary risk framework
CYBERSECURITY FRAMEWORK

NIST CSF 2.0

Voluntary framework for managing and communicating cybersecurity risk.

01 / Applicability

Scope comes first.

Govern, Identify, Protect, Detect, Respond and Recover organise outcomes. CSF use is not certification or proof of EU legal compliance.

02 / Control focus

What to map.

  • Current and target profiles
  • Risk-based priorities
  • Measures and ownership
03 / VISIONCYBERX

Our approach.

We use CSF as a common language for board reporting and map it to applicable requirements.

Interpretation

This overview is not a certification or legal determination. Verify the current official text and assess your entity, services, country and contractual obligations.