{
  "$schema": "https://bestinsuranceresearch.com/llms-full.txt",
  "recordType": "source",
  "id": "nist-csf-2-0",
  "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0",
  "contentVersion": "2026.08.31",
  "generatedFor": "2026-09-06",
  "operator": {
    "legalName": "WJB Services, Inc.",
    "dba": "Bollinsure Insurance Services",
    "license": "6013787",
    "licenseAuthority": "California Department of Insurance"
  },
  "license": "Text on this page may be quoted with attribution and a link to the canonical URL.",
  "notice": "Public page facts only. This record contains no visitor question, no tool input, and no identifier. It is not a coverage determination, an eligibility decision, or individualized advice.",
  "title": "The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29)",
  "publisher": "National Institute of Standards and Technology, U.S. Department of Commerce",
  "url": "https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf",
  "officialHost": true,
  "sourceType": "official-documentation",
  "authorityLevel": "secondary",
  "primary": true,
  "jurisdiction": "US",
  "publishedDate": "2024-02-26",
  "effectiveDate": "2024-02-26",
  "accessedDate": "2026-08-31",
  "lastChecked": "2026-08-31",
  "updateCadence": "major-revision",
  "status": "active",
  "supportsClaims": [
    {
      "claimId": "nist-csf-2-0#c1",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c1",
      "checksum": "21edaef87493",
      "text": "The current edition is CSF 2.0, published February 26, 2024, available free of charge at https://doi.org/10.6028/NIST.CSWP.29."
    },
    {
      "claimId": "nist-csf-2-0#c2",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c2",
      "checksum": "a6269e3c4513",
      "text": "CSF 2.0 organizes outcomes under six Functions: GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), RESPOND (RS), RECOVER (RC)."
    },
    {
      "claimId": "nist-csf-2-0#c3",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c3",
      "checksum": "ac7602ce116d",
      "text": "PR.AA-03: Users, services, and hardware are authenticated."
    },
    {
      "claimId": "nist-csf-2-0#c4",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c4",
      "checksum": "f56e7b391d45",
      "text": "PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties."
    },
    {
      "claimId": "nist-csf-2-0#c5",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c5",
      "checksum": "b4427b611200",
      "text": "PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind."
    },
    {
      "claimId": "nist-csf-2-0#c6",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c6",
      "checksum": "f0b8aa673ee3",
      "text": "PR.DS-11: Backups of data are created, protected, maintained, and tested."
    },
    {
      "claimId": "nist-csf-2-0#c7",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c7",
      "checksum": "156da6deba0b",
      "text": "PR.PS-02: Software is maintained, replaced, and removed commensurate with risk."
    },
    {
      "claimId": "nist-csf-2-0#c8",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c8",
      "checksum": "c808289e5bfe",
      "text": "DE.CM-01: Networks and network services are monitored to find potentially adverse events."
    },
    {
      "claimId": "nist-csf-2-0#c9",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c9",
      "checksum": "db721a4b82b8",
      "text": "RS.MA-01: The incident response plan is executed in coordination with relevant third parties once an incident is declared."
    },
    {
      "claimId": "nist-csf-2-0#c10",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c10",
      "checksum": "40993542be19",
      "text": "RC.RP-03: The integrity of backups and other restoration assets is verified before using them for restoration."
    },
    {
      "claimId": "nist-csf-2-0#c11",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c11",
      "checksum": "591e6af2102d",
      "text": "GV.PO-01: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities, and is communicated and enforced."
    },
    {
      "claimId": "nist-csf-2-0#c12",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c12",
      "checksum": "42d9f0cd5589",
      "text": "ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties."
    },
    {
      "claimId": "nist-csf-2-0#c13",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c13",
      "checksum": "c17274c0f486",
      "text": "The CSF does not prescribe how outcomes should be achieved; it offers a taxonomy of high-level cybersecurity outcomes usable by any organization regardless of size, sector, or maturity."
    },
    {
      "claimId": "nist-csf-2-0#c14",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c14",
      "checksum": "765aef8cefcf",
      "text": "PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected. PR.DS-02: The confidentiality, integrity, and availability of data-in-transit are protected."
    },
    {
      "claimId": "nist-csf-2-0#c15",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/nist-csf-2-0#c15",
      "checksum": "edb9bc06a40c",
      "text": "Cybersecurity Supply Chain Risk Management (GV.SC) is a category within the GOVERN function, covering cyber supply chain risk management processes identified, established, managed, monitored, and improved by organizational stakeholders."
    }
  ],
  "reliedOnBy": [
    {
      "kind": "Example",
      "title": "Reading the HIPAA notification rule against the CISA and NIST control cadences to see why one is a ceiling and the others are intervals",
      "url": "https://bestinsuranceresearch.com/examples/breach-clock-is-a-ceiling-not-a-cadence"
    },
    {
      "kind": "Module",
      "title": "Cyber Control Readiness (23 checks)",
      "url": "https://bestinsuranceresearch.com/tools/cyber-control-readiness"
    }
  ],
  "reliedOnByCount": 2,
  "citation": {
    "text": "National Institute of Standards and Technology, U.S. Department of Commerce. \"The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29).\" 2024-02-26. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (retrieved 2026-08-31).",
    "viaThisSite": "BestInsurance Research source record nist-csf-2-0, content version 2026.08.31. https://bestinsuranceresearch.com/sources/nist-csf-2-0",
    "note": "Cite the underlying source when you can. Cite this record when you are describing our synthesis or our claim list."
  }
}
