The NIST Cybersecurity Framework 2.0 (February 2024) is the most widely used way to structure and measure a security program — and unlike its predecessor, it's explicitly written for organizations of every size and sector, not just critical infrastructure. CSF 2.0 organizes a program into six functions; the biggest change is the new Govern function, which makes leadership ownership and risk strategy a first-class part of the framework instead of an assumption.

Use this checklist for a fast, honest read of where you stand. Score each item yes, partially, or no — the "partially" answers are usually where the fastest wins live.

Govern (GV) — new in 2.0

  • ☐ Cybersecurity risk appetite and priorities are set by leadership, in writing — not inferred by the IT team.
  • ☐ Roles and accountability for cyber risk are assigned, including who owns decisions during an incident.
  • ☐ Suppliers and service providers are part of the risk picture: contracts, access, and monitoring expectations are defined.
  • ☐ Leadership reviews cyber risk on a schedule, in business terms — risk to operations and revenue, not alert counts.

Why it matters: Govern is where CSF 2.0 breaks from 1.1 — programs that treat security as an IT project stall here first, and assessors now look at this function before any control.

Identify (ID)

  • ☐ We maintain a current inventory of hardware, software, services, and data — including OT/plant assets and the systems production depends on.
  • ☐ Critical business processes are mapped to the systems that support them, so we know what an outage of each system actually stops.
  • ☐ Vulnerabilities are tracked with owners and deadlines, prioritized by exploitation and business impact — not just CVSS score.
  • ☐ Risk assessments happen on a cycle and after significant change, not once at audit time.

Protect (PR)

  • ☐ Access follows least privilege: MFA everywhere it matters, admin rights separated, joiner/mover/leaver handled within days, not months.
  • ☐ Systems are hardened against a baseline, and patching has defined windows — with a documented compensating path for the systems that can't be patched.
  • ☐ Data is protected in transit and at rest, and backups are tested by actually restoring, on a schedule.
  • ☐ People know what to do: security awareness is ongoing, and the high-risk roles (finance, admins, executives) get targeted training.

Detect (DE)

  • ☐ Logs from critical systems land in one place, retained long enough to investigate an incident from months ago.
  • ☐ Someone — a person, not just a tool — triages alerts around the clock, including weekends and holidays.
  • ☐ Detections are mapped to real adversary behavior (MITRE ATT&CK), so coverage gaps are visible instead of assumed.
  • ☐ Monitoring covers the environments that are easy to forget: cloud consoles, identity providers, and the OT network.

Respond (RS)

  • ☐ An incident response plan exists, names decision-makers, and has been exercised as a tabletop in the last year.
  • ☐ Escalation paths and communication templates (internal, customers, regulators, insurer) are ready before they're needed.
  • ☐ Containment authority is decided in advance — including who can isolate systems that affect production or revenue.
  • ☐ Incidents end with a written lessons-learned that changes something: a control, a detection, or the plan itself.

Recover (RC)

  • ☐ Recovery priorities are defined by the business: which systems come back first, and what the acceptable downtime for each actually is.
  • ☐ Restoration procedures are documented and tested — including the scenario where backups themselves were targeted.
  • ☐ Recovery communications are planned: who tells customers and stakeholders what, and when.

Scoring your read

Count your honest answers. Mostly yes: your effort belongs in measurement and evidence — proving effectiveness, not adding controls. A band of "partially": pick the one function where a "no" would hurt most and finish it before starting anything new. Mostly no in Govern: start there — every other function inherits its direction from it.

Where MBCTG fits

MBCTG builds and operates security programs mapped to NIST CSF 2.0 — from GRC advisory that stands up the Govern function, to 24/7 detection and response covering Detect and Respond, to OT-specific monitoring for the plant-floor assets most programs leave out. If the checklist surfaced gaps you want a second opinion on, talk to an expert — we'll map your current state to the framework and the fastest path up.