The NIST Cybersecurity Framework 2.0 (February 2024) is the most widely used way to structure and measure a security program — and unlike its predecessor, it's explicitly written for organizations of every size and sector, not just critical infrastructure. CSF 2.0 organizes a program into six functions; the biggest change is the new Govern function, which makes leadership ownership and risk strategy a first-class part of the framework instead of an assumption.
Use this checklist for a fast, honest read of where you stand. Score each item yes, partially, or no — the "partially" answers are usually where the fastest wins live.
Govern (GV) — new in 2.0
- ☐ Cybersecurity risk appetite and priorities are set by leadership, in writing — not inferred by the IT team.
- ☐ Roles and accountability for cyber risk are assigned, including who owns decisions during an incident.
- ☐ Suppliers and service providers are part of the risk picture: contracts, access, and monitoring expectations are defined.
- ☐ Leadership reviews cyber risk on a schedule, in business terms — risk to operations and revenue, not alert counts.
Why it matters: Govern is where CSF 2.0 breaks from 1.1 — programs that treat security as an IT project stall here first, and assessors now look at this function before any control.
Identify (ID)
- ☐ We maintain a current inventory of hardware, software, services, and data — including OT/plant assets and the systems production depends on.
- ☐ Critical business processes are mapped to the systems that support them, so we know what an outage of each system actually stops.
- ☐ Vulnerabilities are tracked with owners and deadlines, prioritized by exploitation and business impact — not just CVSS score.
- ☐ Risk assessments happen on a cycle and after significant change, not once at audit time.
Protect (PR)
- ☐ Access follows least privilege: MFA everywhere it matters, admin rights separated, joiner/mover/leaver handled within days, not months.
- ☐ Systems are hardened against a baseline, and patching has defined windows — with a documented compensating path for the systems that can't be patched.
- ☐ Data is protected in transit and at rest, and backups are tested by actually restoring, on a schedule.
- ☐ People know what to do: security awareness is ongoing, and the high-risk roles (finance, admins, executives) get targeted training.
Detect (DE)
- ☐ Logs from critical systems land in one place, retained long enough to investigate an incident from months ago.
- ☐ Someone — a person, not just a tool — triages alerts around the clock, including weekends and holidays.
- ☐ Detections are mapped to real adversary behavior (MITRE ATT&CK), so coverage gaps are visible instead of assumed.
- ☐ Monitoring covers the environments that are easy to forget: cloud consoles, identity providers, and the OT network.
Respond (RS)
- ☐ An incident response plan exists, names decision-makers, and has been exercised as a tabletop in the last year.
- ☐ Escalation paths and communication templates (internal, customers, regulators, insurer) are ready before they're needed.
- ☐ Containment authority is decided in advance — including who can isolate systems that affect production or revenue.
- ☐ Incidents end with a written lessons-learned that changes something: a control, a detection, or the plan itself.
Recover (RC)
- ☐ Recovery priorities are defined by the business: which systems come back first, and what the acceptable downtime for each actually is.
- ☐ Restoration procedures are documented and tested — including the scenario where backups themselves were targeted.
- ☐ Recovery communications are planned: who tells customers and stakeholders what, and when.
Scoring your read
Count your honest answers. Mostly yes: your effort belongs in measurement and evidence — proving effectiveness, not adding controls. A band of "partially": pick the one function where a "no" would hurt most and finish it before starting anything new. Mostly no in Govern: start there — every other function inherits its direction from it.
Where MBCTG fits
MBCTG builds and operates security programs mapped to NIST CSF 2.0 — from GRC advisory that stands up the Govern function, to 24/7 detection and response covering Detect and Respond, to OT-specific monitoring for the plant-floor assets most programs leave out. If the checklist surfaced gaps you want a second opinion on, talk to an expert — we'll map your current state to the framework and the fastest path up.