Menu

List of NIST Cybersecurity Framework Controls

List of NIST Cybersecurity Framework Controls

Learn about NIST Cybersecurity Framework Controls, including NIST CSF 2.0 core functions, categories, subcategories, tiers, and benefits for managing cybersecurity risks.

Cyberattacks don't usually begin with sophisticated hackers, they begin with missing controls. When a cyber incident makes headlines, the immediate assumption is often that attackers used advanced techniques or exploited unknown vulnerabilities. Many successful attacks happen because organizations overlook basic cybersecurity practices. An unpatched system, excessive user privileges, poor asset visibility, or delayed incident response can be enough to expose an entire business.

The challenge isn't always a lack of cybersecurity tools. Most organizations already have firewalls, endpoint protection, cloud security solutions, and monitoring platforms. The problem is that these controls often operate in isolation without a structured framework to ensure every critical area of cybersecurity is covered.

This is exactly why the NIST Cybersecurity Framework Controls have become a central part of cybersecurity risk management for organizations worldwide. This framework provides a practical structure for identifying cybersecurity risks, protecting critical assets, detecting threats early, responding effectively, and recovering from incidents with minimal disruption.

This guide explains NIST CSF controls, the six core functions introduced in NIST CSF 2.0, and the framework tiers used to assess cybersecurity maturity.

What Are NIST Cybersecurity Framework Controls?

NIST cybersecurity framework controls are the collection of cybersecurity outcomes and practices organizations use to manage cyber risk. In the NIST Cybersecurity Framework 2.0 controls, these practices are organized into Core Functions, Categories, and Subcategories that collectively strengthen an organization's cybersecurity posture.

Unlike prescriptive security standards, the NIST CSF does not tell organizations exactly how to implement security. Instead, it identifies the cybersecurity outcomes every organization should strive toward, allowing businesses to choose technologies and processes that best fit their size, industry, and risk profile.

These controls provide a common language for executives, IT teams, cybersecurity professionals, regulators, customers, and third-party partners to discuss cybersecurity priorities without becoming tied to specific products or vendors.

Organizations frequently use the NIST cybersecurity framework controls to:

  • Identify cybersecurity risks across the business

  • Build structured cybersecurity programs

  • Prioritize security investments

  • Improve regulatory compliance efforts

  • Strengthen resilience against cyber threats

  • Communicate cybersecurity maturity to stakeholders

The flexibility of the framework is one of its biggest strengths. Whether an organization operates entirely on-premises, in the cloud, or across hybrid environments, the NIST CSF provides a consistent structure for managing cybersecurity risk.

List of NIST CSF Controls

The NIST CSF controls list in NIST CSF 2.0 organizes cybersecurity controls into six Core Functions. These functions represent the lifecycle of cybersecurity risk management and together provide comprehensive coverage across the organization. Rather than functioning as isolated activities, the controls are interconnected. Strong governance influences risk identification, which informs protection strategies, enabling faster detection, more effective response, and quicker recovery.

The six NIST CSF functions are:

  • Govern (GV)

  • Identify (ID)

  • Protect (PR)

  • Detect (DE)

  • Respond (RS)

  • Recover (RC)

Each function contains Categories and Subcategories that define specific cybersecurity outcomes organizations should achieve.

The NIST CSF Core Functions Explained (GV, ID, PR, DE, RS, RC)

The NIST CSF core functions provide the overall structure of the framework. Every cybersecurity activity within the framework falls under one of these six functions, making them the foundation of modern cybersecurity risk management. Each of these Core Functions contains multiple NIST CSF categories and subcategories that describe specific cybersecurity outcomes.

Govern (GV)

Govern is the newest addition introduced in NIST CSF 2.0 and reflects the growing importance of cybersecurity governance at the executive level. This function focuses on establishing organizational oversight for cybersecurity by defining policies, assigning responsibilities, managing risk appetite, and ensuring cybersecurity objectives align with business goals. Govern contains several NIST CSF categories and subcategories covering organizational context, cybersecurity strategy, policy development, oversight, and enterprise risk management.

Governance is no longer viewed as solely an IT responsibility. Boards of directors, executive leadership, legal teams, risk managers, and operational leaders all play a role in ensuring cybersecurity decisions receive appropriate oversight.

Typical activities include:

  • Establishing cybersecurity policies

  • Defining organizational roles and responsibilities

  • Managing third-party cybersecurity risks

  • Integrating cybersecurity into enterprise risk management

  • Monitoring governance effectiveness

Identify (ID)

Organizations cannot protect assets they do not know exist. The Identify function focuses on developing a clear understanding of business assets, systems, data, people, suppliers, and operational risks. This includes maintaining asset inventories, understanding business environments, assessing risks, identifying critical services, and evaluating vulnerabilities that may impact operations.

Common Identify activities include:

  • Asset management

  • Risk assessment

  • Business environment analysis

  • Supply chain risk management

  • Vulnerability identification

Protect (PR)

Once critical assets and risks have been identified, organizations must implement safeguards that reduce the likelihood of successful attacks. The Protect function encompasses preventive controls designed to secure systems, users, networks, applications, and sensitive information.

Examples include:

  • Identity and access management

  • Security awareness training

  • Data protection measures

  • Encryption

  • Secure configurations

  • Patch management

  • Backup procedures

  • Network security controls

Detect (DE)

No preventive security control is perfect. The Detect function focuses on identifying cybersecurity events quickly so organizations can respond before significant damage occurs. Continuous monitoring plays a central role here. Organizations monitor systems, networks, applications, cloud environments, and user activities to detect suspicious behavior.

Detection activities commonly include:

  • Security monitoring

  • Log analysis

  • Threat detection

  • Anomaly detection

  • Security event correlation

  • Continuous monitoring

Respond (RS)

Detection alone is insufficient without an organized response. The Respond function outlines how organizations should manage cybersecurity incidents once they occur. The objective is to contain threats, reduce business disruption, communicate effectively, and restore operational stability.

Response planning typically covers:

  • Incident response procedures

  • Communication plans

  • Threat containment

  • Forensic investigations

  • Stakeholder coordination

  • Regulatory notifications

  • Lessons learned

A structured response minimizes downtime while preserving evidence needed for investigations and compliance requirements.

Recover (RC)

Business resilience depends not only on stopping attacks but also on restoring operations efficiently afterward. The Recover function focuses on restoring systems, services, and business operations following cybersecurity incidents.

Recovery activities often include:

  • Disaster recovery planning

  • System restoration

  • Business continuity coordination

  • Recovery testing

  • Improvement planning

  • Post-incident reviews

Understanding NIST CSF Categories and Subcategories

Although organizations often focus on the six Core Functions, the framework becomes significantly more actionable through its NIST CSF categories and subcategories. Categories group related cybersecurity outcomes within each function, while subcategories describe the specific results organizations should achieve.

For example, under the Protect function, categories address areas such as Identity Management, Data Security, Platform Security, and Technology Infrastructure Resilience. Each category is further divided into subcategories that outline measurable cybersecurity outcomes without prescribing a specific technology or implementation method.

This layered structure allows organizations to tailor the framework according to their size, industry, regulatory obligations, and overall cybersecurity maturity.

Why Are NIST CSF Controls Important?

Cybersecurity today extends beyond protecting IT infrastructure. It influences operational resilience, regulatory compliance, customer trust, supply chain security, and business continuity. The NIST cybersecurity framework controls provide organizations with a structured way to manage cyber risk while allowing flexibility to adapt security practices to different industries and business models.

Some of the key benefits include:

  •  Better Risk Visibility

Organizations gain a clearer understanding of critical assets, vulnerabilities, and business risks, enabling informed decision-making instead of reactive security measures.

  • Improved Executive Decision-Making

The framework creates a common language between cybersecurity professionals and business leaders, making cybersecurity discussions more meaningful at the executive level.

  • Greater Operational Consistency

The framework encourages standardized cybersecurity processes across departments, locations, cloud environments, and third-party relationships.

  • Stronger Regulatory Alignment

Although voluntary, the framework aligns well with many cybersecurity and privacy regulations, making compliance initiatives more structured and efficient.

  • Enhanced Cyber Resilience

By covering prevention, detection, response, and recovery, the framework enables organizations to continue operating even when cybersecurity incidents occur.

NIST Cybersecurity Framework 2.0 Controls vs. NIST 800-53 Controls List

A common point of confusion is the difference between NIST Cybersecurity Framework 2.0 controls and the NIST 800-53 controls list. Although they are closely related, they serve different purposes.

The NIST Cybersecurity Framework provides a high-level framework for managing cybersecurity risk through Core Functions, Categories, and Subcategories. In contrast, the NIST 800-53 controls list contains detailed security and privacy controls that organizations, particularly federal agencies and contractors, can implement to satisfy specific security requirements.

Many organizations use both frameworks together. The Cybersecurity Framework helps determine what cybersecurity outcomes should be achieved, while NIST SP 800-53 offers detailed technical and administrative controls that can be mapped to those outcomes during integration.

Who Should Use the NIST Cybersecurity Framework?

A common misconception is that the NIST Cybersecurity Framework is designed only for government agencies or large enterprises. But, organizations of all sizes and industries can adopt the framework because it is scalable and technology-neutral.

The framework is commonly used by:

  • Small and medium-sized businesses

  • Large enterprises

  • Financial institutions

  • Healthcare organizations

  • Manufacturing companies

  • Technology companies

  • Cloud service providers

  • Educational institutions

  • Critical infrastructure operators

  • Government contractors

Organizations beginning their cybersecurity journey often use the framework to establish foundational security practices, while mature organizations use it to benchmark and continuously improve existing cybersecurity programs. Because the framework is flexible, organizations can integrate only the portions most relevant to their current business risks while expanding over time.

Understanding the NIST CSF Framework Tiers

In addition to the Core Functions, the framework introduces Framework Tiers that help organizations understand how mature their cybersecurity risk management practices are.The tiers are not compliance levels or certification grades. Instead, they describe the sophistication and consistency of an organization's cybersecurity processes.

  • Tier 1 – Partial

Cybersecurity activities are largely informal and reactive. Risk management processes are inconsistent, and cybersecurity decisions are often made individually rather than strategically. Organizations at this level may have isolated security controls but lack an organization-wide cybersecurity program.

  • Tier 2 – Risk Informed

Management recognizes cybersecurity risks, and basic governance processes begin to emerge. Security activities become more consistent, although they may still vary across departments. Risk assessments increasingly influence security decisions.

  • Tier 3 – Repeatable

Cybersecurity processes become standardized, documented, and consistently applied throughout the organization. Risk management is integrated into broader business operations, and continuous improvement becomes part of normal governance activities.

  • Tier 4 – Adaptive

    Organizations continuously monitor evolving threats and adjust cybersecurity strategies proactively. Security intelligence, automation, advanced analytics, and continuous learning drive ongoing improvements. Cybersecurity becomes deeply integrated into business strategy rather than functioning as an isolated technical discipline.

Organizations should not automatically aim for Tier 4. The appropriate tier depends on business objectives, regulatory obligations, operational complexity, available resources, and risk tolerance.

Building a Stronger Cybersecurity Foundation with NIST CSF

The NIST cybersecurity framework controls provide far more than a cybersecurity checklist, they establish a structured approach for governing cyber risk, strengthening resilience, and continuously improving security across the organization. Adopting the framework is about creating repeatable processes that improve resilience, strengthen stakeholder confidence, and enable better decision-making as risks change over time.

For organizations looking to align their cybersecurity practices with internationally recognized frameworks, INTERCERT works with businesses across industries seeking greater confidence in their governance and certification journey. As an accredited certification body, INTERCERT enables organizations to demonstrate that their management systems meet globally recognized standards, reinforcing trust with customers, partners, and regulators while supporting long-term business resilience.

Read More:
What’s New in NIST Cybersecurity 2.0 & What You Need to Know?
What is NIST 800-171 and 800-53 Frameworks? A Complete Guide in 2026

 

 

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved