Implementing the NIST Cybersecurity Framework

4 Minute read
Qurash Ramlal
Customer Success Manager | Governance & Security Advisory
Implementing the NIST Cybersecurity Framework
In this article

Share this article

The NIST Cybersecurity Framework (CSF) has become the default way most organisations structure their security programme — including a growing number of South African enterprises. CSF 2.0 added Govern as a sixth function, sharpening the link between strategic oversight and operational execution. This article walks through how to implement the framework in practice, how it interacts with POPIA and ISO 27001, and what a credible implementation actually delivers.

The short answer

Implementing NIST CSF 2.0 follows four steps: define the Target Profile aligned to business and regulatory drivers, assess the Current Profile across the six functions, map gaps against the 23 categories and over 100 subcategories, and execute a sequenced improvement programme tied to outcome metrics. Most organisations integrate it with ISO 27001 and POPIA controls rather than running in parallel.

NIST CSF increasingly supports board reporting, cyber insurance reviews, procurement assurance, operational resilience planning, and executive oversight of cyber risk.

The six functions — Govern, Identify, Protect, Detect, Respond, Recover

CSF 2.0 organises cybersecurity outcomes into six functions. Govern sets strategy and oversight. Identify catalogues, assets, risks, and dependencies. Protect implements controls. Detect surfaces that get through. Responds, contains, eradicates, and communicates. Recover restores operations and learns from the incident. The functions are interdependent — weakness in one creates cost in another.

Define a Target Profile before assessing the Current Profile

Implementation starts with the Target Profile — the outcomes the organisation needs to achieve, scaled to its sector, risk appetite, and regulatory environment. Defining the Target first prevents an implementation that simply assesses everything and produces no priorities. Target Profile statements are written at the category and subcategory level, with informative references to ISO 27001, NIST 800-53, and sector frameworks.

Subcategory mapping — where the real work is

CSF 2.0 has six functions, 23 categories, and over 100 subcategories. Subcategories are the operational unit — each one is a specific outcome (“PR.AA-01: Identities and credentials are issued, managed, verified, revoked, and audited for authorised devices, users, and services”). Subcategory-level mapping produces gap analyses fine-grained enough to be actioned; category-only mapping rarely is.

Tiering — the maturity layer most implementations skip

The NIST CSF defines four Implementation Tiers — Partial, Risk-Informed, Repeatable, and Adaptive — that describe how the organisation manages cybersecurity risk. Tiering is not a maturity score, but it does describe operating discipline. Many implementations skip it; doing so misses an opportunity to communicate posture to the board in a way that connects outcomes to the operating model.

Measuring CSF programme progress

A NIST CSF implementation only becomes meaningful when leadership can measure whether security outcomes are improving over time. Mature programmes track operational, governance, and resilience metrics to demonstrate whether risk-reduction activities translate into measurable capability improvements across the six functions.

Examples commonly tracked include:

  • Mean time to detect (MTTD) and mean time to contain (MTTC) security incidents
  • MFA coverage across privileged, remote-access, and business-critical accounts
  • Patch and vulnerability remediation compliance against defined SLA targets
  • Risk-treatment progress against the organisation’s prioritised remediation roadmap
  • Phishing reporting rates and user-behaviour improvement trends
  • Critical asset visibility and monitoring coverage across cloud, SaaS, and internal environments

These metrics help leadership evaluate whether cybersecurity investment is improving operational resilience, governance maturity, and incident readiness over time rather than simply increasing tooling spend.

Mature CSF implementations increasingly integrate supplier and SaaS risk visibility into the Govern and Identify functions through continuous third-party risk monitoring.

Integrating with ISO 27001 and POPIA

NIST CSF is a framework for structuring the programme; ISO 27001 is a certifiable management system; POPIA is a legal regime. Mature organisations integrate them — CSF subcategories map to ISO 27001 Annex A controls and POPIA Section 19 safeguards, producing a single body of evidence that satisfies multiple stakeholders. Running them as separate programmes creates duplicate work and inconsistent reporting.

Key Takeaways

  • CSF 2.0 has six functions — Govern is the new addition, sharpening the strategic-to-operational link.
  • Target Profile is defined first; Current Profile is assessed against it. Order matters.
  • Subcategory-level mapping (100+ subcategories) is what produces actionable gap analyses.
  • Implementation Tiers describe operating discipline — useful for board communication.
  • Integrate NIST CSF with ISO 27001 and POPIA — running them separately duplicates evidence and creates inconsistency.

How Cyber Resilience Can Help

Cyber Resilience helps organisations implement NIST CSF 2.0 through structured profile mapping, governance alignment, and operational improvement programmes integrated with ISO 27001 and POPIA requirements.

Speak to our team to arrange a NIST CSF readiness discussion.

Qurash Ramlal

Customer Success Manager | Governance & Security Advisory

Qurash Ramlal works closely with Cyber Resilience clients to support long-term cybersecurity maturity, governance alignment, and operational resilience improvement.

With experience across cybersecurity, telecommunications, and managed services environments, he focuses on helping organisations strengthen governance visibility, improve security awareness, and align operational security initiatives to evolving business risk.

Expertise

ISO 27001 • Managed Security Services • Governance • Client Success • Cybersecurity Advisory

Frequently asked questions

Do we need ISO 27001 if we already align with NIST CSF?

It depends on stakeholder expectations. NIST CSF is a framework; ISO 27001 is a certifiable management system. Customers, regulators, and insurers can independently verify ISO 27001 certification. Many organisations use NIST CSF for programme structure and ISO 27001 for certifiable governance.

How long does a NIST CSF implementation take?

Initial profile development and subcategory mapping typically takes six to twelve weeks. The improvement programme that follows is multi-year — moving from a Current Profile to a Target Profile across 100+ subcategories is not a sprint. Many organisations target measurable progress quarterly, with an annual full reassessment.

What is the difference between NIST CSF and NIST SP 800-53?

NIST CSF is a framework — outcomes and categories organised by function. NIST SP 800-53 is a control catalogue with hundreds of specific controls at multiple impact levels. CSF subcategories often reference SP 800-53 controls as informative references. Federal US agencies use SP 800-53 directly; private-sector organisations more often use CSF with selected 800-53 controls.

How does NIST CSF reporting work at board level?

Most organisations report function-level posture (six summary scores) with selected category and subcategory drill-down for material gaps or trending items. Tier classification, mean time to detect and contain, and material risks from the Identify function provide a defensible board summary.

Related Insights

Cyber resilience insights grounded in operational reality.

Practical guidance, operational perspectives, regulatory insights, and forensic-led thinking across cybersecurity, governance, resilience, and digital risk.

Need Clarity on your CURRENT RESILIENCE POSTURE?

Whether you need a focused assessment, operational support, governance maturity, or incident response guid-ance, we will help you understand your current position and build a practical path forward.