Toolkit · Security · about 5 minutes
NIST CSF 2.0 Readiness Check
The framework cannot be failed, which is why nothing here is scored as a hard stop. What it can be is meaningless, and that happens when an organisation adopts the vocabulary without ever setting a target profile. The Govern questions are really testing for that.
23 questions. Nothing is sent anywhere as you answer, the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.
Govern
Added as a full function in version 2.0, and the one that decides whether the rest is real.
Is there a defined target profile stating what maturity you intend to reach, rather than only a description of where you are?
Without a target, the framework describes your current state and asks nothing of you.
Is cybersecurity risk expressed in terms leadership can act on, and reviewed by them?
Are roles, responsibilities and authorities for cybersecurity defined and understood?
Is supply chain cybersecurity risk managed as a defined programme rather than per contract?
Are policies established, communicated and reviewed on a schedule?
Identify
Knowing what you have and what threatens it.
Is there a maintained inventory of hardware, software, services and data, including what is externally hosted?
Are assets prioritised by criticality to the business rather than treated uniformly?
Is there a documented risk assessment process producing a current, owned risk register?
Are improvements identified from exercises, incidents and reviews fed back into the programme?
Protect
The safeguards themselves.
Is multi-factor authentication enforced on remote access, administrative accounts and cloud services?
Is access managed through a joiners, movers and leavers process with periodic review?
Is data protected at rest and in transit, with protections matched to how the data is classified?
Is there a patch and configuration management process with defined timeframes?
Is security awareness training delivered, recorded and refreshed?
Detect
Whether you would notice.
Is security-relevant logging collected centrally from endpoints, servers, network and cloud?
Are alerts triaged by a named owner with a recorded outcome, rather than accumulating unread?
Is detection coverage assessed against the techniques that would actually be used against you?
Are logs retained long enough to investigate an intrusion discovered months later?
Respond and Recover
What happens next, and how you get back.
Is there an incident response plan with defined severities, roles and external contacts?
Has the plan been exercised with the people who would run it, including leadership?
Are backups held where a compromised administrator account cannot reach them, and restore-tested?
Is there a defined recovery sequence stating which systems return first and what depends on what?
Is there a communications plan for notifying customers, regulators and staff during an incident?