National framework

NIST Cybersecurity Framework (NIST CSF)

The US NIST cybersecurity framework — voluntary in origin, but the de-facto common language for ICT and cyber risk in the financial sector worldwide.

What it is

The NIST Cybersecurity Framework (CSF) was first published in 2014 by the US National Institute of Standards and Technology and updated to CSF 2.0 in 2024. It organises cybersecurity practice into six core Functions Govern, Identify, Protect, Detect, Respond, Recover — each broken down into Categories and Subcategories, with implementation tiers and target profiles.

Why a European bank should know it

Although NIST CSF is a US voluntary framework, it has become the lingua franca of cyber risk management in the financial sector worldwide. EBA ICT Risk Guidelines, DORA, ECB cyber expectations and national regulators all use NIST CSF terminology in supervisory dialogue. Vendor-risk questionnaires, internal audit plans and board-level cyber reports routinely use its Function/Category structure.

See also

How this matters in our work

Bucephalus security and operations documentation maps to both ISO 27001 and NIST CSF Functions, so that institutions whose audit programme is anchored in either framework can find their expected control vocabulary.