The US NIST cybersecurity framework — voluntary in origin, but the de-facto common language for ICT and cyber risk in the financial sector worldwide.
The NIST Cybersecurity Framework (CSF) was first published in 2014 by the US National Institute of Standards and Technology and updated to CSF 2.0 in 2024. It organises cybersecurity practice into six core Functions — Govern, Identify, Protect, Detect, Respond, Recover — each broken down into Categories and Subcategories, with implementation tiers and target profiles.
Although NIST CSF is a US voluntary framework, it has become the lingua franca of cyber risk management in the financial sector worldwide. EBA ICT Risk Guidelines, DORA, ECB cyber expectations and national regulators all use NIST CSF terminology in supervisory dialogue. Vendor-risk questionnaires, internal audit plans and board-level cyber reports routinely use its Function/Category structure.
Bucephalus security and operations documentation maps to both ISO 27001 and NIST CSF Functions, so that institutions whose audit programme is anchored in either framework can find their expected control vocabulary.