NIST CSF (Cybersecurity Framework)
A globally adopted framework for organising cybersecurity risk, with identity sitting at the centre of Protect, and increasingly, Detect.
What is the NIST CSF?
The NIST Cybersecurity Framework, now in its 2.0 revision, organises cybersecurity activity into six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. It isn't a certification like ISO 27001: it's a common language for describing cybersecurity risk and maturity, widely used by boards, regulators, and insurers as a benchmark.
Identity and access management sits squarely inside the Protect function, and increasingly inside Detect too, as identity-based attacks have become the dominant breach vector.
CSF 2.0's addition of the Govern function is the most consequential change for identity programmes: it requires leadership accountability for cybersecurity risk decisions, not just technical controls, so an identity strategy now needs a named owner and a documented risk appetite, not just a working provisioning system. The Protect function's PR.AA category (Identity Management, Authentication, and Access Control) is the direct home for IAM work; most gap assessments we run find PR.AA sub-categories scored inconsistently across business units using the very same platform, because ownership, not technology, turns out to be the actual gap.
How IAM Tech helps
We map your existing identity controls against the CSF's functions, identify the gaps that matter most, and prioritise remediation using the same risk-based structure NIST recommends, not a generic checklist.
- Current-state assessment mapped to CSF functions and categories
- Access control design aligned to the Protect function
- Continuous, behaviour-based monitoring aligned to the Detect function
- Board-ready maturity reporting, not just a technical scorecard
Common questions
Is NIST CSF mandatory?
Not directly for most UK/EU organisations: it's a US-originated voluntary framework. It's increasingly used regardless as a common benchmark, because boards, cyber insurers, and regulators outside the US reference its maturity tiers as a shared language, even where a different formal regulation actually applies.
How does NIST CSF relate to ISO 27001?
They overlap heavily but aren't interchangeable: ISO 27001 is a certifiable management-system standard with an external audit; CSF is a self-assessed maturity framework with no certification. Many organisations map their ISO 27001 controls against CSF categories to get a maturity view without running two entirely separate assessments.
What is the PR.AA category in NIST CSF 2.0?
PR.AA (Identity Management, Authentication, and Access Control) is the specific Protect-function category identity and access management work maps onto: covering identity proofing, credential management, authentication, authorization, and access revocation for both human and non-human identities.
