Episode Details
Back to Episodes
NIST CSF 2.0: No CISO, No Excuse
Description
The new NIST Cybersecurity Framework 2.0 is out, and most teams still ask the same question: what do I do tomorrow? Lieuwe Jan Koning sits down with NIST's Amy Mahn and Daniel Elliott to turn the framework into a concrete next step. Governance is now its own function. Profiles tell you where you are and where you need to be. And the Quick Start Guides give a 15-page answer to a problem most people think needs 300 pages.
If you run security with limited resources, this episode shows you where to start and why the whole thing is free.
Timestamps
- (00:00) - The framework changed. What do you do tomorrow?
- (02:00) - Why Govern became its own function
- (05:49) - Profiles: current state, target state, gap analysis
- (08:08) - Community profiles: sharing across a sector
- (10:29) - Quick Start Guides and mappings to ISO 27001, SOC 2, HIPAA
- (14:24) - No CISO? Where small businesses start
- (17:50) - The future of CSF and how to contribute
Key Topics Covered
- Why governance moved out of "Identify" and became its own function in CSF 2.0, and what that signals about cyber risk at board level.
- How organizational and community profiles turn the framework into a current-state, target-state, and gap analysis you can act on.
- Why CSF 2.0 stopped being a single PDF and became guides, spreadsheets, mappings, and search tools.
- How CSF maps to ISO 27001, SOC 2, and HIPAA so you report once instead of many times.
- Where a small business or an IT manager wearing every hat should actually begin.
Related ON2IT Content & Referenced Resources:
NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework
NIST CSF Quick Start Guides: https://www.nist.gov/cyberframework/quick-start-guides
National Cybersecurity Center of Excellence (NCCoE): https://www.nccoe.nist.gov/
NIST CSF contact: csf@nist.gov
Threat Talks website: https://threat-talks.com/