HERM records what the institution runs and how sensitive each system is. The NIST CSF adds how well each of those is defended — a common language for security posture that maps straight onto the classification and criticality already in the model.
The NIST Cybersecurity Framework is a voluntary, widely adopted framework for managing cybersecurity risk. Its core organizes security work into a small set of functions, each broken into categories and outcomes, so an institution can describe its current posture, set a target, and close the gap in a shared vocabulary.
Its purpose is the question that follows the moment you know what you run: how well is each of these defended, and where is the risk concentrated. It turns a sensitivity label into a program.
CSF 2.0 organizes cybersecurity into six functions, with Govern wrapping the other five. Each runs on data the estate model already holds. Adapted from the NIST Cybersecurity Framework 2.0.
Identify and Recover lean directly on the model: Identify is the estate inventory; Recover follows each system's recovery tier.
The CSF's first function is Identify — know your assets, data, and risk. That is precisely what the estate model is. Pair them and the framework starts from a real inventory instead of a blank page, and security posture attaches to systems that already carry sensitivity and criticality.
The asset and data inventory the CSF asks for is the catalog you have already built.
Each system's data classification sets how strongly it must be protected — no separate risk survey.
The recovery tier already on each system is the restoration order the Recover function needs.
Extending the model toward the CSF means adding a security-posture layer to each record. A pragmatic starting set:
Where each system stands against each CSF function today, and where it needs to be.
Which safeguards apply to a system — access control, encryption, monitoring, backup.
Likelihood and impact per system, informed by its classification and criticality.
Whether a system is actively monitored, and by what.
Past events touching a system — the evidence trail for Respond and Recover.
Which regulations or policies each system must satisfy.
Start with the most sensitive systems the model already flags. Rate each against the six functions, and the gap between current and target posture becomes a prioritized security roadmap — anchored to the systems that would hurt most if they failed.
The NIST Cybersecurity Framework is published by the U.S. National Institute of Standards and Technology. This page describes how it complements HERM; profiles, ratings, and control coverage are local extensions.