> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# NIST CSF

> Implement the original NIST Cybersecurity Framework (v1.1) across five core functions.

> Implement the original NIST Cybersecurity Framework (v1.1) across five core functions.

The NIST Cybersecurity Framework (CSF) 1.1 is a voluntary framework from the U.S. National Institute of Standards and Technology. It organizes cybersecurity activities into five core functions — Identify, Protect, Detect, Respond, and Recover — providing a common language for managing and reducing cyber risk.

<Note>
  If you are starting fresh, consider NIST CSF 2.0, which adds the Govern function. CSF 1.1 remains widely referenced in existing contracts and programs.
</Note>

## Who needs NIST CSF?

<CardGroup cols={2}>
  <Card title="Critical infrastructure" icon="industry">
    Originally designed for the 16 critical infrastructure sectors, including energy, finance, and healthcare.
  </Card>

  <Card title="Maturing security programs" icon="chart-line">
    Organizations building a structured, risk-based security program from the ground up.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Identify" icon="magnifying-glass">
    Develop organizational understanding of cybersecurity risk to systems, assets, data, and capabilities.
  </Card>

  <Card title="Protect" icon="shield">
    Develop and implement safeguards to ensure delivery of critical services.
  </Card>

  <Card title="Detect" icon="radar">
    Implement activities to identify the occurrence of a cybersecurity event.
  </Card>

  <Card title="Respond" icon="bolt">
    Take action regarding a detected cybersecurity incident.
  </Card>

  <Card title="Recover" icon="arrows-rotate">
    Maintain plans for resilience and restore capabilities impaired by incidents.
  </Card>
</CardGroup>

## How DSALTA helps with NIST CSF

<Steps>
  <Step title="Activate NIST CSF">
    Select NIST CSF from the Frameworks page. DSALTA maps all five functions to pre-built controls.
  </Step>

  <Step title="Review mapped controls">
    Review controls across the five functions and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations for continuous automated evidence collection.
  </Step>

  <Step title="Approve policies">
    Review and approve AI-generated policies mapped to CSF outcomes.
  </Step>

  <Step title="Track readiness">
    Monitor your maturity and coverage across all functions.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Should I use CSF 1.1 or 2.0?" icon="code-compare">
    New programs should generally adopt CSF 2.0 for its added Govern function and broader applicability. Use 1.1 if your contracts or existing program specifically reference it.
  </Accordion>

  <Accordion title="Is NIST CSF mandatory?" icon="scale-balanced">
    It is voluntary for most private organizations, though some federal contracts and sector regulators require alignment.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
