Crowdstrike reported a 75% increase in cloud environment intrusions from 2022 to 2023 ( shows that the global average cost of a data breach in 2024 is USD 4.88M, a 10% increase over last year and the highest total ever. Cyber attacks would scale much faster with the help of artificial intelligence. If organizations are not prepared, the consequences will be dire.
There are many security frameworks that can help organizations enable security and safety for their applications and users. In this blog post, we will discuss NIST CSF, one of the most used security frameworks that helps organizations understand and prevent cybersecurity risks. We will cover the key enhancements in NIST CSF 2.0 briefly, explain the primary components of CSF in detail, and show the best practices for maintaining NIST CSF in the cloud.
What is NIST CSF?
The NIST Cybersecurity Framework is designed to help private sector organizations evaluate and enhance their capacity to prevent, detect, and respond to cyber-attacks. The framework is meant to supplement an organization's current risk management and cybersecurity procedures.
We can call it an add-on to an organization’s existing information/cyber security posture. The framework offers recommendations based on best practices and industry standards. It assists businesses of all sizes, from startups to major corporations, in determining the best course of action for enhancing cyber-security and cyber resilience and evaluating the present level of their cyber-security processes. In February 2024, NIST introduced NIST CSF v2.0 with several upgrades.
Key enhancements in NIST CSF 2.0
CSF 1.1 has 5 functions, 23 categories, and 108 subcategories. The CSF 2.0 has 6 functions, 22 categories, and 106 subcategories. CSF 2.0 is an extension of CSF 1.1 that includes several category realignments and the addition of the ‘Govern’ function.
Here are key enhancements in NIST CSF 2.0:
Supply Chain Risk Management (SCRM): NIST CSF 2.0 places a greater emphasis on SCRM. Given the rise of supply chain attacks, organizations are now encouraged to manage risks not only within their systems but also across their entire supply chain.
Identity Management and Access Control: Enhanced guidelines for managing identities and access controls are included, reflecting the critical role these elements play in securing organizational infrastructure.
Measurement and Metrics: The updated framework provides improved guidelines on measuring the effectiveness of cybersecurity practices, helping organizations to continuously assess and enhance their security posture.
Integration with Privacy Framework: NIST CSF 2.0 is more closely aligned with , helping organizations to better assess their current cybersecurity posture and set realistic improvement goals.
Best practices for maintaining NIST CSF Compliance in the cloud
Know your cloud service provider's security measures: The first step towards maintaining NIST CSF compliance in the cloud is understanding your cloud service provider's security measures and the service alignment with the NIST CSF framework. All major cloud service providers have stringent security controls in place, but it is important to familiarize yourself with them and ensure they align with the NIST CSF framework.
Use encryption for data protection: Encryption is a key component of data protection and a crucial aspect of NIST CSF compliance. Make sure all sensitive data stored or transmitted on your cloud infrastructure is encrypted using approved algorithms. This includes data at rest as well as data in transit.
Implement access controls: Controlling access to resources within your cloud environment is vital for maintaining NIST CSF compliance. Utilize Identity and Access Management (IAM) tools provided by your cloud service provider to manage user permissions and privileges effectively.
Regularly monitor your cloud environment: Monitoring your cloud infrastructure regularly helps detect any potential vulnerabilities or suspicious activities that could compromise your organization's security posture. Set up alerts to track any unusual activity or changes made within your environment.
Conduct regular risk assessments: Conducting regular risk assessments allows you to identify potential risks within your environment and take steps to mitigate them before they turn into serious threats. This practice also aligns with one of the core functions of the NIST CSF - Identity.
Implement multi-factor authentication (MFA): MFA adds an extra layer of security to user authentication by requiring additional verification methods, such as a one-time password or biometric scan. This helps prevent unauthorized access and is recommended by the NIST CSF framework.
Keep your cloud infrastructure up-to-date: Regularly updating your cloud infrastructure and applications is crucial for maintaining NIST CSF-2.0 compliance. By doing this, the likelihood of a cyberattack is decreased by ensuring that any known vulnerabilities are patched.
Following these best practices will help organizations maintain NIST CSF compliance in their cloud environment and ensure the security of their critical assets and information. It is also important to note that maintaining compliance is an ongoing process, and regular audits should be conducted to identify any gaps or areas for improvement. By staying vigilant and following these practices, businesses can strengthen their security posture and protect themselves from potential cyber threats in the cloud.
Various public cloud services aligned with NIST CSF 2.0
When using the public cloud, there are multiple native services available that can help us align with the NIST CSF and improve the overall security posture. The table below maps the cloud services with the primary functions of NIST primary functions. Below is a list of various native services supported by various cloud providers at the time we were writing the blog.
| CSF Function | AWS | GCP | Azure |
|---|---|---|---|
| Govern | AWS Identity and Access Management (IAM) AWS Organizations AWS CloudTrail AWS Config AWS Artifact AWS Compliance Center | Security Command Center Policy Intelligence Cloud deployment manager Supply chain (GKE Security posture) Policy Compliance(GKE Security posture) | Azure Policy Azure Blueprints Azure Compliance Manager Azure Security Center Azure Monitor Azure Governance Visualizer (AzGovViz) Microsoft Compliance Score |
| Identify | AWS Config AWS CloudTrail Amazon Inspector AWS Risk and Compliance Program: AWS Cloud Adoption Framework (CAF) | Cloud identity and access management Cloud asset inventory Security command center GKE security posture | Azure Security Center Azure Active Directory (Azure AD) Azure Policy Azure Blueprints Azure Advisor |
| Protect | AWS Identity and Access Management (IAM) Amazon Virtual Private Cloud (VPC) AWS Key Management Service (KMS) AWS Shield AWS WAF Amazon GuardDuty AWS Certificate Manager AWS CloudTrail AWS Config | Cloud identity and access management Vpc service controls Shielded VM’s Security Command Center Policy Intelligence Cloud deployment manager Access approval API | Azure Active Directory (Azure AD) Azure Information Protection Azure Security Center Azure Firewall Azure Key Vault Azure Multi-Factor Authentication (MFA) Azure Virtual Network |
| Detect | Amazon GuardDuty AWS CloudTrail Amazon Macie AWS Network Firewall Amazon CloudWatch AWS Config | Security Command Center Event threat detection Cloud logging and cloud monitoring GKE Security posture | Azure Security Center Azure Sentinel Azure Monitor Microsoft Defender for Cloud (formerly Azure Security Center) |
| Respond | AWS Lambda Amazon Simple Notification Service (SNS) AWS CloudWatch AWS Step Functions AWS Security Hub Amazon Detective | Security Command Center Event threat detection Cloud functions and pub/sub Cloud logging and cloud monitoring | Azure Security Center Azure Sentinel Azure Monitor Microsoft Defender for Endpoint Azure Logic Apps |
| Recover | AWS Backup Amazon S3 Glacier AWS CloudFormation Amazon Route 53 AWS Elastic Beanstalk AWS CloudEndure Disaster Recovery | Google cloud storage Persistent disk storage Cloud SQL backups Cloud KMS Google Kubernetes Engine(GKE) backups Disaster recovery planning guide | Azure Backup Azure Site Recovery Azure Storage |
Final words
NIST CSF-2.0 is an impressive framework that covers all aspects of cybersecurity, its redesigned structure now involves and focuses on topics that were taken lightly in the past by organizations like open source compliance management. It is the cherry on top of current best practices which can guide organizations to streamline their cybersecurity posture.
I hope you found this blog post informative and engaging. I’d love to hear your thoughts on this post. Let’s connect and start a conversation on .
SOCIAL SHARE CARD GENERATOR