🔧 AI Nachrichten Major AI platforms go down in unprecedented simultaneous outage(03.09.2026 um 17:34 Uhr)
🔧 AI Nachrichten ChatGPT, Claude, and Grok Down? Users Report Widespread Outages(03.09.2026 um 19:14 Uhr)
🔧 AI Nachrichten OpenAI Launches GPT-6 Astra, Says We May Have Entered the AGI Era(03.09.2026 um 22:08 Uhr)
🔧 AI Nachrichten Claude Comes to CarPlay as Fifth Major AI Chatbot App(05.09.2026 um 05:31 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra Is AGI, Says NVIDIA CEO Jensen Huang(07.09.2026 um 06:31 Uhr)
🔧 AI Nachrichten Blame AI companies for Mac mini and Mac Studio shortage(31.08.2026 um 10:32 Uhr)
🔧 AI Nachrichten Major AI platforms go down in unprecedented simultaneous outage(03.09.2026 um 17:34 Uhr)
🔧 AI Nachrichten ChatGPT, Claude, and Grok Down? Users Report Widespread Outages(03.09.2026 um 19:14 Uhr)
🔧 AI Nachrichten OpenAI Launches GPT-6 Astra, Says We May Have Entered the AGI Era(03.09.2026 um 22:08 Uhr)
🔧 AI Nachrichten Claude Comes to CarPlay as Fifth Major AI Chatbot App(05.09.2026 um 05:31 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra Is AGI, Says NVIDIA CEO Jensen Huang(07.09.2026 um 06:31 Uhr)
🔧 AI Nachrichten Blame AI companies for Mac mini and Mac Studio shortage(31.08.2026 um 10:32 Uhr)

🔧 Programmierung 🕛 kürzlich 12 Min Lesezeit SECURITY-FEED
0

Streamline Your Organization Security Posture with NIST CSF 2.0

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

Crowdstrike reported a 75% increase in cloud environment intrusions from 2022 to 2023 ( shows that the global average cost of a data breach in 2024 is USD 4.88M, a 10% increase over last year and the highest total ever. Cyber attacks would scale much faster with the help of artificial intelligence. If organizations are not prepared, the consequences will be dire.



There are many security frameworks that can help organizations enable security and safety for their applications and users. In this blog post, we will discuss NIST CSF, one of the most used security frameworks that helps organizations understand and prevent cybersecurity risks. We will cover the key enhancements in NIST CSF 2.0 briefly, explain the primary components of CSF in detail, and show the best practices for maintaining NIST CSF in the cloud.






What is NIST CSF?



The NIST Cybersecurity Framework is designed to help private sector organizations evaluate and enhance their capacity to prevent, detect, and respond to cyber-attacks. The framework is meant to supplement an organization's current risk management and cybersecurity procedures.



We can call it an add-on to an organization’s existing information/cyber security posture. The framework offers recommendations based on best practices and industry standards. It assists businesses of all sizes, from startups to major corporations, in determining the best course of action for enhancing cyber-security and cyber resilience and evaluating the present level of their cyber-security processes. In February 2024, NIST introduced NIST CSF v2.0 with several upgrades.






Key enhancements in NIST CSF 2.0



CSF 1.1 has 5 functions, 23 categories, and 108 subcategories. The CSF 2.0 has 6 functions, 22 categories, and 106 subcategories. CSF 2.0 is an extension of CSF 1.1 that includes several category realignments and the addition of the ‘Govern’ function.



Here are key enhancements in NIST CSF 2.0:





  1. Supply Chain Risk Management (SCRM): NIST CSF 2.0 places a greater emphasis on SCRM. Given the rise of supply chain attacks, organizations are now encouraged to manage risks not only within their systems but also across their entire supply chain.


  2. Identity Management and Access Control: Enhanced guidelines for managing identities and access controls are included, reflecting the critical role these elements play in securing organizational infrastructure.


  3. Measurement and Metrics: The updated framework provides improved guidelines on measuring the effectiveness of cybersecurity practices, helping organizations to continuously assess and enhance their security posture.


  4. Integration with Privacy Framework: NIST CSF 2.0 is more closely aligned with , helping organizations to better assess their current cybersecurity posture and set realistic improvement goals.








Best practices for maintaining NIST CSF Compliance in the cloud




  1. Know your cloud service provider's security measures: The first step towards maintaining NIST CSF compliance in the cloud is understanding your cloud service provider's security measures and the service alignment with the NIST CSF framework. All major cloud service providers have stringent security controls in place, but it is important to familiarize yourself with them and ensure they align with the NIST CSF framework.


  2. Use encryption for data protection: Encryption is a key component of data protection and a crucial aspect of NIST CSF compliance. Make sure all sensitive data stored or transmitted on your cloud infrastructure is encrypted using approved algorithms. This includes data at rest as well as data in transit.


  3. Implement access controls: Controlling access to resources within your cloud environment is vital for maintaining NIST CSF compliance. Utilize Identity and Access Management (IAM) tools provided by your cloud service provider to manage user permissions and privileges effectively.


  4. Regularly monitor your cloud environment: Monitoring your cloud infrastructure regularly helps detect any potential vulnerabilities or suspicious activities that could compromise your organization's security posture. Set up alerts to track any unusual activity or changes made within your environment.


  5. Conduct regular risk assessments: Conducting regular risk assessments allows you to identify potential risks within your environment and take steps to mitigate them before they turn into serious threats. This practice also aligns with one of the core functions of the NIST CSF - Identity.


  6. Implement multi-factor authentication (MFA): MFA adds an extra layer of security to user authentication by requiring additional verification methods, such as a one-time password or biometric scan. This helps prevent unauthorized access and is recommended by the NIST CSF framework.


  7. Keep your cloud infrastructure up-to-date: Regularly updating your cloud infrastructure and applications is crucial for maintaining NIST CSF-2.0 compliance. By doing this, the likelihood of a cyberattack is decreased by ensuring that any known vulnerabilities are patched.




Following these best practices will help organizations maintain NIST CSF compliance in their cloud environment and ensure the security of their critical assets and information. It is also important to note that maintaining compliance is an ongoing process, and regular audits should be conducted to identify any gaps or areas for improvement. By staying vigilant and following these practices, businesses can strengthen their security posture and protect themselves from potential cyber threats in the cloud.






Various public cloud services aligned with NIST CSF 2.0



When using the public cloud, there are multiple native services available that can help us align with the NIST CSF and improve the overall security posture. The table below maps the cloud services with the primary functions of NIST primary functions. Below is a list of various native services supported by various cloud providers at the time we were writing the blog.


















































CSF Function AWS GCP Azure
Govern AWS Identity and Access Management (IAM)
AWS Organizations
AWS CloudTrail
AWS Config
AWS Artifact
AWS Compliance Center
Security Command Center
Policy Intelligence
Cloud deployment manager
Supply chain (GKE Security posture)
Policy Compliance(GKE Security posture)
Azure Policy
Azure Blueprints
Azure Compliance Manager
Azure Security Center
Azure Monitor
Azure Governance Visualizer (AzGovViz)
Microsoft Compliance Score
Identify AWS Config
AWS CloudTrail
Amazon Inspector
AWS Risk and Compliance Program:
AWS Cloud Adoption Framework (CAF)
Cloud identity and access management
Cloud asset inventory
Security command center
GKE security posture
Azure Security Center
Azure Active Directory (Azure AD)
Azure Policy
Azure Blueprints
Azure Advisor
Protect AWS Identity and Access Management (IAM)
Amazon Virtual Private Cloud (VPC)
AWS Key Management Service (KMS)
AWS Shield
AWS WAF
Amazon GuardDuty
AWS Certificate Manager
AWS CloudTrail
AWS Config
Cloud identity and access management
Vpc service controls
Shielded VM’s
Security Command Center
Policy Intelligence
Cloud deployment manager
Access approval API
Azure Active Directory (Azure AD)
Azure Information Protection
Azure Security Center
Azure Firewall
Azure Key Vault
Azure Multi-Factor Authentication (MFA)
Azure Virtual Network
Detect Amazon GuardDuty
AWS CloudTrail
Amazon Macie
AWS Network Firewall
Amazon CloudWatch
AWS Config
Security Command Center
Event threat detection
Cloud logging and cloud monitoring
GKE Security posture
Azure Security Center
Azure Sentinel
Azure Monitor
Microsoft Defender for Cloud (formerly Azure Security Center)
Respond AWS Lambda
Amazon Simple Notification Service (SNS)
AWS CloudWatch
AWS Step Functions
AWS Security Hub
Amazon Detective
Security Command Center
Event threat detection
Cloud functions and pub/sub
Cloud logging and cloud monitoring
Azure Security Center
Azure Sentinel
Azure Monitor
Microsoft Defender for Endpoint
Azure Logic Apps
Recover AWS Backup
Amazon S3 Glacier
AWS CloudFormation
Amazon Route 53
AWS Elastic Beanstalk
AWS CloudEndure Disaster Recovery
Google cloud storage
Persistent disk storage
Cloud SQL backups
Cloud KMS
Google Kubernetes Engine(GKE) backups
Disaster recovery planning guide
Azure Backup
Azure Site Recovery
Azure Storage





Final words



NIST CSF-2.0 is an impressive framework that covers all aspects of cybersecurity, its redesigned structure now involves and focuses on topics that were taken lightly in the past by organizations like open source compliance management. It is the cherry on top of current best practices which can guide organizations to streamline their cybersecurity posture.



I hope you found this blog post informative and engaging. I’d love to hear your thoughts on this post. Let’s connect and start a conversation on .






References



Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
3 Quellen
GPT-6 Astra Release Today? OpenAI’s Next Major AI Model Is Almost Here
1 Quelle
Apple accuses OpenAI of destroying evidence as trade-secrets fight intensifies
1 Quelle
Major AI platforms go down in unprecedented simultaneous outage
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Streamline Your Organization Security Posture with NIST CSF 2.0

Thematisch verwandte Begriffe: Streamline, Your, Organization, Security · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...