GRC › Module 4 › Lesson 2
NIST CSF Named
NIST CSF named literacy covers Identify, Protect, Detect, Respond, Recover functions and categories — map one fictional asset on YOUR $GRC_LAB to CSF outcomes.
Visual · t37_nist_csf_named
NIST CSF named literacy. $GRC_LAB only. Original Cyberlium.
Opening
NIST CSF organizes outcomes across five functions — literacy teaches CSF vocabulary so fictional org control gaps on $GRC_LAB align to a common US framework language.
The NIST Cybersecurity Framework 2.0 structures programs into Govern plus Identify, Protect, Detect, Respond, Recover — each with categories and subcategories describing outcomes, not prescriptive product lists. Profiles document current vs target state for YOUR fictional org sector on $GRC_LAB notes. Cyberlium maps CSF row on YOUR $GRC_LAB — function, category example, current vs target gap note for one fictional lab system. Next: Framework Fit.
1. CSF functions (named)
Govern: organizational context, roles, supply chain. Identify: asset management, risk assessment, improvement. Protect: access control, data security, training. Detect: monitoring, analysis. Respond: incident management. Recover: restoration, communications.
On $GRC_LAB, write CSF row — function, category ID example, gap note for one fictional asset.
Command guide
Try these commands — CSF functions (named)
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
NIST Cybersecurity Framework — https://www.nist.gov/cyberframework NIST CSF 2.0 — https://www.nist.gov/cyberframework CIS Controls — https://www.cisecurity.org/controls
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export GRC_LAB=${GRC_LAB:-$HOME/cyberlium-lab/t37-grc}
curl -sS https://www.nist.gov/cyberframework | head -10
cat > "$GRC_LAB/notes/nist-csf-named.txt" <<'EOF'
NIST Cybersecurity Framework — NAMED LITERACY:
Functions (CSF 2.0): Govern, Identify, Protect, Detect, Respond, Recover
Categories/Subcategories: outcome-based security activities
Profiles: current vs target state for YOUR org
Tiers: implementation maturity (Partial → Adaptive)
Use: communicate risk posture to leadership — map controls to subcategories
Lab: nist-csf-mapping-stub.md — fictional LAB-ORG-001 cross-reference
EOFCommand — copy this
grep -E 'Govern|Identify|Protect|Profiles' "$GRC_LAB/notes/nist-csf-named.txt" curl -sS https://www.nist.gov/cyberframework | head -5
Primary tools to practice this lesson: curl, grep. Reference sites: NIST Cybersecurity Framework (https://www.nist.gov/cyberframework); NIST CSF 2.0 (https://www.nist.gov/cyberframework); CIS Controls (https://www.cisecurity.org/controls). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Why CSF literacy complements ISO conversations
US federal contractors and critical infrastructure often reference NIST CSF — crosswalks to ISO Annex A exist for integrated programs. Outcome language helps board slides without product jargon on lab templates.
Students map lab CSF profiles on notes — production profiles follow sector-specific guidance and agency requirements.
3. Lab boundary
Forbidden: claiming NIST CSF profile completion certifies legal compliance. Allowed: NIST CSF named card — function map with $GRC_LAB fictional example.
Ship: NIST CSF named card for YOUR lab org. Next: Framework Fit.
4. What you ship: NIST CSF named card for $GRC_LAB
Function, category, current vs target gap. $GRC_LAB named. chmod 600.
5. What you record before the next lesson
Date. NIST CSF card. $GRC_LAB named. File t37-m04-l02-nist-csf-named.txt chmod 600.
6. Wrong vs right: fraudulent certs vs YOUR lab templates
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Copy full NIST publication into lab notes as compliance proof. Skip Govern function entirely.
Right
Write NIST CSF named card for YOUR $GRC_LAB. Next: Framework Fit.
Mission: map NIST CSF on YOUR lab asset
1) Name five core functions plus Govern. 2) Pick one category per Protect and Detect. 3) Write current vs target gap sentence. 4) chmod 600.
Stuck? Ask Cyberlium AI Mentor
CSF describes outcomes — map YOUR controls to categories, do not buy checklist theater.
Knowledge Check
APPLY: NIST CSF functions include:
Multiple choice
Knowledge Check
APPLY: True or False: CSF categories describe outcomes — not mandatory product lists.
True or False
Knowledge Check
APPLY: NIST CSF literacy on Cyberlium uses:
Multiple choice