About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Environmental, Social and Governance Services ERP & Enterprise Software Advisory Fraud & Forensics SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Insights & Events

At RubinBrown, we provide valuable insights detailing emerging trends and industry-specific information. Our events, hosted virtually and in-person, keep you informed and connected to the topics and industries that matter most to you and your organization.

View All Insights & Events
Jun 11

RubinBrown’s Leveraging Technology for Business Success

Learn More & Register
Jun 17

RubinBrown’s Rural Health Webinar Series

Learn More & Register
Jul 15

RubinBrown’s Provider Education Portal Webinar: E/M Essentials for Residents

Learn More & Register

FASB Proposes Update To Enhance Guidance On Debt Modifications And Extinguishments

Learn More

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to Insights

Navigating the NIST Cybersecurity Framework 2.0: What You Need to Know

Contact Us

Navigating the NIST Cybersecurity Framework 2.0: What You Need to Know

Contact Us

The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) stands as a versatile security blueprint applicable across all industry segments. Its flexibility allows organizations to customize and scale the framework to suit their unique needs. On February 26, 2024, NIST released version 2.0 of the CSF, introducing pivotal enhancements to bolster its accessibility and adaptability, aiding organizations in managing and mitigating cybersecurity risks effectively.

The new framework has significant changes that help organizations manage and reduce cybersecurity risks more effectively. These changes also make it easier for all users to navigate and utilize the framework. Transitioning to the new standards will take time and effort. The end result will be standards that are better suited to each organization's risk tolerance, industry, size, and operational needs.

Key among the changes in the NIST CSF 2.0 are:

An Increased Focus on Governance

“Govern” has been added as a sixth core function, joining Identify, Protect, Detect, Respond, and Recover as the primary areas of focus in a cybersecurity program. The addition of the “Govern” function in the NIST CSF 2.0 highlights the critical role that governance plays in an organization’s cybersecurity risk management strategy.

The function involves activities to create and enforce policies for the organization's cybersecurity program. This includes defining the organization’s cybersecurity strategy, roles and responsibilities, and resource allocation. It also includes oversight and monitoring of cybersecurity activities to ensure compliance with policies and standards.

Good governance is important to make sure a company's cybersecurity practices match its goals and risk tolerance. Governance helps prioritize cybersecurity, allocate resources, and measure effectiveness of cybersecurity efforts in an organization.

The function involves creating a cybersecurity structure with clear roles. It also includes conducting risk assessments and audits to find and mitigate cybersecurity risks. It also requires developing and enforcing, cybersecurity policies to help ensure consistency and continuity. Lastly, it emphasizes security training and awareness programs to make employees key security assets.
The NIST Cybersecurity Framework encourages organizations to be proactive in managing cybersecurity risks by adding the Govern function. This helps organizations identify their security strengths and weaknesses. It also helps them make informed decisions about investing in cybersecurity tools and resources. Additionally, it promotes a culture of security awareness and accountability within the organization.

The Significance of the Supply Chain has Increased.

Managing supply chain risk is now a top priority due to the current threat landscape and interconnected operating environments. NIST CSF 2.0 effectively addresses these risks.
NIST has added a new section to focus on Cybersecurity Supply Chain Risk Management (C-SCRM) within the "Govern" function. It outlines the main goals for organizations in C-SCRM. Organizations can use the new Quick-Start Guide in the NIST Cybersecurity Framework 2.0. This guide can help them assess their current C-SCRM capability. They can use CSF to identify, prioritize and mitigate risks in their supply chain. They can then establish procedures to address these risks and continually enhance their C-SCRM program.

Securing the supply chain protects the organization’s IT assets, and business operations, and fosters the trust of their customers and partners. Additionally, they can ensure that their supply chain is able to withstand evolving threats. Ultimately, effective  risk management is essential for building a strong cybersecurity posture and safeguarding the overall security and resilience of the organization.

Greater Customization Options

The updated CSF now has tiers and organizational profiles. Organizations can tailor them to their specific needs and security requirements. The customization makes it easy to compare to standard profiles. These profiles are based on industry, risk, and importance.

This flexibility helps organizations prioritize their security efforts and resources. It allows them to meet their specific requirements. Organizations can compare their current security posture (profile) against a standard industry profile which also shows how well an organization's security measures align with industry standards. This allows for easy comparison to standard profiles based on industry, risk, and importance.

This flexibility helps organizations prioritize their security efforts and resources according to their specific requirements. Comparing against standard profiles also gives insight into how well an organization's security measures align with industry standards.

Overall, the updated CSF will enhance organizational security maturity, improve risk management strategies, and ultimately strengthen the overall cybersecurity posture. The CSF will help organizations protect their important assets and data from cyber threats by offering a personalized security approach.  

New Tools and Resources for CSF 2.0 in 2024

NIST has added new tools to the updated CSF to make it easier for people to use. These tools include quick start guides, implementation examples, and informative references.
The quick start guides provide organizations with a plan for using the CSF. This makes the process easier by breaking it down into simple steps. This helps companies start faster and more efficiently, saving time and resources needed for implementation.

Implementation examples offer real-world scenarios and case studies of how organizations have successfully implemented the CSF. These examples can serve as inspiration for companies looking to adopt the framework and provide valuable insights into best practices.

Informative references provide additional resources and guidance on specific topics related to cybersecurity, helping organizations navigate complex issues and make informed decisions. By offering a wealth of information and support, NIST is making it easier for companies to adopt the CSF and improve their cybersecurity posture.

We Can Help

RubinBrown’s dedicated team of cyber security professionals understands the nuances of CSF 2.0 and will be ready to assist organizations with upgrading their standards from previous versions of NIST or transitioning from other frameworks.

For more information about the new NIST CSF 2.0, or to inquire about our cyber-health checkup, security assessment, penetration testing, or compliance analysis, visit www.rubinbrown.com/cyber.

 
 

Published: 04/16/2024

Readers should not act upon information presented without individual professional consultation.

Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.

 

Contact Us:

Talk to Our Experts

Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications
1-800-678-3134 Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

Firm News Disclaimers Privacy Policy Client Payment © 2025 RubinBrown LLP
RubinBrown Executive Recruiting RubinBrown Advisors RubinBrown Corporate Finance