Short for the NIST Cybersecurity Framework: optional standards, guidelines and practices that help organisations handle cyber risk. Alongside ISO, it supplies most controls in the baseline assessment Compliance Manager starts with.
Also called NIST Cybersecurity Framework.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains CSF in context, with comparison tables and the common traps.
Terms in this definition
- Risk
As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
- ISO
The International Organization for Standardization. SQL became an ISO standard in 1987, twelve months after ANSI adopted it.
- Baseline
A formally reviewed and approved specification that may afterwards be altered only under formal change control. The word also describes the architecture as it stands today.
- Compliance Manager
Helps an organisation measure itself against regulations and standards: ready-made assessments test its controls, suggested improvement actions show what to fix, and a compliance score records progress. Part of Microsoft Purview.
Related terms
- Data Protection Baseline
The ready-made assessment Compliance Manager gives every subscription, which sets your first compliance score. Most controls in it come from ISO and NIST CSF, with some taken from GDPR and FedRAMP.
- Microsoft 365 data protection baseline
Compliance Manager's starting assessment, included for all organisations at no extra cost. Its controls come mostly from NIST CSF and ISO and cover data protection and governance, and your first compliance score is calculated from it.