www.wileyconnect.com NIST Cybersecurity Framework 2.0 Released Amid Evolving Threat Landscape
Article Content
- •NIST released Cybersecurity Framework 2.0 on February 26, 2024, updating guidance from 2018.
- •The new version emphasizes risk governance and supply chain risk management.
- •Organizations are encouraged to integrate CSF 2.0 into their cybersecurity risk management programs.
On February 26, 2024, NIST released Cybersecurity Framework version 2.0 (CSF 2.0), updating its foundational guidance last revised in April 2018. The new version introduces significant changes, particularly in risk governance and supply chain risk management, reflecting the evolving cybersecurity landscape. CSF 2.0 aims to provide flexible, risk-based guidance for organizations to manage cybersecurity risks effectively. Key components include a Framework Core, Implementation Tiers, and Framework Profiles. The update emphasizes the importance of third-party risk management and secure software development practices. Organizations are encouraged to integrate CSF 2.0 into their existing cybersecurity risk management programs. NIST is also seeking public input on developing Community Profiles, which will help tailor the framework to specific sectors. This update is crucial for organizations aiming to enhance their cybersecurity posture in response to emerging threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…