Lesson 8: NIST CSF 2.0 — From Evidence to a Six-Function Coverage Map
In lesson 5 you chose a framework, in lesson 6 you validated a control, and in lesson 7 you built a risk register. Now apply NIST CSF 2.0 to a synthetic retail incident: create one piece of evidence for each of its six Functions — Govern, Identify, Protect, Detect, Respond, and Recover — and expose
The six Functions are six questions: who sets the rules, what matters, how it is protected, how we notice trouble, what we do during an incident, and how we restore service. Every answer needs evidence.
- The Six Functions of NIST CSF 2.0
- Six concurrent and continuous groups of cybersecurity outcomes: Govern, Identify, Protect, Detect, Respond, and Recover.
- Control Family
- A group of security controls associated with a specific function (e.g. access control, encryption, and network security all belong to 'Protect').
- National Cyber Directorate
- The central body responsible for protecting Israel's civilian cyber space, reporting directly to the Prime Minister. Operates CERT-IL, guides critical infrastructure, regulates the cyber market, and runs the 119 hotline.
- Privacy Protection Authority
- The regulator responsible for personal data, under the Ministry of Justice. Enforces the privacy law, manages database registration, and investigates personal-data breaches.
- National Digital Directorate
- Responsible for the government's digital transformation and information systems, including יה"ב (government cyber defense) and Project Nimbus (the government's move to the cloud).