info@nexoprivacy.com +254 768200243 Mon - Sat | 24 Hours
Home Policies NIST Privacy Framework & CSF 2.0
International · United States / Global

NIST Privacy Framework & CSF 2.0

Voluntary, risk-based frameworks from the US National Institute of Standards and Technology - widely adopted globally as the gold standard.

Quick facts

  • Code: NIST
  • Jurisdiction: United States / Global
  • Region: International
  • Enforcement:
    Voluntary - but a default expectation for US federal supply chain
  • Official source

The NIST Privacy Framework and the Cybersecurity Framework 2.0 give organisations a shared vocabulary to manage privacy and cyber risk. We map your controls to Govern, Identify, Protect, Detect, Respond and Recover.


Key principles & obligations

Govern
Identify
Protect
Detect
Respond
Recover
Privacy engineering
More in International

Related frameworks.

Global (Payment Card Industry)

PCI DSS v4.0

Mandatory technical and operational standard for any organisation that stores, processes or transmits cardholder data.

Read summary
Global

ISO/IEC 27701 - Privacy Information Management

Extends ISO/IEC 27001 with privacy-specific controls - the de-facto international certification for a Privacy Information Management System (PIMS).

Read summary
Global

ISO/IEC 27001:2022 - Information Security

The international standard for an Information Security Management System (ISMS) - increasingly demanded by enterprise buyers worldwide.

Read summary