Which cybersecurity framework did NIST first release in 2014 to help organizations manage cyber risk?
Answer
NIST Cybersecurity Framework
Answer
NIST Cybersecurity Framework
NIST first released the NIST Cybersecurity Framework in 2014 to help organizations manage cyber risk.
The framework was developed by the U.S. National Institute of Standards and Technology in response to a U.S. executive-order initiative focused on improving critical-infrastructure cybersecurity. It gives organizations a common language for understanding, assessing, prioritizing, and communicating cybersecurity activities.
Its original core organized outcomes into five functions: Identify, Protect, Detect, Respond, and Recover. NIST later expanded the framework, and Cybersecurity Framework 2.0, released in 2024, added Govern as a core function and broadened its audience beyond critical infrastructure.
The framework is guidance rather than a single technical product or mandatory universal checklist. It can complement standards such as ISO/IEC 27001, control catalogs such as CIS Controls, and adversary-behavior knowledge bases such as MITRE ATT&CK. Organizations adapt its recommendations to their size, sector, risks, and legal obligations.
Source: Wikipedia · fact-checked Sept. 2026