NIST CSF 2.0 and COBIT security programmes
A NIST CSF 2.0 programme runs your security work against the NIST Cybersecurity Framework: a current profile of where you are, a target profile of where you need to be, and a funded roadmap between the two. We build that programme, including the Govern function added in version 2.0, and set up the reporting cadence that keeps it current after the first assessment is filed.
What changed in CSF 2.0
NIST published Cybersecurity Framework 2.0 in February 2024. The biggest change is a sixth function, Govern, which sits over the other five and covers risk strategy, roles, policy and supply chain risk. The framework is also now written for every organization, not only critical infrastructure.
If your last assessment used version 1.1, the Govern gaps are usually the new findings: nobody formally owns cyber risk, or supplier risk is handled by procurement with no security input. A plain-language walk through the functions is in NIST CSF 2.0 in plain terms.
How a CSF gap assessment works
Current profile. We interview the people who run each area and look at evidence: access reviews, backup restore records, incident tickets. Each outcome gets a rating based on what exists, not on what the policy says.
Target profile. Management sets the target, informed by your risk appetite, your contracts and your regulators. A clinic and a payments processor should not have the same target.
Roadmap. The gaps between the two profiles become a sequenced plan with owners, rough effort and dependencies. Quick fixes go first so the programme shows movement in the first quarter.
Keeping the programme alive
Most CSF assessments die in a shared drive. The fix is a reporting cadence: owners update their outcomes quarterly, the profile is re-scored once a year, and the board sees a one-page view of movement against target. Where you already track risks, the profile gaps feed the risk register and KRIs so there is one list, not two.
Where there is no senior owner to run that cadence, it can sit with a fractional security lead.
Where COBIT fits
ISACA’s COBIT framework governs information and technology as a whole: investment decisions, IT processes, performance. CSF is narrower and deeper on security. If your internal audit function already reports against COBIT, we map the CSF profile into its governance objectives so the security programme speaks the language the board already reads.
Canadian context
CSF has no legal force in Canada, but it maps well to what Canadian regulators and insurers ask for. Federally regulated financial institutions can map a profile to OSFI Guideline B-13. Organizations handling personal information can use the Protect and Govern outcomes to document their security safeguards under PIPEDA, BC PIPA or, for a BC public body, FIPPA. We are not lawyers; whether those safeguards meet the law is a question we work through alongside your counsel. If you are working toward ISO 27001, the profile also lines up with ISO 27001 readiness.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
How long does a CSF 2.0 gap assessment take?
For a mid-sized organization with one main technology estate, the current profile, target profile and first roadmap usually take several weeks of elapsed time. Most of that is interviews and evidence gathering, not writing.
Should we use NIST CSF or COBIT?
Use CSF 2.0 when the question is cyber risk and security outcomes. Use COBIT when the board wants governance of information and technology as a whole. Many organizations run CSF for security and map it into an existing COBIT structure.
Is NIST CSF mandatory in Canada?
No. No Canadian law requires it. Organizations here use it because it is free, familiar to insurers and customers, and can be mapped to ISO 27001 and to regulator guidance such as OSFI Guideline B-13.
Do we need a GRC platform to run it?
No. A spreadsheet profile and a quarterly review meeting are enough to start. A platform becomes worth buying once the profile has owners and a review cycle that already works.
Start with a current profile
Tell us the size of the estate, which framework you report against today, if any, and who will own the programme. The reply says what a first assessment would cover. Related work is under cyber risk and governance.