NIST Cybersecurity Framework v2.0
A risk-based approach to managing cyber security developed by the US National Institute of Standards and Technology. Organises all cyber security activities into six core functions: Govern, Identify, Protect, Detect, Respond, and Recover.
See where NodeZero appliesWhat is the NIST Cybersecurity Framework?
The NIST Cybersecurity Framework is a risk-based approach to managing cyber security developed by the US National Institute of Standards and Technology. Version 2.0, released in February 2024, organises all cyber security activities into six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Unlike prescriptive standards that mandate specific controls, NIST CSF provides a flexible structure that organisations adapt to their own risk profile, industry, and regulatory environment.
NIST CSF is one of five frameworks approved under Australia's SOCI Act CIRMP rules for addressing the cyber hazard vector. Its flexibility makes it a common choice for organisations that already align to NIST standards or operate across multiple jurisdictions. However, that same flexibility means the framework relies heavily on the organisation's own risk assessment to determine what "adequate" looks like -- assessors and auditors need to see evidence that controls are appropriate, not just that they exist on paper.
Where NodeZero applies
NodeZero provides direct testable evidence across the Identify, Protect, and Detect functions — discovering unknown assets, chaining real attack paths to prove whether protective controls hold, and validating whether monitoring and deception layers detect attacker behaviour. Coverage in Respond and Recover is narrower but meaningful: remediation verification (Quick Verify) generates evidence of response effectiveness, and Tripwires feed your incident-response workflow. For the Govern function, we cleanly delineate what sits outside autonomous testing.
This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.
Please note the following requires separate evidence: Govern (GV).
Showing coverage grouped by compliance category.
Identify (ID)
Direct coverage of asset discovery, vulnerability identification, and threat context.
Internal pentestingCore
Enumerates every reachable host from the attacker perspective — often surfacing hardware assets the CMDB doesn't know about.
High-Value TargetingElite only
Infers the small set of crown-jewel assets that carry most of the business risk — executive and finance accounts, ERP systems, domain controllers — and prioritises the attack paths that reach them.
Web application pentestingPriced separately
Identifies and validates the application-layer vulnerabilities infrastructure testing does not reach — OWASP Top 10 weaknesses, access-control failures and business-logic flaws in bespoke applications — each proven by real exploitation rather than inferred.
Threat Actor IntelligenceElite only
Correlates your validated attack paths with MITRE ATT&CK techniques and named threat-actor campaigns — concrete threat-intelligence evidence.
Vulnerability Management HubCore
The Vulnerability Management Hub tracks each proven weakness through team-decided states (To Do, Fixed, Risk Accepted, False Positive) alongside system-observed Open, Mitigated and Regressed status, and Vulnerability Risk Intelligence re-ranks by real exploitability — evidence for the prioritised-and-tracked slice of ID.RA-06 across the technical-risk portfolio NodeZero has proven. Risk appetite and communication remain organisational.
Protect (PR)
Strong coverage. NodeZero tests whether protective controls actually prevent exploitation.
AD Password AuditCore
Audits credentials on user, service, privileged, and break-glass accounts; first AI to solve GOAD in 14 minutes (Horizon3-reported) — it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit.
Phishing Impact TestingCore
Takes credentials captured by your phishing tool into a supporting internal pentest and proves what each stolen credential can actually reach — data, admin access, cloud pivot, domain compromise — showing where a phished credential was not contained by MFA or least privilege.
BloodHound (integrated)Core
Visualises AD attack graphs to over-privileged accounts — makes the separation-of-duties and least-privilege failures visible.
Segmentation testingCore
Enumerates IPs, ports, services, and applications to validate that segmentation actually enforces the logical boundaries PR.IR-01 requires.
Endpoint Security EffectivenessCore
Reports per-host and per-vendor block/allow across 40+ EDR vendors with every permitted action mapped to MITRE ATT&CK — evidence that endpoint controls are actually enforcing.
Internal pentestingCore
Exploits unpatched and end-of-life software — proof of which maintenance gaps create actual attack paths.
Advanced Data PilferingElite only
Auto-classifies the exfiltratable data an attacker can reach against 12 business-risk categories (Sony, Equifax, SolarWinds, Verkada, CloudNordic analogs).
Detect (DE)
Direct coverage via deception, adversary-technique mapping, and attack-activity generation.
NodeZero TripwiresPro & Elite
AWS credentials files, MySQL dumps, and Windows process monitors placed where NodeZero's already reached — silent until triggered, then routed to your SIEM.
AD TripwiresPro & Elite
Kerberoasting bait, AS-REP decoys, and domain-user scraping bait catch the exact techniques real attackers use against AD.
Internal pentestingCore
Every NodeZero action is timestamped with proofs and commands — correlate with your SIEM to find logging gaps and validate whether analysis of adverse events actually works.
High-Value TargetingElite only
Every validated attack chain is scored for business impact and mapped to the crown-jewel assets it reaches — concrete impact and scope estimates per chain.
Threat Actor IntelligenceElite only
Each validated attack path is correlated with MITRE ATT&CK techniques and named threat-actor campaigns, so analysis carries the threat context built in.
Respond (RS)
Narrow coverage. NodeZero supports response with remediation-verification evidence and an operational backlog.
Quick VerifyCore
Post-incident, re-run the exact attack chain to get proof the containment mitigation actually holds.
Vulnerability Management HubCore
Every ticket carries the attack-path context your response team needs, with Open → Mitigated → Regressed lifecycle tracking to confirm eradication.
Recover (RC)
Narrow coverage. NodeZero validates that post-recovery state is actually secure.
Vulnerability Management HubCore
Regression detection flags when a recovered system drifts back to a previously vulnerable state — early warning that the restoration produced the same weakness.
See every control mapped to NodeZero
The full control-by-control coverage map — every NIST CSFrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.
Who does this apply to?
NIST CSF is a voluntary framework -- there is no statutory requirement to adopt it in the United States or Australia. However, it is one of five frameworks approved under Australia's SOCI CIRMP rules for meeting the cyber and information security hazard obligation, making it a common choice for critical infrastructure entities that operate across multiple jurisdictions or already align to NIST standards.
The framework is designed to be sector-agnostic and scale-agnostic. It is used by Fortune 500 companies, government agencies, small businesses, and non-profits alike. Organisations that operate in regulated industries often adopt NIST CSF as the overarching structure for their cyber security programme, mapping sector-specific requirements (such as HIPAA, PCI DSS, or CPS 234) into the framework's six functions.
If your organisation needs a flexible, internationally recognised structure for managing cyber security risk -- particularly if you operate across borders or need to demonstrate alignment with a well-known standard to customers, partners, or regulators -- NIST CSF is a strong choice.
Four tiers of risk management sophistication
NIST CSF uses four Implementation Tiers to describe how sophisticated an organisation's cyber security risk management is. NIST is explicit that tiers are not maturity levels — organisations select a target tier based on their risk appetite, business goals, and resources, and use the framework to move toward it.
Risk management practices are not formalised, and risk is managed in an ad-hoc, sometimes reactive manner. Limited organisational awareness of cyber security risk and no routine collaboration with external partners.
NIST definition →Risk management practices are approved by management but not established as organisation-wide policy. Prioritisation is informed by organisational risk objectives, the threat environment, and business requirements.
NIST definition →Organisation-wide approach to managing cyber security risk. Risk-informed policies, processes, and procedures are defined, implemented as intended, reviewed, and improved. Regular collaboration with suppliers and partners.
NIST definition →Organisation adapts its cyber security practices based on previous and current activities, including lessons learned and predictive indicators. Continuous improvement, with cyber security integrated into enterprise risk management.
NIST definition →Risk management practices are not formalised, and risk is managed in an ad-hoc, sometimes reactive manner. Limited organisational awareness of cyber security risk and no routine collaboration with external partners.
NIST definition →Risk management practices are approved by management but not established as organisation-wide policy. Prioritisation is informed by organisational risk objectives, the threat environment, and business requirements.
NIST definition →Organisation-wide approach to managing cyber security risk. Risk-informed policies, processes, and procedures are defined, implemented as intended, reviewed, and improved. Regular collaboration with suppliers and partners.
NIST definition →Organisation adapts its cyber security practices based on previous and current activities, including lessons learned and predictive indicators. Continuous improvement, with cyber security integrated into enterprise risk management.
NIST definition →Close the gaps before your next assessment
See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.