NIST CSF 2.0¶
ORSM complements NIST CSF 2.0 rather than replacing it.
NIST CSF provides a structured approach across Govern, Identify, Protect, Detect, Respond and Recover.
ORSM adds an operational architecture question:
Once these capabilities are implemented, do they remain proportionate, sustainable, survivable and recoverable?
Examples of useful alignment include:
- Protection Intent with risk identification and protection objectives;
- Complexity and Dependency Resilience with governance and risk management;
- Operational Resilience with Respond and Recover considerations; and
- Recovery Engineering with demonstrable recovery capability.
The ORSM assessment should be applied to the architecture produced by the organisation's NIST CSF implementation rather than treated as a competing control catalogue.