Skip to content

NIST CSF 2.0

ORSM complements NIST CSF 2.0 rather than replacing it.

NIST CSF provides a structured approach across Govern, Identify, Protect, Detect, Respond and Recover.

ORSM adds an operational architecture question:

Once these capabilities are implemented, do they remain proportionate, sustainable, survivable and recoverable?

Examples of useful alignment include:

  • Protection Intent with risk identification and protection objectives;
  • Complexity and Dependency Resilience with governance and risk management;
  • Operational Resilience with Respond and Recover considerations; and
  • Recovery Engineering with demonstrable recovery capability.

The ORSM assessment should be applied to the architecture produced by the organisation's NIST CSF implementation rather than treated as a competing control catalogue.