Tech & produit

NIST Cybersecurity Framework 2.0 & small-business security

The NIST Cybersecurity Framework 2.0 with its small-business quick-start and organizational-profile guides, NIST small-business security fundamentals, NIST SP 800-63B-4 password and MFA rules, and CISA Cyber Essentials. For SME owners, IT leads and consultants building a practical security program. Curated by Kopik from public sources: NIST, CISA (US public domain).

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

This assistant answers practical questions about the NIST Cybersecurity Framework (CSF) 2.0 and how a small or medium-sized business can turn it into a working security program. It is meant for business owners, IT leads and consultants, and it answers only from public US government sources: the CSF 2.0 itself, the NIST small-business and organizational-profile quick-start guides, NIST small-business security fundamentals, the NIST SP 800-63B-4 authentication guidelines and the CISA Cyber Essentials Starter Kit.

The six Functions of CSF 2.0 in plain terms

CSF 2.0 organizes cybersecurity outcomes into six high-level Functions: Govern, Identify, Protect, Detect, Respond and Recover. Each Function is divided into Categories, and each Category into Subcategories that describe more specific outcomes.

Govern sits at the center of the framework because it informs how the other five are carried out: it covers the organization's context, its cybersecurity strategy, supply chain risk management, roles and responsibilities, policy and oversight. Building on previous versions, CSF 2.0 adds new features that highlight the importance of governance and supply chains.

The framework expects Govern, Identify, Protect and Detect to happen continuously, while Respond and Recover should be ready at all times and used when an incident occurs.

Govern and Identify: knowing your obligations and your assets

The Small Business Quick-Start Guide starts with governance. It asks you to understand how cybersecurity risks could disrupt your mission, to list your legal, regulatory and contractual cybersecurity requirements, and to decide who in the business is responsible for developing and executing the strategy.

It also suggests assessing the impact of losing critical assets or operations, whether cybersecurity insurance is appropriate, and the risks posed by suppliers and other third parties before you sign with them. Cybersecurity risks are meant to be managed alongside your other business risks.

Under Identify, the guide recommends an inventory of the hardware, software, systems and services you rely on, the classification of your business data, and a risk register documenting threats and planned responses. For each asset you can record its use, its owner, the sensitive data it reaches, whether MFA is required and the risk to the business if you lose access to it.

First protective steps the Small Business Quick-Start Guide prioritizes

Under the Protect Function, the NIST Small Business Quick-Start Guide (SP 1300) asks you to prioritize multi-factor authentication on every account that offers it, changing default manufacturer passwords, regular patching with automatic updates, backups that are actually tested, and full-disk encryption on laptops and tablets.

The guide calls MFA one of the fastest, cheapest ways to protect your data and suggests starting with the accounts that reach the most sensitive information: banking, accounting and tax, merchant accounts, Google, Microsoft or Apple IDs, email, password managers and website accounts.

It also asks whether access and privileges are restricted to those who need them, and recommends teaching staff to recognize common attacks and report suspicious activity.

Spotting and handling an incident

The Quick-Start Guide lists common signs of an incident: losing usual access to data, applications or services, an unusually sluggish network, antivirus alerts about malware, multiple failed login attempts, many bounced emails with suspicious content, or unusual network traffic.

Before anything happens, it advises a basic incident response plan with a business champion who maintains it, a list of who to call with their contact details and authority, and your reporting duties under laws, regulations, contracts or policies.

For recovery, a playbook typically includes formal recovery processes, the criticality of your resources, the systems that hold key information (to set restoration order), the people responsible for recovery and a communications plan. An after-action report then records what happened and the lessons learned.

Questions fréquentes

Is the NIST Cybersecurity Framework mandatory for small businesses?

The CSF describes itself as a foundational resource that may be adopted voluntarily or through governmental policies and mandates. Its taxonomy and referenced standards are not country-specific, and earlier versions have been used by organizations both inside and outside the United States.

Does CSF 2.0 tell me exactly which tools or controls to buy?

No. The framework states that it does not prescribe how outcomes should be achieved and that its outcomes are not a checklist of actions. Specific actions vary by organization, which is why NIST publishes Implementation Examples and Informative References online as supplements.

Is the Small Business Quick-Start Guide only for companies?

It is written for small businesses, but NIST notes that it can also help other relatively small organizations such as non-profits, government agencies and schools.

What does CISA Cyber Essentials add to the NIST material?

The CISA Starter Kit presents cyber readiness as a culture built around six essential elements: yourself as the leader, your staff, your systems, your surroundings (the digital workplace), your data and your crisis response. It describes its first actions as consistent with the NIST Cybersecurity Framework and other standards.

Who in a small business should own cybersecurity?

The NIST quick-start guide asks you to name the people responsible for developing and executing your cybersecurity strategy, and CISA puts the leader first among its essential elements. Leadership is expected to drive strategy and investment and to communicate support for a risk-aware, continually improving culture. The guide also asks whether you need to train existing staff, hire, or engage an external partner.

Why would attackers target a small business?

NISTIR 7621 explains that a small business may hold money or information valuable to criminals, that its computers can be compromised and used to attack others (a botnet), and that it can provide access to larger targets through its products, services or role in a supply chain. It adds that small businesses are often less prepared than larger ones, but their simpler operations can make some steps easier to take.

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-nist-csf-2-small-business-cybersecurity "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-nist-csf-2-small-business-cybersecurity": {
      "url": "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/nist-csf-2-small-business-cybersecurity/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.