Compliance
NIST CSF 2.0 mapped to Microsoft capabilities
The framework everyone claims to follow. What each function means in a Microsoft estate, including the one added in 2.0 that most organisations have not addressed.
CSF is a language, not a checklist
NIST Cybersecurity Framework 2.0 gives you a vocabulary for describing where your capability is strong and where it is thin. It is not certifiable, nobody audits you against it, and that is the point: it is for organising a conversation, particularly with a board.
Version 2.0 added Govern alongside the original five functions, and that addition is the part most organisations have not done anything about, because it is the only one you cannot buy.
| Where it lives | |
|---|---|
| Govern | Policy, roles, risk appetite. Not a product |
| Identify | Purview data discovery, asset inventory in Intune and Defender |
| Protect | Entra ID, Conditional Access, Intune, Purview DLP |
| Detect | Defender XDR, Microsoft Sentinel |
| Respond | Sentinel automation, Defender response actions, your runbook |
| Recover | Backup, tested restore, and the communications plan |
A tool can support a function. It cannot satisfy one, particularly Govern.
Where Microsoft estates are typically strongest and weakest
Our assessment of the usual shape, offered as an argument rather than as survey data.
- Protect35
- Detect26
- Recover22
- Govern17
Relative maturity in our view, not measured data.
The two functions worth your attention
Recover, because almost every organisation has backups and almost none have tested a restore under time pressure. An untested restore is a belief, not a capability.
Govern, because it is new, it is unglamorous, and it is the function that determines whether the other five get funded. It is also the only one where the answer is a document rather than a licence, which is precisely why it gets skipped.
The verdict
Use CSF to structure the board conversation, not to buy products
Its value is a shared vocabulary for describing capability and gaps to people who do not read security tooling documentation.
Do not use a vendor CSF mapping as evidence of maturity. Those documents describe what a product could support, not what you have configured.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.