Established model
The NIST Cybersecurity Framework
National Institute of Standards and Technology · 2014
Also known as NIST CSF
A common structure for managing cyber risk, organised around what an organisation must be able to do before, during and after an incident.
Its place in the frameworkBusiness Core›Technology
What it does
It groups security work into a few functions — identifying what needs protecting, protecting it, detecting attacks, responding and recovering — and the 2024 revision added governing as a function of its own. Its main value is as a shared map: it lets management, technical staff and suppliers describe their position and their gaps in the same terms.
- Reach for it when
- When security is discussed only in terms of tools, and when the board asks how exposed the company is and nobody can answer in business terms.
- Where it stops
- It says what to cover, not how much is enough or which controls to buy. It was written for US critical infrastructure and needs translating for a small company’s scale and risks.
National Institute of Standards and Technology, Framework for Improving Critical Infrastructure Cybersecurity, 2014; The NIST Cybersecurity Framework 2.0, 2024.
Why it sits at Technology
The organisation’s tools and systems taken as a whole: what exists, how it connects, how each part was sourced, how it is protected, and what it will take to keep it working.
A model is only useful when you reach for it at the right moment. This one answers a question that arises here — so it is filed here, and nowhere else. These are the working areas it serves:
- The technology estateRoss, Weill & Robertson, Enterprise Architecture as Strategy (2006), on operating models as the prior choice an architecture should follow; Zachman, “A framework for information systems architecture”, IBM Systems Journal (1987); The Open Group Architecture Framework (TOGAF) on architecture principles and landscape views.
- Build, buy or subscribeWilliamson, The Economic Institutions of Capitalism (1985), on asset specificity and the make-or-buy boundary; Lacity & Willcocks on IT sourcing decisions (Global Information Technology Outsourcing, 2001); Wardley’s mapping of capabilities by evolution stage (Wardley Maps, 2016).
- AI and automationNIST AI Risk Management Framework 1.0 (2023); ISO/IEC 42001:2023 on AI management systems; Parasuraman, Sheridan & Wickens, “A model for types and levels of human interaction with automation”, IEEE Transactions on Systems, Man, and Cybernetics (2000); Regulation (EU) 2024/1689, the AI Act, as the regulatory classification the register has to be able to answer to.
- SecurityNIST Cybersecurity Framework 2.0 (2024) and its six functions; ISO/IEC 27001:2022 and the Annex A controls; the CIS Critical Security Controls v8; the NIS2 Directive (EU) 2022/2555 as the regulatory context for many organisations.
- Technical debt and renewalCunningham’s debt metaphor (OOPSLA experience report, 1992); Kruchten, Nord & Ozkaya, Managing Technical Debt (2019); Fowler’s technical debt quadrant (2009) and strangler fig pattern (2004); the TIME model of application portfolio rationalisation associated with Gartner.
What it touches elsewhere
Nothing in a business is decided on its own. A conclusion reached with this model at Technology lands in these other cores, whether or not anyone follows it there.
- Business CoreOperational Systems, under Tooling, judges whether one tool fits one process. The estate here holds the organisation-wide catalogue that assessment refers to, so the same system is not listed twice.
- Business CoreBusiness Assets keeps the asset register, the IP position and the lifecycle dates of held assets. Security and renewal here refer to those entries and add the attacker’s and the architect’s view of them.
- Business CoreCompliance maps which rules apply — the AI Act and NIS2 among them — and owns breach notification under incident response. Governance sets the risk appetite that security and AI risks are reported against.
- Data CoreData Governance decides who owns which data, who may see it and how long it is kept. Technology owns the systems that enforce those decisions, and the AI register refers to them for the data each use draws on.
- Time CoreRenewal is delivered as projects, planned and run under Project management. The roadmap here sets the sequence and the architecture; the schedule lives there.
- Omni CorePersonalization and Customer Support are where much customer-facing AI appears. What the customer should experience is decided there; the oversight and evaluation of the underlying system are held here.
Filed at the same place
These answer questions that arise at Technology too. Where they disagree with this one, the disagreement is the useful part.
- The technology acceptance modelWhether people use a new system depends mainly on whether they think it will help them and whether they think it will be easy.
- The TOGAF StandardA method for describing how a business, its information and its technology fit together, and for changing that fit deliberately.
- Wardley mappingMap what a user needs, the components that serve it, and how far each component has evolved from novel to commodity.
Elsewhere in Business Core
- Tuckman’s stages of group development
- Belbin Team Roles
- Herzberg’s two-factor theory
- Jobs to be done
- The Kano model
- The value proposition canvas
- The business model canvas
- The Van Westendorp price sensitivity meter
- Value-based pricing
- Core competence
- VRIO
- The resource-based view
- The theory of constraints
- Lean thinking
- Co-opetition and the value net
- Transaction cost economics
- Stakeholder theory
- The power–interest grid
- DuPont analysis
- Break-even and cost–volume–profit analysis
- Unit economics
- The Kraljic Matrix
- The bullwhip effect
- The SCOR Model
- On-time in-full
- Overall equipment effectiveness
- Value stream mapping
- The three lines model
- ISO 31000 risk management
- Maslow’s hierarchy of needs
- Kotter’s eight-step change model
- Situational leadership
- The Lean Startup
- Design thinking
- Porter’s value chain
- The McKinsey 7S framework
- Six Sigma and DMAIC
- Stage-gate
- Beyond budgeting
- Dynamic capabilities
- Intangible assets
- The four S’s of intangible investment
- Net present value and discounted cash flow
- The Modigliani–Miller theorem
- The pecking order theory
- COSO Internal Control — Integrated Framework
- ISO 37301 compliance management systems
- COSO Enterprise Risk Management
- Agency theory
- Mintzberg’s organisational configurations
- The Star Model
- Lewin’s change model
- The ADKAR model
- Effectuation
- Open innovation
- Failure mode and effects analysis
These are other people’s models, named here so you can go to the source and use them properly. The Omnigoal is not affiliated with their authors and is not endorsed by them; nothing of theirs is reproduced here — no canvas, no diagram, no wording. Each is described in our own words, with the originator credited, because the framework is a place to put thinking, not a replacement for the people who did it. Model names and trademarks belong to their respective owners and are used here only to refer to the work itself.
All 166 models