Compliance — NIST CSF 2.0
NIST CSF 2.0 — all six functions covered with continuous monitoring evidence
NIST CSF 2.0 added Govern as the sixth function and expanded Detect subcategories. ManySignal maps to every CSF subcategory relevant to security monitoring — with machine-verifiable DE.CM evidence, integrated threat intelligence (DE.AE-07), and automated response (RS.MA-01).
Control mapping — NIST CSF 2.0 to ManySignal
| Subcategory ID | Subcategory Name | ManySignal Capability |
|---|---|---|
| GV.OC-01 | Organisational Context (Govern) | Asset inventory and criticality context feed into detection prioritisation — high-value assets monitored with stricter thresholds |
| ID.AM-01 | Asset Management | Automatic asset discovery via cloud provider APIs and network telemetry — entity graph maintains live asset inventory |
| PR.AA-01 | Identities and Credentials — Manage | Identity lifecycle monitoring — provisioning, access review, and deprovisioning compliance tracking |
| PR.AA-05 | Access Permissions — Least Privilege | Privilege escalation and over-permissioned role usage anomaly detection |
| DE.CM-01 | Networks and Environments — Monitored | Continuous network flow analysis — East-West and North-South traffic anomaly detection |
| DE.CM-03 | Personnel Activity — Monitored | User behaviour analytics — identity-centric anomaly detection across all connected data sources |
| DE.CM-06 | External Service Provider Activity — Monitored | Third-party access baselining — vendor credential anomalies and out-of-scope access detection |
| DE.AE-02 | Adverse Events — Analysed | Multi-source event correlation in the entity graph — alert correlation across identity, network, and endpoint |
| DE.AE-07 | Cyber Threat Intelligence — Integrated | Threat intelligence feed integration — IOC matching and ATT&CK TTP correlation |
| RS.MA-01 | Incident Management — Executed | Automated response playbooks — containment actions executed without manual intervention on confirmed threats |
| RC.RP-01 | Recovery Plan — Executed | Recovery evidence tracking — system restoration events documented in case management |
CSF function coverage
Govern (GV)
Asset context, supply chain risk, strategy alignment evidence
Identify (ID)
Automated asset discovery, threat intelligence inventory
Protect (PR)
Access control monitoring, encryption verification, least-privilege enforcement
Detect (DE)
Full coverage — continuous monitoring, anomaly detection, TI correlation
Respond (RS)
Automated playbooks, incident management, escalation workflows
Recover (RC)
Recovery action documentation, post-incident evidence, improvement tracking
Evidence and audit status
ManySignal's CSF 2.0 mapping document is available to customers and prospects on request. SOC 2 Type II available under NDA at trust@manysignal.com. Cyber insurance underwriter assessment packages formatted to CSF function are available for renewal submissions.
NIST CSF 2.0 — common questions
How does ManySignal map to NIST CSF 2.0 versus NIST CSF 1.1?
NIST CSF 2.0 (released February 2024) added a sixth function — Govern (GV) — alongside the existing Identify, Protect, Detect, Respond, and Recover. ManySignal's control mapping covers all six functions. The most significant changes relevant to monitoring are: the expansion of Detect (DE) subcategories, the new continuous monitoring requirements in DE.CM, and the addition of supply chain risk management controls that ManySignal addresses via third-party access monitoring.
Is NIST CSF voluntary, and does ManySignal help demonstrate compliance?
NIST CSF is voluntary for most private sector organisations, but has been adopted as a compliance expectation by many US federal agencies (via CISA), state regulators, and cyber insurance underwriters. ManySignal provides evidence packaging aligned to CSF subcategory IDs, so organisations can demonstrate their security posture against CSF to regulators, insurers, or customers who require CSF adoption.
How does ManySignal address the new Govern (GV) function in CSF 2.0?
The Govern function focuses on cybersecurity strategy, policies, and oversight. ManySignal contributes evidence for GV subcategories related to: organisational context (asset inventory and risk context), supply chain risk management (third-party monitoring), and continuous improvement (detection effectiveness metrics). The GV function's strategy and policy controls are addressed by the customer's ISMS — ManySignal's role is operational monitoring evidence.
Can ManySignal help us achieve a specific NIST CSF maturity tier?
NIST CSF Tiers (1-4) describe the maturity of an organisation's cybersecurity risk management practices. ManySignal's continuous monitoring, automated detection, and integrated threat intelligence contribute to Tier 3 (Repeatable) and Tier 4 (Adaptive) characteristics — specifically: formal and repeatable detection processes (Tier 3), adaptive response based on threat intelligence (Tier 4). The platform's metrics and evidence packages support the assessment of tier progress.
How does ManySignal support CISA's cross-sector cybersecurity guidance based on NIST CSF?
CISA's cybersecurity advisories and cross-sector guidance are consistently mapped to NIST CSF functions. ManySignal's threat intelligence integrations include CISA KEV (Known Exploited Vulnerabilities) feed, CISA AA advisories, and ISAC threat feeds — ensuring that CISA-published IOCs are automatically checked against your environment. When a CISA alert is relevant to your industry, ManySignal surfaces it as a prioritised threat hunt.
See your CSF 2.0 posture in action
Connect your cloud provider and identity logs. We'll generate a live CSF 2.0 Detect function evidence summary showing your current anomaly detection coverage.