NIST Cybersecurity Framework (CSF 2.0) Guide
CSF 2.0 places security awareness and training inside the Protect function and holds leadership accountable under Govern. Claro operationalizes those outcomes with simulations, training, and reporting.
- Regulator
- NIST (voluntary framework)
- Applies to
- Any organization, globally
Overview
The NIST Cybersecurity Framework 2.0, published in 2024, is a voluntary framework for understanding, managing, and reducing cybersecurity risk. It is widely adopted around the world as a common language between technical teams, executives, and partners. Rather than prescribing specific tools, it organizes cybersecurity outcomes into a structure that any organization can adapt to its own size, sector, and risk appetite. Many Indonesian organizations use it as a best-practice baseline or to communicate their security posture to international customers.
CSF 2.0 is built around six core Functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the addition that defines the 2.0 revision, establishing that cybersecurity risk is a leadership responsibility woven through the other five. Together the Functions describe the full lifecycle of managing risk, from setting strategy and knowing your assets to defending, detecting, and recovering from incidents. The human layer appears across several of them, most visibly in Protect and Govern.
Security awareness and training map primarily to the Protect function, specifically the Awareness and Training category, often referred to as PR.AT. Its subcategories expect that all personnel receive awareness and training, including how to recognize social engineering, and that individuals in specialized roles receive training tailored to those roles. Oversight and accountability for the program, including who owns it and how it is measured, sit under the Govern function. In short, everyone is trained, specialists get more, and leadership stays accountable.
This page is general guidance, not legal advice, and CSF 2.0 is voluntary rather than a law. For authoritative detail, refer to the framework as published by NIST and adapt it to your own context, ideally with qualified advisers. Claro supports the awareness and training outcomes and the evidence that leadership oversight relies on, but it does not by itself implement the entire framework. The framework covers far more than the human layer, and adoption is your organization's decision.
What the rule expects
PR.AT-01 awareness and training for all personnel
All personnel should be provided with cybersecurity awareness and training so they can perform their tasks with security in mind, including recognizing social engineering such as phishing. This is a broad, organization-wide expectation, not one limited to technical staff. The outcome is a workforce that can spot and resist manipulation.
PR.AT-02 role-based training for specialized roles
Individuals in specialized roles should receive training tailored to the specific risks and responsibilities of those roles. General awareness alone is not sufficient for people with elevated access or sensitive duties. The framework expects differentiated content matched to the role.
Recognizing social engineering as an explicit outcome
CSF 2.0 calls out the ability to recognize and respond to social engineering as part of awareness. Phishing is the most common vector for this, so the practical test is whether people can identify and report suspicious messages. Measurable recognition, not just exposure to content, is the goal.
Govern: leadership accountability for the program
The Govern function establishes that cybersecurity risk, including the human layer, is owned and overseen by leadership. Someone must be accountable for the awareness program, its resourcing, and its results. This shifts awareness from an IT chore to a governed business activity.
Measurement and continuous improvement
CSF 2.0 emphasizes understanding your current profile and moving toward a target profile over time. That implies measuring how the awareness program performs and improving it, rather than treating training as a checkbox. Metrics on susceptibility and reporting make this improvement visible.
Detect and Respond: people as sensors
The Detect and Respond functions benefit directly when trained employees report suspicious activity quickly. Awareness therefore feeds detection, shortening the time an attacker goes unnoticed. A reporting culture is part of turning the human layer into an asset.
Tailoring the framework to your context
CSF 2.0 is meant to be adapted through profiles and tiers rather than adopted wholesale. Your awareness activities should reflect your actual risk, sector, and maturity. Evidence should show that your chosen outcomes are being met, not that you copied a generic template.
How Claro helps you comply
Cover PR.AT-01 with organization-wide awareness
Claro delivers cybersecurity awareness to all personnel through bilingual micro-modules and phishing simulations that specifically build the ability to recognize social engineering. Assignment rules ensure the whole workforce is reached, not just the security team. Content in English and Bahasa Indonesia keeps it relevant across Indonesian teams.
Deliver role-based training for PR.AT-02
Learning paths and assignment rules let you target specialized roles with tailored content, matching the framework's expectation of role-based training. Just-in-time enrollment routes users into role-relevant modules after a failed simulation. This makes differentiation practical rather than theoretical.
Measure social-engineering recognition directly
Localized phishing simulations track per-recipient opens, clicks, submissions, and reports, giving you a measurable read on who can recognize an attack. Risk scoring turns that into trends you can move from a current profile toward a target profile. This is measurement, not just exposure.
Turn employees into sensors for Detect and Respond
The phish-report button, delivered through an Outlook add-in and a Gmail extension, lets employees report suspicious mail in one click. This reporting loop shortens detection time and supports the Detect and Respond functions. Every report is captured and scored.
Give leadership the oversight Govern requires
Claro's compliance module includes NIST CSF framework logic, mapping control coverage so leaders can see program status at a glance. Claro-style PDF board reports and scheduled delivery give governance owners the evidence they are accountable for. This supports the accountability that Govern establishes.
Show continuous improvement over time
Per-user and per-department risk scoring, plus a gamification and behavior engine, make progress visible across successive cycles. You can demonstrate movement toward a target profile rather than a static snapshot. Audit logs and per-tenant isolation keep the record trustworthy.
Frequently asked questions
No. CSF 2.0 is a voluntary framework published by NIST, not a regulation. Organizations adopt it as a best-practice baseline and to communicate their risk posture to customers and partners. Many Indonesian organizations use it precisely because international clients recognize it.
This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.
Related pages
SOC 2
An AICPA attestation on security controls that commonly expects documented security awareness training as evidence.
Learn moreUU PDP (Law 27/2022)
Indonesia's Personal Data Protection Law. Build the awareness and breach-response readiness it expects.
Learn moreOJK POJK 11/2022
OJK's IT and cyber-resilience rule for banks. Evidence the awareness and testing it calls for.
Learn moreBuild defensible security awareness evidence
Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.
Request a demo