NIST CSF 2.0
The NIST Cybersecurity Framework 2.0, published in 2024, organizes a security program into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is a management framework for deciding and communicating priorities rather than a technical standard.
Version 2.0 added the Govern function, making accountability, policy, and oversight an explicit part of the framework rather than an assumption. Each function breaks into categories and subcategories that an organization scores itself against, producing a current profile and a target profile.
It applies to any organization. For OT it is typically paired with NIST SP 800-82 for the technical detail and ISA/IEC 62443 for the architecture.
Why it matters in cement, mining, and aggregates
The Govern function is where the OT Service Owner role lives: someone accountable for OT security across the fleet, with defined roles and change control. Operators that adopt CSF 2.0 corporately can report the plant side of it through that owner.
Source: NIST Cybersecurity Framework 2.0