What it means
The NIST Cybersecurity Framework organises cyber security activity into a small number of functions and a tiered view of maturity. Version 2.0 added Govern alongside the original five. It is voluntary, widely adopted internationally, and deliberately outcome-based rather than prescriptive.
Its value is as a common language across technical and executive audiences. Its limit is the same thing: an outcome-based framework does not say whether your implementation of an outcome was a reasonable decision.
Where MyRISK fits
What we do about it
MyRISK does not score or certify against NIST CSF. Where a framework leaves off — showing that a specific decision taken under it was reasonable at the time — is where Trace starts.
Is this the thing you are actually trying to fix?
A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.