Abstract
This systematic review evaluates the adoption and effectiveness of the NIST Cybersecurity Framework (CSF) in mitigating cyber threats across diverse sectors. Following PRISMA guidelines, we analyzed studies published between 2015 and 2024 from major academic databases, focusing on the framework’s five core functions: Identify, Protect, Detect, Respond, and Recover. Results indicate widespread recognition but uneven adoption—large organizations show strong performance in the Protect and Detect functions, while small and medium-sized enterprises (SMEs) face implementation barriers due to limited resources. The framework’s flexibility and risk-based approach are notable strengths, though its voluntary nature and lack of localized standards pose challenges. Compared to ISO/IEC 27001 and COBIT, NIST CSF is more adaptable but less prescriptive. We identify key gaps in empirical validation and sector-specific applications, and recommend future research integrating AI-driven threat detection and regional adaptations.
| Original language | English |
|---|---|
| Pages (from-to) | 723-735 |
| Number of pages | 13 |
| Journal | International Journal of Advanced Computer Science and Applications |
| Volume | 16 |
| Issue number | 6 |
| DOIs | |
| State | Published - 2025 |
UN SDGs
This output contributes to the following UN Sustainable Development Goals (SDGs)
-
SDG 8 Decent Work and Economic Growth
-
SDG 9 Industry, Innovation, and Infrastructure
Keywords
- Cyberattacks
- cyberthreats
- organizational resilience
- risk management
- small and medium enterprises
Fingerprint
Dive into the research topics of 'Cybersecurity and the NIST Framework: A Systematic Review of its Implementation and Effectiveness Against Cyber Threats'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver