Cybersecurity and the NIST Framework: A Systematic Review of its Implementation and Effectiveness Against Cyber Threats

Juan Luis Salas-Riega, Yasmina Beatriz Riega-Virú, Mario Edison Ninaquispe Soto, José Miguel Salas-Riega · International Journal of Advanced Computer Science and Applications · 2025

This systematic review evaluates the adoption and effectiveness of the NIST Cybersecurity Framework (CSF) in mitigating cyber threats across diverse sectors. Following PRISMA guidelines, we analyzed studies published between 2015 and 2024 from major academic databases, focusing on the framework's five core functions: Identify, Protect, Detect, Respond, and Recover. Results indicate widespread recognition but uneven adoption—large organizations show strong performance in the Protect and Detect functions, while small and medium-sized enterprises (SMEs) face implementation barriers due to limited resources. The framework's flexibility and risk-based approach are notable strengths, though its voluntary nature and lack of localized standards pose challenges. Compared to ISO/IEC 27001 and COBIT, NIST CSF is more adaptable but less prescriptive. We identify key gaps in empirical validation and sector-specific applications, and recommend future research integrating AI-driven threat detection and regional adaptations.

Read the paper · More papers on PaperTik