It is a basic consensus in the industry to clarify the cyber security situation of organizations and improve their cyber security protection capabilities based on risk management.This paper introduces the main content of the NIST CyberSecurity Framework 2.0 version include kernel,profile and layers etc,and analyzes its main differences between version 1.1 and version 2.0,providing reference for Chinese network operators to strengthen risk management.