NIST CSF 2.0 Profile: [organization / system]
Cybersecurity Framework profile – current posture, target posture,
and the gap plan. Six functions: Govern, Identify, Protect, Detect,
Respond, Recover.
| Field | Value |
|---|
| Scope | [org / system boundary] |
| Owner | @name |
| Assessed | YYYY-MM-DD |
| Target profile by | YYYY-MM-DD |
| Status | Draft / Approved |
Governance
| Item | Value |
|---|
| Cyber risk owner (exec) | @name |
| Policy framework | [linked policies] |
| Risk appetite statement | [one line] |
Function-by-function assessment
Rate current vs target maturity per category (1 initial, 2 partial,
3 defined, 4 managed, 5 optimized).
GOVERN
| Category | Current | Target | Gap plan |
|---|
| GV.OC (context) | N | N | |
| GV.RM (risk strategy) | | | |
| GV.RR (roles/responsibilities) | | | |
| GV.PO (policy) | | | |
| GV.SC (supply chain) | | | |
IDENTIFY
| Category | Current | Target | Gap plan |
|---|
| ID.AM (asset mgmt) | N | N | |
| ID.RA (risk assessment) | | | |
| ID.IM (improvement) | | | |
PROTECT
| Category | Current | Target | Gap plan |
|---|
| PR.AA (identity/access) | N | N | |
| PR.AT (awareness/training) | | | |
| PR.DS (data security) | | | |
| PR.PS (platform security) | | | |
| PR.IR (infrastructure resilience) | | | |
DETECT
| Category | Current | Target | Gap plan |
|---|
| DE.CM (continuous monitoring) | N | N | |
| DE.AE (adverse event analysis) | | | |
RESPOND
| Category | Current | Target | Gap plan |
|---|
| RS.MA (incident mgmt) | N | N | |
| RS.AN (analysis) | | | |
| RS.CO (communication) | | | |
| RS.MI (mitigation) | | | |
RECOVER
| Category | Current | Target | Gap plan |
|---|
| RC.RP (recovery execution) | N | N | |
| RC.CO (communication) | | | |
Priority actions
| Priority | Category | Action | Owner | Due |
|---|
| P1 | | | @name | YYYY-MM-DD |
Review
Next assessment: YYYY-MM-DD. Method: [self / third-party].