markdowneditor

NIST CSF 2.0 Profile: [organization / system]

CSF profile – six functions, current vs target

ISO 및 컴플라이언스표준NIST CSF 2.0nistcsf

사용법: Posture assessment without a certification path. Honest current-state scores matter more than target ambitions.

미리보기

NIST CSF 2.0 Profile: [organization / system]

Cybersecurity Framework profile – current posture, target posture, and the gap plan. Six functions: Govern, Identify, Protect, Detect, Respond, Recover.

FieldValue
Scope[org / system boundary]
Owner@name
AssessedYYYY-MM-DD
Target profile byYYYY-MM-DD
StatusDraft / Approved

Governance

ItemValue
Cyber risk owner (exec)@name
Policy framework[linked policies]
Risk appetite statement[one line]

Function-by-function assessment

Rate current vs target maturity per category (1 initial, 2 partial, 3 defined, 4 managed, 5 optimized).

GOVERN

CategoryCurrentTargetGap plan
GV.OC (context)NN
GV.RM (risk strategy)
GV.RR (roles/responsibilities)
GV.PO (policy)
GV.SC (supply chain)

IDENTIFY

CategoryCurrentTargetGap plan
ID.AM (asset mgmt)NN
ID.RA (risk assessment)
ID.IM (improvement)

PROTECT

CategoryCurrentTargetGap plan
PR.AA (identity/access)NN
PR.AT (awareness/training)
PR.DS (data security)
PR.PS (platform security)
PR.IR (infrastructure resilience)

DETECT

CategoryCurrentTargetGap plan
DE.CM (continuous monitoring)NN
DE.AE (adverse event analysis)

RESPOND

CategoryCurrentTargetGap plan
RS.MA (incident mgmt)NN
RS.AN (analysis)
RS.CO (communication)
RS.MI (mitigation)

RECOVER

CategoryCurrentTargetGap plan
RC.RP (recovery execution)NN
RC.CO (communication)

Priority actions

PriorityCategoryActionOwnerDue
P1@nameYYYY-MM-DD

Review

Next assessment: YYYY-MM-DD. Method: [self / third-party].

관련 템플릿