| name | performing-nist-csf-maturity-assessment |
| description | Conduct a NIST Cybersecurity Framework (CSF) 2.0 maturity assessment across the six core Functions (Govern, Identify, Protect, Detect, Respond, Recover), scoring organizational posture against the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) and producing an improvement roadmap. Use when benchmarking an organization's cybersecurity program maturity or preparing a CSF-based gap analysis and remediation plan. |
| domain | cybersecurity |
| subdomain | compliance-governance |
| tags | ["compliance","governance","nist","csf","maturity-assessment","risk-management"] |
| nist_csf | ["GV.OC-01","GV.RM-01","GV.PO-01","ID.RA-01","GV.OV-01"] |
| version | 1.0 |
| author | mahipal |
| license | Apache-2.0 |
| mitre_attack | ["T1078","T1530","T1685.002"] |
Performing NIST CSF Maturity Assessment
Overview
The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions: Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF, using the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) to measure organizational cybersecurity posture and create improvement roadmaps.
When to Use
- When conducting security assessments that involve performing nist csf maturity assessment
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Prerequisites
- Understanding of cybersecurity risk management principles
- Access to NIST CSF 2.0 documentation and reference tool
- Knowledge of organizational IT/OT environment and security controls
- Stakeholder access across business units for assessment interviews
Core Concepts
CSF 2.0 Functions (6 Functions, 22 Categories)
| Function | Code | Categories | Purpose |
|---|
| Govern | GV | 6 | Establish and monitor cybersecurity risk management strategy |
| Identify | ID | 3 | Determine current cybersecurity risk to the organization |
| Protect | PR | 5 | Implement safeguards to prevent or reduce risk |
| Detect | DE | 2 | Find and analyze possible cybersecurity attacks |
| Respond | RS | 4 | Take action regarding detected cybersecurity incidents |
| Recover | RC | 2 | Restore capabilities impaired by cybersecurity incidents |
Govern Function (New in CSF 2.0)
- GV.OC: Organizational Context
- GV.RM: Risk Management Strategy
- GV.RR: Roles, Responsibilities, and Authorities
- GV.PO: Policy
- GV.OV: Oversight
- GV.SC: Cybersecurity Supply Chain Risk Management