Terminology Index

Glossary

2953 terms

Open concept maps
C
32

CSF Profiles

In the NIST Cybersecurity Framework, a Profile is a snapshot of an organization's chosen cybersecurity outcomes, used to describe its current state, define a target state, and plan the gap between them.

A CSF Profile aligns the framework's functions and categories to an organization's business needs, risk tolerance, and resources. By creating a Current Profile and a Target Profile, an organization can see where it stands, where it wants to be, and prioritize the gap. Profiles make the CSF adaptable rather than one-size-fits-all, and they are a primary mechanism for using it to drive improvement.

Introduced in: Security Frameworks and Control Mapping

Examples

  • Documenting a Current Profile of which CSF outcomes are met today.
  • Defining a Target Profile aligned to business risk priorities.
  • Prioritizing initiatives from the gap between current and target profiles.