Terminology Index
Glossary
2953 terms
C32
CSF Profiles
In the NIST Cybersecurity Framework, a Profile is a snapshot of an organization's chosen cybersecurity outcomes, used to describe its current state, define a target state, and plan the gap between them.
A CSF Profile aligns the framework's functions and categories to an organization's business needs, risk tolerance, and resources. By creating a Current Profile and a Target Profile, an organization can see where it stands, where it wants to be, and prioritize the gap. Profiles make the CSF adaptable rather than one-size-fits-all, and they are a primary mechanism for using it to drive improvement.
Introduced in: Security Frameworks and Control Mapping
Examples
- Documenting a Current Profile of which CSF outcomes are met today.
- Defining a Target Profile aligned to business risk priorities.
- Prioritizing initiatives from the gap between current and target profiles.
