csf-mapping

Map cybersecurity programs to NIST CSF 2.0 and produce tiered gap analyses.

345|47|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/briiirussell/cybersecurity-skills --skill csf-mapping
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: csf-mapping
Source: https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/csf-mapping
Command: npx skills add https://github.com/briiirussell/cybersecurity-skills --skill csf-mapping

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you translate your real cybersecurity program into NIST Cybersecurity Framework (CSF) 2.0 governance language so you can clearly communicate current maturity, gaps, and priorities to boards, auditors, and CISOs.

Core Features & Use Cases

  • NIST CSF 2.0 posture mapping: Maps your current practices to CSF 2.0 Functions, Categories, and Subcategories (including the new Govern function).
  • Tiered gap analysis: Produces current tier vs target tier assessments and explicitly identifies the delta, evidence, and closure plan for each scoped Subcategory.
  • Governance-ready deliverables: Outputs executive-friendly risk framing and a time-phased roadmap (next 30/90 days, next 12 months) tied to owners and success metrics.
  • Evidence cross-referencing: Uses outputs from related audit skills in the repo as evidence to support the “current state” portion of the assessment.

Quick Start

Use the csf-mapping skill to generate a NIST CSF 2.0 posture assessment for your organization, including a gap analysis, tier ratings, and a prioritized roadmap.

Frequently Asked Questions about csf-mapping

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map my cybersecurity program to NIST CSF 2.0 for board reporting?

To map your cybersecurity program to NIST CSF 2.0 for board reporting, you score current practices against CSF 2.0 Functions and Subcategories to produce a tiered gap analysis with a prioritized, governance-ready roadmap.

What is the best way to perform a NIST CSF 2.0 gap analysis with maturity tiers?

A NIST CSF 2.0 gap analysis with maturity tiers evaluates your current practices against target tiers across all six Functions, explicitly identifying the delta, required evidence, and closure plans for each scoped Subcategory.

Can I generate a time-phased cybersecurity roadmap from a CSF 2.0 posture assessment?

Yes, you can generate a time-phased cybersecurity roadmap from a CSF 2.0 posture assessment that organizes prioritized remediation actions into 30-day, 90-day, and 12-month intervals tied to named owners and success metrics.

Does the NIST CSF 2.0 Govern function need to be included in a maturity gap analysis?

Yes, the NIST CSF 2.0 Govern function must be included in a maturity gap analysis to ensure cybersecurity risk management strategy expectations are properly scoped and integrated with the Identify, Protect, Detect, Respond, and Recover functions.

Can I use audit evidence to support my current state CSF 2.0 tier rating?

You can use outputs from related audit skills as cross-referenced evidence to substantiate your current state CSF 2.0 tier rating, providing documented proof for auditors and CISOs without performing active exploitation.