nist-csf

Guides NIST CSF 2.0 and 1.1 gap assessments, profiles, tiers, and framework mappings.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nist-csf-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nist-csf
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/nist-csf
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nist-csf-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Security, risk, and compliance teams often struggle to interpret and apply the NIST Cybersecurity Framework, from understanding the six CSF 2.0 functions to building gap assessments, organizational profiles, and implementation roadmaps without a dedicated consultant. ## Core Features & Use Cases - Gap Assessments & Profiles: Produces structured Current vs. Target Profile tables across all six CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) with priority ratings. - Tier Assessment & Roadmaps: Evaluates Implementation Tiers 1-4 across three dimensions and generates phased 30/60/90-day remediation plans with effort and risk-reduction ratings. - Cross-Framework Mapping: Maps CSF subcategories to NIST SP 800-53 Rev 5, ISO 27001:2022, CIS Controls v8, and COBIT, plus CSF 1.1 to 2.0 migration guidance. - Use Case: A healthcare compliance lead asks for a CSF 2.0 gap assessment; the skill loads the full subcategory reference, produces a function-by-function gap table, and recommends a prioritized remediation sequence aligned to HIPAA-relevant categories. ## Quick Start Ask the assistant to perform a NIST CSF 2.0 gap assessment for your organization, including current state, target state, and priority for each subcategory.

Frequently Asked Questions about nist-csf

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a NIST CSF 2.0 gap assessment?

A CSF 2.0 gap assessment rates each subcategory across the six functions with a current state, target state, gap, and priority. Provide your industry, organization size, and known high-risk areas, then review the resulting table to build a prioritized remediation roadmap.

What changed between NIST CSF 1.1 and CSF 2.0?

CSF 2.0 adds a sixth function, Govern, expands supply chain risk management from 5 to 10 subcategories, and reduces total subcategories from 108 to 106. It also targets all organizations and sectors, not just critical infrastructure, and moves informative references to an online tool.

How do NIST CSF implementation tiers work?

CSF tiers range from Tier 1 (Partial) to Tier 4 (Adaptive) and describe how formalized and integrated risk management practices are. They are not maturity levels; organizations should operate at the tier matching their risk environment rather than aiming for Tier 4.

Can NIST CSF be mapped to ISO 27001 or NIST 800-53?

Yes, CSF subcategories map to NIST SP 800-53 Rev 5, ISO 27001:2022 Annex A, CIS Controls v8, and COBIT. For example, PR.AA access control subcategories align with the AC control family in 800-53 and ISO clauses A.5.15 through A.5.18.

What is a NIST CSF profile and how do I build one?

A CSF profile documents the alignment between your cybersecurity activities and business requirements, risk tolerance, and resources. Build a Current Profile of achieved outcomes and a Target Profile of desired outcomes, then use the gap between them to drive your action plan.

Does this skill provide official compliance certification or legal advice?

No, it provides informational guidance based on the public NIST CSF 2.0 and 1.1 publications. It does not constitute legal, audit, or professional compliance advice, and organizations should engage qualified cybersecurity professionals to validate implementations.