nist-cybersec-framework

Maps cybersecurity activities onto NIST CSF 2.0 domains and establishes a control baseline.

3|Updated Apr 12, 2026
One-click install
npx skills add https://github.com/mauriciodelrio/delriodev-skills --skill nist-cybersec-framework
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nist-cybersec-framework
Source: https://github.com/mauriciodelrio/delriodev-skills/tree/main/es-skills/governance-risk-and-compliance/nist-cybersec-framework
Command: npx skills add https://github.com/mauriciodelrio/delriodev-skills --skill nist-cybersec-framework

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps organizations implement and align cybersecurity controls to the NIST Cybersecurity Framework (CSF) 2.0, providing a structured approach to governance, asset management, risk assessment, protection, detection, response, and recovery.

Core Features & Use Cases

  • Align governance policies, risk appetite, and supplier security requirements with CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover).
  • Establish and maintain an asset inventory with classifications, criticality, and dependencies; perform risk assessments and track mitigations.
  • Implement automated protection, detection, incident response, and recovery planning through predefined playbooks and guardrails.
  • Use in SaaS or on-prem environments to standardize security controls, incident handling, and post-incident learning with RTO/RPO guidance.

Quick Start

Analyze your current security posture against CSF 2.0 domains and begin mapping controls, assets, and incident response artifacts to the framework.

Frequently Asked Questions about nist-cybersec-framework

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map my software security controls to the NIST CSF 2.0 framework?

To map security controls to the NIST CSF 2.0 framework, you analyze your current posture against its six domains: Govern, Identify, Protect, Detect, Respond, and Recover. This establishes a comprehensive control baseline for asset management, risk assessment, and incident response.

What is the best way to establish governance policies and risk appetite for cybersecurity?

The best way to establish cybersecurity governance policies and risk appetite is by aligning them with the NIST CSF 2.0 Govern domain. This approach standardizes supplier security requirements and defines concrete guardrails for your software team's operations.

How do I implement automated incident response playbooks with RTO and RPO guidance?

You can implement automated incident response and recovery planning by mapping your operations to NIST CSF 2.0 Respond and Recover domains. This generates predefined playbooks, automated response guardrails, and specific RTO/RPO guidance for post-incident learning.

Can I use the NIST Cybersecurity Framework for a small software team in a SaaS environment?

Yes, you can apply the NIST Cybersecurity Framework to software teams of any size in SaaS or on-prem environments. It scales to standardize security controls, threat detection, and asset classification without requiring extensive prerequisite components.

How do I perform a risk assessment and track mitigations for my software assets?

To perform risk assessment and track mitigations, you establish an asset inventory with classifications, criticality, and dependencies. Mapping this to the NIST CSF Identify domain helps systematically evaluate risks and monitor mitigation progress across your software.

Does the NIST CSF 2.0 include specific examples for secure configuration and MFA implementation?

Yes, applying the NIST CSF 2.0 Protect domain provides concrete examples for implementing MFA, security headers, and secure configuration checks. This ensures your software protections align with recognized governance and risk-management standards.