What problem does it solve?
Security teams struggle to measure and communicate their cybersecurity posture in a structured, defensible way. This Skill guides a complete maturity assessment against the NIST Cybersecurity Framework (CSF) 2.0, turning scattered policies and controls into scored Current and Target Profiles with a prioritized improvement roadmap.
Core Features & Use Cases
- Six-Function Coverage: Assesses all CSF 2.0 Functions (Govern, Identify, Protect, Detect, Respond, Recover) including the new Govern function with supply chain and oversight categories.
- Tier-Based Scoring: Rates each Category and Subcategory against the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) with evidence validation guidance to prevent inflated self-attested scores.
- Gap Analysis & Roadmap: Produces Current and Target Profiles, a gap analysis report, and a phased improvement roadmap with quick wins, medium-term improvements, and long-term initiatives.
- Use Case: A CISO preparing for a board review uses this Skill to score all 22 CSF Categories, validate tier ratings against dated artifacts like SIEM dashboards and policy documents, and present a 12-month maturity roadmap tied to the risk register.
Quick Start
Perform a NIST CSF 2.0 maturity assessment for our organization and produce a Current Profile, Target Profile, and prioritized improvement roadmap.