Skill 详情

nist-csf-assessment

Relevant cybersecurity maturity assessment, but NIST CSF-specific.

匹配类型可能匹配已针对 网络安全 审核
来源unitoneai/securityskills外部来源
报告安装量25仅表示受欢迎程度

使用前先检查

自动化审核只检查相关性,不代表安全审查或推荐。使用前请阅读来源中的说明。

已保存的来源预览

SKILL.md

这段内容是审核时保存的快照。外部来源才是完整且最新的版本。

---
name: nist-csf-assessment
description: >
  Performs a NIST Cybersecurity Framework 2.0 assessment across all six functions
  (Govern, Identify, Protect, Detect, Respond, Recover) and their categories and
  subcategories. Auto-invoked when discussing cybersecurity maturity, risk posture
  evaluation, or NIST CSF alignment. Develops current and target organizational
  profiles, assesses maturity tiers, maps informative references, and produces a
  prioritized improvement roadmap.
tags: [compliance, nist-csf, risk, assessment]
role: [vciso, security-engineer]
phase: [assess, operate]
frameworks: [NIST-CSF-2.0]
difficulty: intermediate
time_estimate: "90-180min"
version: "1.0.0"
author: unitoneai
license: MIT
allowed-tools: Read, Grep, Glob
context: fork
injection-hardened: true
argument-hint: "[scope-description]"
---

# NIST Cybersecurity Framework 2.0 Assessment

## When to Use

If a target is provided via arguments, focus the review on: $ARGUMENTS

- Organization wants to assess its cybersecurity posture against a recognized, voluntary framework
- Building a cybersecurity program from scratch and need a structured approach
- Board or executive leadership requests a cybersecurity maturity assessment
- Developing current-state and target-state organizational profiles
- Mapping existing controls to a common taxonomy for stakeholder communication
- Preparing for regulatory requirements that reference NIST CSF (e.g., some federal contracts, state regulations, insurance questionnaires)
- Evaluating supply chain cybersecurity risk management practices
- Annual or periodic reassessment of cybersecurity program maturity

## Context

The NIST Cybersecurity Framework (CSF) 2.0, published February 26, 2024, is a major update to the original CSF 1.1 (April 2018). CSF 2.0 is designed for all organizations, not just critical infrastructure, and introduces the GOVERN function as a new top-level function emphasizing cybersecurity governance, risk management strategy, and supply chain risk management.

### Key Changes from CSF 1.1 to 2.0

- **GOVERN (GV) function added**: Elevates governance from an implicit concept to an explicit, top-level function
- **Expanded scope**: Explicitly applies to all organizations regardless of size, sector, or maturity
- **Organizational Profiles**: Replaces "Framework Profiles" terminology; emphasizes current and target state documentation
- **Supply chain risk management**: Elevated with dedicated subcategories under GV and ID
- **Improved implementation guidance**: CSF 2.0 Reference Tool and implementation examples published alongside the framework
- **Community Profiles**: Sector-specific or community-developed profiles recognized as formal artifacts

### CSF 2.0 Structure

| Function | ID | Categories |
|----------|----|-----------|
| **GOVERN** | GV | Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles, Responsibilities, and Authorities (GV.RR), Policy (GV.PO), Oversight (GV.OV), Cybersecurity Supply Chain Risk Management (GV.SC) |
| **IDENTIFY** | ID | Asset Management (ID.AM), Risk Assessment (ID.RA), Improvement (ID.IM) |
| **PROTECT** | PR | Identity Management, Authentication, and Access Control (PR.AA), Awareness and Training (PR.AT), Data Security (PR.DS), Platform Security (PR.PS), Technology Infrastructure Resilience (PR.IR) |
| **DETECT** | DE | Continuous Monitoring (DE.CM), Adverse Event Analysis (DE.AE) |
| **RESPOND** | RS | Incident Management (RS.MA), Incident Analysis (RS.AN), Incident Response Reporting and Communication (RS.CO), Incident Mitigation (RS.MI) |
| **RECOVER** | RC | Incident Recovery Plan Execution (RC.RP), Incident Recovery Communication (RC.CO) |

### CSF Tiers

| Tier | Name | Description |
|------|------|-------------|
| **Tier 1** | Partial | Risk management is ad hoc; limited awareness of cybersecurity risk at the organizational level; no established processes |
| **Tier 2** | Risk Informed | Risk management practices are approved by management b
在 GitHub 阅读完整来源 (打开外部页面)
相关上下文

相关工作