home / frameworks / nist-csf / profiles-and-tiers

// NIST CSF hub

NIST CSF profiles and tiers

How organizational profiles, community profiles, and the 4 tiers turn the CSF Core into a working plan.

What a profile is

An organizational profile describes an organization's cybersecurity posture in terms of CSF outcomes. NIST describes 2 parts. A current profile lists the outcomes the organization achieves today and how well. A target profile lists the outcomes it has chosen and prioritized to meet its risk management objectives, often looking ahead to new threats, technologies, or regulatory requirements.

Comparing the two shows the gaps. The organization then builds an action plan, with owners, budgets, and timelines, to close the gaps that matter most to its mission and its customers. NIST publishes a spreadsheet template so the current and target views can sit side by side.

Building and using a profile

The CSF 2.0 document sets out 5 steps for using profiles. They follow a cycle rather than a one-time project.

Scope comes first. A profile can cover a whole company, one business unit, or a single system such as a payment platform, and the choice affects how much evidence the team has to gather. Many Canadian organizations start with the systems that hold customer data or support services sold to U.S. clients, because those are the areas questionnaires ask about.

  • Scope the profile
  • Gather the information needed to prepare it
  • Create the current and target profiles
  • Analyze gaps and build an action plan
  • Carry out the plan and update the profile

Community profiles

A community profile is a baseline of CSF outcomes written for a shared need, such as a sector, a technology, or a threat. NIST lists community profiles for manufacturing, semiconductor manufacturing, ransomware risk management, the financial sector, telecommunications, transit, cloud security, internet routing, genomic data, positioning, navigation, and timing services, and incident response, along with a Cyber AI Profile.

An organization can use a community profile as the starting point for its own target profile. That saves time. It also lines the organization up with what peers, customers, and regulators in its sector already expect to see in a security program. NIST also publishes a guide and a template for groups that want to write their own community profile.

The 4 tiers

Tiers describe the rigour of an organization's cybersecurity risk governance and risk management practices, looking at the organization as a whole rather than at individual systems. They aren't control scores. There are 4: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4).

Tier 1 is ad hoc. Risk is handled case by case with limited awareness across the organization. At Tier 2, leadership approves risk practices but they may not be organization-wide policy. Tier 3 means practices are formally approved, expressed as policy, and updated regularly, while Tier 4 means the organization adapts its practices based on lessons learned and predictive indicators. NIST says organizations should aim for the tier that meets their goals and is feasible to reach, and that a higher tier isn't always needed.

Practical tips

Keep profiles short enough to maintain. A target profile that lists all 106 subcategories at the same priority rarely helps anyone decide what to fund next. Most teams mark a smaller set as high priority for the coming year and note which informative references, such as ISO/IEC 27001 controls or Canadian Centre for Cyber Security baseline controls, they'll use to meet each one.

Profiles also work well for reporting to boards and to customers. A one-page view of current and target status by function is easier to discuss than a long control spreadsheet.

Resources

All NIST CSF resources

References

  1. The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29), NIST
  2. CSF 2.0 Profiles, NIST
  3. CSF 2.0 Quick Start Guides, NIST