workflow

CSF 2.0 Profile & Maturity Assessment

Runs on an Audit item created for this assessment cycle (audit_type = readiness) — the CSF assessment engagement the workflow instance attaches to and enriches as it progresses (scope, period, rating, and report fields are written on that Audit item; every in-scope Control is linked to it so the controls-scoped profile is queryable). Build, against that boundary, a NIST CSF 2.0 Current Profile, a Target Profile, an organizational Tier rating, a subcategory gap analysis, and a CISO-ready remediation roadmap. The workflow originates on its own — scoping ingests prior CSF profiles and open POA&M (Issue) items as data, not as a named upstream handoff. In scope: rating the in-scope control set against the CSF 2.0 Core, setting target outcomes, assigning a Tier, and producing a prioritized roadmap. Out of scope: executing the remediation projects themselves and re-performing independent assurance testing. The named deliverable is the assessment package (profiles, gap analysis, Tier, posture report, roadmap, closure artifact), handed off to TWO downstream workflows that consume it rather than repeat the profiling: the Cybersecurity Assurance Review (always) and the AI Governance & Risk/Impact Assessment (only when AI systems fall inside the boundary).

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
monitor

Details

teams
  • it
  • executive
domains
  • controls
standards
  • nist-csf-2
sourceTemplateId
workflow-library:controls-csf-profile-maturity-assessment
releaseId
sha256:27c45a606d72b2ab411434c5a4c54d39fbe813777b3075321f79ec72cf5de5a8
canonicalUrl
https://workflow-library.com/all/?w=controls-csf-profile-maturity-assessment
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-AUDIT-22
    • UC-RISK-13
    • UC-RISK-14
    • UC-GOV-02
    • UC-GOV-04
    • UC-GOV-06
    • UC-GOV-09
    • UC-GOV-10
    • UC-GOV-11
    • UC-GOV-12
    • UC-TPRM-01
    • UC-RISK-15
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:27c45a606d72b2ab411434c5a4c54d39fbe813777b3075321f79ec72cf5de5a8

            Connections