workflow
CSF 2.0 Profile & Maturity Assessment
Runs on an Audit item created for this assessment cycle (audit_type = readiness) — the CSF assessment engagement the workflow instance attaches to and enriches as it progresses (scope, period, rating, and report fields are written on that Audit item; every in-scope Control is linked to it so the controls-scoped profile is queryable). Build, against that boundary, a NIST CSF 2.0 Current Profile, a Target Profile, an organizational Tier rating, a subcategory gap analysis, and a CISO-ready remediation roadmap. The workflow originates on its own — scoping ingests prior CSF profiles and open POA&M (Issue) items as data, not as a named upstream handoff. In scope: rating the in-scope control set against the CSF 2.0 Core, setting target outcomes, assigning a Tier, and producing a prioritized roadmap. Out of scope: executing the remediation projects themselves and re-performing independent assurance testing. The named deliverable is the assessment package (profiles, gap analysis, Tier, posture report, roadmap, closure artifact), handed off to TWO downstream workflows that consume it rather than repeat the profiling: the Cybersecurity Assurance Review (always) and the AI Governance & Risk/Impact Assessment (only when AI systems fall inside the boundary).
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- monitor
Details
- teams
- it
- executive
- domains
- controls
- standards
- nist-csf-2
- sourceTemplateId
- workflow-library:controls-csf-profile-maturity-assessment
- releaseId
- sha256:27c45a606d72b2ab411434c5a4c54d39fbe813777b3075321f79ec72cf5de5a8
- canonicalUrl
- https://workflow-library.com/all/?w=controls-csf-profile-maturity-assessment
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-AUDIT-22
- UC-RISK-13
- UC-RISK-14
- UC-GOV-02
- UC-GOV-04
- UC-GOV-06
- UC-GOV-09
- UC-GOV-10
- UC-GOV-11
- UC-GOV-12
- UC-TPRM-01
- UC-RISK-15
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:27c45a606d72b2ab411434c5a4c54d39fbe813777b3075321f79ec72cf5de5a8
Connections
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-04 — Set tone at the top: integrity, ethics, and risk-aware culture
- CSF 2.0 Profile & Maturity Assessment oversees UC-RISK-14 — Track deficiencies to closure with remediation action plans
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-11 — Allocate adequate resources and budget for security
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-10 — Attract, develop, and retain competent personnel
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-06 — Define security roles, responsibilities, and authorities
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-02 — Understand organizational context and stakeholder expectations
- CSF 2.0 Profile & Maturity Assessment oversees UC-TPRM-01 — Operate a third-party security risk management program
- CSF 2.0 Profile & Maturity Assessment oversees UC-RISK-15 — Continually improve the risk management program
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-09 — Appoint accountable security leadership (CISO)
- CSF 2.0 Profile & Maturity Assessment oversees UC-AUDIT-22 — Review risk strategy and performance with leadership
- CSF 2.0 Profile & Maturity Assessment oversees UC-RISK-13 — Monitor and review risk management performance
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-12 — Align strategy and business objectives with mission and risk