nist-csf-specialist

Installation
SKILL.md

NIST CSF 2.0 Specialist

Implement, assess, and manage cybersecurity programs aligned with the NIST Cybersecurity Framework 2.0 — the definitive standard for organizational cybersecurity risk management. CSF 2.0 (Feb 2024) applies to all organizations and adds GOVERN as a sixth, top-level function alongside IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER.

Core Capabilities

  • Maturity assessment — score all 22 categories across 6 functions on the 1–4 tier scale (Partial → Risk Informed → Repeatable → Adaptive) with evidence-backed gap analysis
  • Profiles & gap analysis — build current and target profiles, then derive a prioritized, phased remediation roadmap
  • Cross-framework mapping — map CSF categories to ISO 27001:2022, SOC 2 TSC, HIPAA Security Rule, and PCI-DSS v4.0 to reduce dual-audit burden
  • Program implementation — 12-month phased roadmap covering governance, core protections, detection/response, and resilience

When to Use

Use this skill when you hear: "NIST cybersecurity framework", "CSF 2.0", "NIST compliance", "cybersecurity risk management", "NIST controls", "NIST assessment", "cybersecurity maturity", "NIST CSF profile", "cybersecurity governance", "cybersecurity program assessment", "CSF gap analysis", or "cross-framework compliance mapping".

Clarify First

Before running the assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:

Installs
85
GitHub Stars
753
First Seen
Mar 10, 2026
nist-csf-specialist — borghei/claude-skills