- Provides the exact GV.RM-02 outcome and states that organizations can repeat the Profile steps as often as needed.
References and citations
- Use the official tool to confirm the outcome text and current supplementary resources before updating a row.
A field-by-field NIST CSF 2.0 Current and Target Profile worksheet for compatible outcome comparisons, evidence, gaps, and action plans.
This is an optional operating template, not a NIST-mandated form. Keep one Profile header and one row per selected Core outcome.
Structured answer sets in this page tree.
Cited legal and guidance references.
An describes current and/or target cybersecurity posture through selected CSF Core outcomes. This worksheet follows NIST's five-step Profile cycle: scope the Profile, gather information, create the and/or , analyze gaps and create an action plan, then implement the plan and update the Profile. Adapt the fields, characterization scale, review cadence, and retention rules to the organization and any controlling requirements; CSF 2.0 does not mandate a form, score, deadline, or evidence package.
The Profile owner completes the header before outcome owners, evidence custodians, and reviewers add rows. Every Current and Target entry must use the same stated boundary or clearly identify why a comparison is not valid.
Use the cited sources to turn the guidance into scoped decisions, owners, evidence requests, and review checkpoints.
Create cited tasks, evidence requests, and review checkpoints for this NIST CSF 2.0 scope.
Check source coverage, ownership, evidence gaps, and next steps before publishing or operationalizing the work.
Create one row for each selected CSF Subcategory. Keep the official outcome text separate from the organization's characterization, implementation method, and evidence.
Do not mark a row complete because a policy exists or an action has been assigned. Close it only when the stated acceptance criterion is met, the supporting evidence covers the scope, and the authorized reviewer records the updated Current characterization.
Worked row: GV.RM-02 concerns establishing, communicating, and maintaining risk appetite and risk tolerance statements. A Current entry might record that an approved statement exists but distribution and scheduled maintenance are not evidenced. The Target entry can select the complete outcome, the gap can identify communication and maintenance, and the action plan can assign distribution records and a review mechanism. This example illustrates the worksheet; NIST does not prescribe those particular artifacts.