Board metrics to prioritize
Report the measures that help executives decide whether to maintain or adjust risk strategy, priorities, resources, or risk responses. Pair each measure with its business or mission objective, scope, owner, trend, threshold, data period, and the decision or escalation it can trigger. Connect the threshold to the organization's approved or tolerance statement.
Current-to- gaps and action-plan status show whether priority outcomes are moving. Risk indicators show changes in exposure or impact. Performance indicators show whether a selected practice operates as intended. Control counts can supply detail, but they do not show business significance unless they are connected to a Core outcome and risk decision.
Use only when the organization has chosen them to inform its Profiles. Report the supporting governance and risk-management observations; do not present Tier movement as a universal maturity score or imply that Tier 4 is always the required destination.
NIST published on February 26, 2024 as voluntary, outcome-based guidance for organizations of any size or sector. It does not create a universal reporting deadline, metric formula, certification, or legal safe harbor. A law, regulator, customer agreement, insurer, or internal policy may impose separate measures or reporting dates, so record those requirements beside the CSF outcome instead of presenting them as NIST requirements.
- Priority Current-to-Target gaps by business service, risk consequence, owner, due date, and action-plan status.
- Exposure above approved appetite or tolerance, including the response, decision authority, review date, and trend.
- Risk-reduction milestones delivered and the corresponding change in the Profile or operational risk measure.
- Coverage and tested performance of outcomes protecting mission-essential services, with exceptions and stale evidence identified.
- Critical supplier exposure, unmet contractual or due-diligence expectations, and unresolved concentration or exit dependencies.
- Incident and recovery measures for important services, such as time to declare, contain, restore, and confirm normal operation, interpreted against approved objectives.
- Tier observations for the reported scope only when Tiers inform the organization's Profiles.
CSF 2.0 supports board-metric design by tying cybersecurity outcomes, profiles, and implementation tiers to organizational risk decisions.
NIST resource center for CSF 2.0 quick-start guides, examples, profiles, and informative references.
NIST risk assessment guidance used as adjacent support for risk analysis and prioritization.