WorkflowGLOBALNIST CSF 2.0

NIST CSF 2.0 Profile Workshop Workflow

Prepare and run a NIST CSF 2.0 Profile workshop that produces scoped outcome decisions, evidence requests, and an owned gap plan.

Use meeting time for judgments that require several owners. Gather scope, risk context, and evidence before the session, then record unresolved questions instead of forcing consensus.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Run a Profile workshop when several owners must make outcome-level Current and Target decisions for one scope. The session should end with recorded decisions, unresolved questions, evidence requests, and an owned gap action plan. NIST CSF 2.0 describes a five-step Profile cycle, but it does not require a workshop, prescribe an agenda, or set a universal deadline. This workflow is Sorena's optional facilitation method.

Section 1

Profile workshop workflow: triggers, owners, actions, and outputs

Hold a workshop when Current or judgments cross teams, evidence conflicts, priorities compete, or an accountable risk decision is needed. A Profile lead can handle uncontested updates asynchronously and bring only disputed or high-impact items to the session.

  • 1 | Charter | Trigger: new Profile, material scope change, scheduled review, or unresolved decision | Owner: sponsor and Profile lead | Action: define purpose, boundary, exclusions, covered period, assumptions, decision rights, and selected outcomes | Branch: escalate if the sponsor cannot approve the boundary | Record: approved charter.
  • 2 | Prepare | Trigger: charter approved | Owner: risk, system, process, supplier, and evidence owners | Action: collect policies, requirements, risk priorities, business-impact information, practices, tools, work roles, and dated evidence | Branch: mark an outcome unknown if the required facts cannot be obtained before the session | Record: pre-read and evidence index.
  • 3 | Characterize Current | Trigger: sufficient material is available for review | Owner: outcome owners with facilitator | Action: state what is achieved or attempted, to what extent, for which population and period | Branch: record conflicting evidence and assign a resolver instead of averaging opinions | Record: Current statement, limitations, and evidence requests for each selected .
  • 4 | Select Target and analyze gaps | Trigger: Current judgment recorded | Owner: risk owner and sponsor | Action: select and prioritize the desired outcome, analyze the gap, and choose a response | Branch: accept, mitigate, share or transfer, avoid, change the target, request evidence, or escalate under the organization's risk process | Record: driver, dependencies, resources, owner, milestone, acceptance criterion, and approval.
  • 5 | Close and update | Trigger: decisions complete or timebox reached | Owner: Profile lead | Action: read back decisions, issue the Profile and action plan, and route open items | Branch: withhold approval where evidence or authority remains missing | Record: Profile version, decision log, communication list, open-item register, and reassessment triggers.
Section 2

Facilitation rules for outcome-level decisions

Review one at a time using the same scope. The facilitator records the decision and rationale but should not overrule the accountable owner or convert missing evidence into a favorable score.

  • Current | What is achieved or attempted now, to what extent, for which population and period, and what records support that statement?
  • Target | Which desired outcome is selected and prioritized, and is the driver a mission objective, stakeholder expectation, threat, requirement, dependency, or planned change?
  • Gap | What risk or constraint follows from the difference, and what response, owner, resources, dependency, and acceptance criterion apply?
  • Disagreement | Is the conflict about facts, evidence sufficiency, priority, resources, or decision authority? Record the issue and route it to the named resolver.
  • No decision | If the evidence or authorized owner is absent, record an open question and due date. Do not treat workshop silence as approval or risk acceptance.
Section 3

Closeout record and reassessment triggers

Send the decision record to participants for factual correction, then route approvals through the organization's existing authority model. The workshop itself does not create authority to accept risk. Preserve the prior Profile version so reviewers can trace changed scope, outcome text, evidence, priorities, and approvals.

  • Header | Profile name and version; scope; date; sponsor; facilitator; attendees and roles; assumptions; exclusions; decision-rights statement.
  • Outcome row | CSF identifier and text; Current characterization and evidence; Target priority and driver; gap; response; rationale; owner; milestone; acceptance criterion.
  • Open item | Missing evidence, conflicting statement, absent authority, dependency, resolver, due date, and effect on the Profile conclusion.
  • Decision record | Approver, decision date, conditions, residual uncertainty, communication recipients, and links to the action plan and protected evidence.
  • Reassess after a material change in scope, mission, requirements, threats, technology, supplier dependency, risk direction, evidence, or action-plan status; also use any review cadence set by the organization.
Primary sources

References and citations

doi.org
Referenced sections
  • States that the Profile cycle can be repeated as often as needed and describes updates flowing through risk registers, progress reports, and revised Profiles.
csrc.nist.gov
Referenced sections
  • Official tool for checking Core identifiers and exporting the Core, Implementation Examples, and Informative References used in workshop materials.
Related guides

Explore more topics

How should teams handle evidence mapping under NIST CSF 2.0?
Map policies, configurations, tests, logs, approvals, and operating records to specific NIST CSF 2.0 outcomes without treating a reference or policy as proof of performance.
How should teams handle implementation examples under NIST CSF 2.0?
Use NIST CSF 2.0 Implementation Examples as optional, non-exhaustive ways to help achieve a Subcategory outcome, then tailor and test the chosen practice.
How should teams handle supplier risk under NIST CSF 2.0?
Apply NIST CSF 2.0 supplier-risk outcomes across selection, contracting, monitoring, incident coordination, and relationship exit, with effort based on criticality and risk.
How should teams handle target profiles under NIST CSF 2.0?
Build a NIST CSF 2.0 Target Profile by selecting and prioritizing desired Core outcomes, then turn Current-to-Target gaps into owned risk actions.
How should teams handle tiers under NIST CSF 2.0?
Use NIST CSF 2.0 Tiers to characterize risk governance and management rigor for a defined scope without turning them into certification levels or a universal maturity score.
NIST CSF 2.0 Core Functions Guide
Understand GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER, including their Categories, concurrent use, ownership, evidence, and Profile decisions.
NIST CSF 2.0 current and target profile template: operating columns and evidence rows
A field-by-field NIST CSF 2.0 Current and Target Profile worksheet for compatible outcome comparisons, evidence, gaps, and action plans.
NIST CSF 2.0 Current vs Target Profile Template
Build a NIST CSF 2.0 Current and Target Profile with a defined scope, outcome-level evidence, priorities, owners, milestones, and reassessment triggers.
NIST CSF 2.0 Evidence Mapping Workflow
Map a NIST CSF 2.0 outcome to evidence, test what the record proves, document gaps, and assign the next risk decision.
NIST CSF 2.0 FAQ: practical implementation questions
Direct answers on NIST CSF 2.0 Tiers, GOVERN, Profiles, supplier risk, Implementation Examples, evidence mapping, and board reporting.
NIST CSF 2.0 GOVERN Function FAQ
Start the NIST CSF 2.0 GOVERN function by naming decision owners, risk strategy, policy expectations, oversight cadence, and supplier-risk accountability before mapping controls.
NIST CSF 2.0 Governance and Metrics Guide
Connect NIST CSF 2.0 GOVERN outcomes to decisions, owners, risk appetite, and metrics without inventing a single maturity score.
NIST CSF 2.0 Implementation Examples Guide
Use NIST CSF 2.0 Implementation Examples as optional prompts, adapt them to one scoped outcome, and define evidence that tests the result.
NIST CSF 2.0 Profile Workshop Template
A fill-in NIST CSF 2.0 Profile workshop template for scope, roles, outcome decisions, evidence gaps, approvals, and follow-up.
NIST CSF 2.0 Requirements Mapping Guide
Build a traceable mapping from applicable requirements to NIST CSF 2.0 outcomes, controls, evidence, gaps, and owners without treating the mapping as proof of compliance.
NIST CSF 2.0 vs CIS Controls v8.1: Mapping and Gap Analysis
Map CSF 2.0 outcomes to CIS Controls v8.1 safeguards without confusing a crosswalk with implementation evidence or full outcome achievement.
NIST CSF 2.0 vs CIS Controls v8.1: Which to Use
Choose CSF 2.0 for outcome-based risk governance, CIS Controls v8.1 for prioritized safeguards, or combine them with separate claims and evidence.
NIST CSF 2.0 vs ISO/IEC 27001:2022: Which to Use
Choose CSF 2.0 for outcome-based cyber-risk governance or ISO/IEC 27001:2022 for a requirements-based ISMS and possible certification.
NIST CSF 2.0 vs NIST RMF: practical side-by-side comparison
Decide when to use NIST CSF 2.0 outcomes and Profiles, when to use the seven-step NIST RMF process, and how to connect their evidence.
NIST CSF 2.0 vs SP 800-53 Rev. 5: control mapping and coverage gaps
Map CSF 2.0 outcomes to SP 800-53 Rev. 5 controls while preserving scope, tailoring, assessment, and partial-coverage limits.
NIST CSF 2.0 vs SP 800-53 Rev. 5: Which to Use
Choose CSF 2.0 for outcome-based cybersecurity governance or SP 800-53 Rev. 5 for control selection, tailoring, implementation, and assessment.
NIST CSF 2.0: step-by-step workflow for building current and target profiles
Build compatible NIST CSF 2.0 Current and Target Profiles, analyze each gap, and turn the comparison into a risk-informed action plan.
What should an NIST CSF 2.0 Current Profile include to be useful for audits and risk decisions?
A useful CSF 2.0 Current Profile should show current outcomes, accountable owners, supporting evidence, known gaps, dependencies, and review dates. It should be specific enough that a reviewer can understand what is true today without re-interviewing every team.
Which NIST CSF 2.0 metrics are useful for board and executive reporting?
Use board-level CSF 2.0 metrics that show risk decisions, business impact, target-profile gaps, and progress against priorities. Avoid only reporting control counts; executives need to see whether cybersecurity outcomes are improving in the context of organizational objectives.