performing-nist-csf-maturity-assessment

Featured

The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Performing NIST CSF Maturity Assessment ## Overview The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions: Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF, using the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) to measure organizational cybersecurity posture and create improvement roadmaps. ## When to Use - When conducting security assessments that involve performing nist csf maturity assessment - When following incident response procedures for related security events - When performing scheduled security testing or auditing activities - When validating security controls through hands-on testing ## Prerequisites - Understanding of cybersecurity risk management principles - Access to NIST CSF 2.0 documentation and reference tool - Knowledge of organizational IT/OT environment and security controls - Stakeholder access across business units for assessment interviews ## Core Concepts ### CSF 2.0 Functions (6 Functions, 22 Categories) | Function | Code | Categories | Purpose | |----------|------|-----------|---------| | **Govern** | GV | 6 | Establish and monitor cybersecurity risk management strategy | | **Identify** | ID | 3 | Determine current cybersecurity risk to the organization | | **Protect** | PR | 5 | Implement safeguards to prevent or reduce risk | |...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Solid

nist-csf

Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I assess my cybersecurity posture?", or any request involving organizational cybersecurity risk strategy or framework alignment.

488 Updated today
Sushegaad
Data & Documents Listed

nist-csf

Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I assess my cybersecurity posture?", or any request involving organizational cybersecurity risk strategy or framework alignment.

2 Updated today
Jandyoverseas977
AI & Automation Listed

auditoria-ciberseguridad

Evaluar la postura de ciberseguridad de la organización aplicando NIST CSF 2.0, ISO 27001/27002 y CIS Controls — gobernanza de seguridad, identificación, protección, detección, respuesta y recuperación. Activar siempre que se hable de ciberseguridad, cybersecurity audit, NIST CSF, ISO 27001, ISO 27002, CIS Controls, MITRE ATT&CK, SIEM, SOC, EDR, DLP, IAM, MFA, gestión de vulnerabilidades, pentest, red team, ransomware, phishing, NIS 2, zero trust, gestión de identidades, respuesta a incidentes, IR, threat hunting, breach.

0 Updated 6 days ago
marcelinero
AI & Automation Solid

cmmc

Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".

488 Updated today
Sushegaad
AI & Automation Solid

cybersecurity-risk-assessor

Medical device cybersecurity risk assessment skill per FDA premarket and postmarket guidance

1,034 Updated today
a5c-ai