i-Prot

Frameworks · NIST CSF 2.0

NIST CSF: organize your cybersecurity program by functions.

We adopt the NIST Cybersecurity Framework 2.0 to organize your program and measure its maturity — no certification, with a focus on governance and improvement.

diagram · frameworks · nist csf 2.0

Who it applies to

NIST CSF applies to any organization that wants to structure and mature its cybersecurity program with a common language, without needing to be certified.

What the framework requires

NIST CSF isn’t certified: it’s a voluntary framework that organizes the program into six functions and lets you measure maturity (Tiers) and define a target profile.

Six functions

Govern, Identify, Protect, Detect, Respond and Recover.

Profiles

Current and target state of the program.

Maturity Tiers

From partial to adaptive, to measure progress.

A common language

A framework that leadership and technical staff share.

Risks of not acting

  • Managing cybersecurity without a structure or a common language.
  • Being unable to measure maturity or demonstrate progress.
  • Scattering effort without a clear target profile.
  • Making it harder to communicate risk to leadership.

The i-Prot proposal

We adopt NIST CSF 2.0 as the program framework: we assess the current profile, define the target and a roadmap by function, with maturity metrics. Integrated into the CGF cycle.

How we work with this framework

Current profile

Assessment of the state by function and category.

Target profile

Desired state based on risk and business.

Gap analysis

Differences between current and target.

Roadmap

Initiatives prioritized by function.

Measurement and improvement

Maturity Tiers and indicators over time.

Deliverables

  • Gap analysis
  • Implementation plan
  • Controls matrix
  • System documentation
  • Evidence
  • Internal audit
  • Management review
  • Roadmap

How it connects with CGF

CGF uses NIST CSF as a source of requirements. This framework mainly covers the Assess, Prioritize, Design and Improve stages of the cycle.

See the CGF methodology →

Complyze and NIST CSF

Complyze organizes the program by function, keeps the target profile and tracks maturity (Tiers) and the roadmap’s progress.

Frequently asked questions

Want to structure your program with NIST CSF?

Tell us your context and we’ll define the target profile and the roadmap.

By submitting you accept our privacy policy.

By submitting you accept the privacy policy and the processing of your data in order to be contacted.