What it does. Conduct a NIST Cybersecurity Framework (CSF) 2.0 maturity assessment across the six core Functions (Govern, Identify, Protect, Detect, Respond, Recover), scoring organizational posture against the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) and producing an improvement roadmap. Use when benchmarking an organization's cybersecurity program maturity or preparing a CSF-based gap analysis and remediation plan. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-nist-csf-maturity-assessment, or copy the skill folder into ~/.claude/skills/performing-nist-csf-maturity-assessment/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-nist-csf-maturity-assessment/SKILL.md
SKILL.md (verbatim)
name: performing-nist-csf-maturity-assessment
description: Conduct a NIST Cybersecurity Framework (CSF) 2.0 maturity assessment across the six core Functions (Govern, Identify, Protect, Detect, Respond, Recover), scoring organizational posture against the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) and producing an improvement roadmap. Use when benchmarking an organization's cybersecurity program maturity or preparing a CSF-based gap analysis and remediation plan.
domain: cybersecurity
subdomain: compliance-governance
tags:
- compliance
- governance
- nist
- csf
- maturity-assessment
- risk-management
nist_csf:
- GV.OC-01
- GV.RM-01
- GV.PO-01
- ID.RA-01
- GV.OV-01
version: '1.0'
author: mahipal
license: Apache-2.0
mitre_attack:
- T1078
- T1530
- T1685.002
Performing NIST CSF Maturity Assessment
Overview
The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions: Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF, using the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) to measure organizational cybersecurity posture and create improvement roadmaps.
When to Use
- When conducting security assessments that involve performing nist csf maturity assessment
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Prerequisites
- Understanding of cybersecurity risk management principles
- Access to NIST CSF 2.0 documentation and reference tool
- Knowledge of organizational IT/OT environment and security controls
- Stakeholder access across business units for assessment interviews
Core Concepts
CSF 2.0 Functions (6 Functions, 22 Categories)
| Function |
Code |
Categories |
Purpose |
| Govern |
GV |
6 |
Establish and monitor cybersecurity risk management strategy |
| Identify |
ID |
3 |
Determine current cybersecurity risk to the organization |
| Protect |
PR |
5 |
Implement safeguards to prevent or reduce risk |
| Detect |
DE |
2 |
Find and analyze possible cybersecurity attacks |
| Respond |
RS |
4 |
Take action regarding detected cybersecurity incidents |
| Recover |
RC |
2 |
Restore capabilities impaired by cybersecurity incidents |
Govern Function (New in CSF 2.0)
- GV.OC: Organizational Context
- GV.RM: Risk Management Strategy
- GV.RR: Roles, Responsibilities, and Authorities
- GV.PO: Policy
- GV.OV: Oversight
- GV.SC: Cybersecurity Supply Chain Risk Management
Implementation Tiers
| Tier |
Name |
Description |
| Tier 1 |
Partial |
Ad hoc, reactive; limited awareness of cybersecurity risk |
| Tier 2 |
Risk-Informed |
Risk-aware but not organization-wide; approved but may not be policy |
| Tier 3 |
Repeatable |
Formal policies; consistently implemented; regularly updated |
| Tier 4 |
Adaptive |
Continuous improvement; real-time risk response; lessons learned integrated |
Workflow
Phase 1: Scoping and Preparation (Weeks 1-2)
- Define assessment scope (enterprise-wide vs. business unit)
- Identify stakeholders and schedule interviews
- Gather existing documentation (policies, procedures, architecture diagrams)
- Customize CSF Profile for organizational context
- Select assessment methodology (self-assessment, facilitated, third-party)
Phase 2: Current State Assessment (Weeks 3-6)
- Assess each CSF Category and Subcategory against Implementation Tiers
- For each subcategory, evaluate:
- Policy/documentation maturity
- Implementation completeness
- Automation level
- Measurement and metrics
- Continuous improvement evidence
- Score using tier criteria (1-4 scale)
- Document evidence supporting each tier rating
- Identify strengths, gaps, and improvement areas
Phase 3: Target State Definition (Weeks 7-8)
- Define target tier for each Function based on:
- Risk appetite and tolerance
- Industry requirements and benchmarks
- Regulatory obligations
- Available resources and budget
- Create Target Profile documenting desired maturity state
- Validate target state with executive leadership
Phase 4: Gap Analysis and Roadmap (Weeks 9-12)
- Compare Current Profile to Target Profile
- Prioritize gaps based on risk reduction potential
- Develop improvement roadmap with:
- Short-term quick wins (0-3 months)
- Medium-term improvements (3-12 months)
- Long-term strategic initiatives (12-24 months)
- Estimate resource requirements for each initiative
- Assign ownership and timelines
Phase 5: Implementation and Reassessment (Ongoing)
- Execute improvement roadmap initiatives
- Track progress against milestones
- Conduct periodic reassessments (annually recommended)
- Report maturity progress to leadership
- Adjust roadmap based on evolving threats and business changes
Key Artifacts
- CSF Current Profile (by Function/Category/Subcategory)
- CSF Target Profile
- Gap Analysis Report
- Maturity Assessment Scorecard
- Improvement Roadmap with Priorities
- Executive Summary and Dashboard
Common Pitfalls
- Assessing technology only without evaluating governance and people
- Setting unrealistic target tiers without resource commitment
- Treating assessment as one-time rather than continuous process
- Ignoring the new Govern function in CSF 2.0
- Not aligning CSF assessment with existing compliance requirements (ISO 27001, SOC 2)
References
Other files in this skill
assets/template.md (verbatim)
NIST CSF 2.0 Maturity Assessment Scorecard
Organization: ________________
Assessment Date: ________________
Assessor: ________________
Scoring Guide
| Tier |
Name |
Criteria |
| 1 |
Partial |
Ad hoc; limited awareness; no formal process |
| 2 |
Risk-Informed |
Management-approved; inconsistent application |
| 3 |
Repeatable |
Formal policies; consistent implementation; metrics |
| 4 |
Adaptive |
Continuous improvement; real-time; advanced automation |
Function: GOVERN (GV)
| Category |
Current (1-4) |
Target (1-4) |
Gap |
Evidence |
Notes |
| GV.OC - Organizational Context |
|
|
|
|
|
| GV.RM - Risk Management Strategy |
|
|
|
|
|
| GV.RR - Roles and Responsibilities |
|
|
|
|
|
| GV.PO - Policy |
|
|
|
|
|
| GV.OV - Oversight |
|
|
|
|
|
| GV.SC - Supply Chain Risk Mgmt |
|
|
|
|
|
| Function Average |
|
|
|
|
|
Function: IDENTIFY (ID)
| Category |
Current (1-4) |
Target (1-4) |
Gap |
Evidence |
Notes |
| ID.AM - Asset Management |
|
|
|
|
|
| ID.RA - Risk Assessment |
|
|
|
|
|
| ID.IM - Improvement |
|
|
|
|
|
| Function Average |
|
|
|
|
|
Function: PROTECT (PR)
| Category |
Current (1-4) |
Target (1-4) |
Gap |
Evidence |
Notes |
| PR.AA - Identity & Access Control |
|
|
|
|
|
| PR.AT - Awareness and Training |
|
|
|
|
|
| PR.DS - Data Security |
|
|
|
|
|
| PR.PS - Platform Security |
|
|
|
|
|
| PR.IR - Infrastructure Resilience |
|
|
|
|
|
| Function Average |
|
|
|
|
|
Function: DETECT (DE)
| Category |
Current (1-4) |
Target (1-4) |
Gap |
Evidence |
Notes |
| DE.CM - Continuous Monitoring |
|
|
|
|
|
| DE.AE - Adverse Event Analysis |
|
|
|
|
|
| Function Average |
|
|
|
|
|
Function: RESPOND (RS)
| Category |
Current (1-4) |
Target (1-4) |
Gap |
Evidence |
Notes |
| RS.MA - Incident Management |
|
|
|
|
|
| RS.AN - Incident Analysis |
|
|
|
|
|
| RS.CO - Response Communication |
|
|
|
|
|
| RS.MI - Incident Mitigation |
|
|
|
|
|
| Function Average |
|
|
|
|
|
Function: RECOVER (RC)
| Category |
Current (1-4) |
Target (1-4) |
Gap |
Evidence |
Notes |
| RC.RP - Recovery Plan Execution |
|
|
|
|
|
| Function Average |
|
|
|
|
|
Overall Summary
| Function |
Current Avg |
Target Avg |
Gap |
| Govern |
|
|
|
| Identify |
|
|
|
| Protect |
|
|
|
| Detect |
|
|
|
| Respond |
|
|
|
| Recover |
|
|
|
| Overall |
|
|
|
Top Priority Gaps
| # |
Category |
Current |
Target |
Recommended Action |
Owner |
Timeline |
| 1 |
|
|
|
|
|
|
| 2 |
|
|
|
|
|
|
| 3 |
|
|
|
|
|
|
| 4 |
|
|
|
|
|
|
| 5 |
|
|
|
|
|
|
Sign-off
| Role |
Name |
Signature |
Date |
| CISO |
|
|
|
| CTO/CIO |
|
|
|
| Risk Officer |
|
|
|
references/api-reference.md (verbatim)
API Reference — Performing NIST CSF Maturity Assessment
Libraries Used
- csv: Parse and generate assessment CSV files
- pathlib: File operations
CLI Interface
python agent.py assess --csv assessment_responses.csv
python agent.py gaps --csv assessment_responses.csv
python agent.py template [--output template.csv]
python agent.py executive --csv assessment_responses.csv
Core Functions
assess_from_csv(assessment_file) — Calculate maturity scores
Scores each NIST CSF function (Identify, Protect, Detect, Respond, Recover).
Calculates overall maturity level (1-4 scale) and gap-to-target.
generate_gap_analysis(assessment_file) — Prioritized gap report
Classifies gaps: HIGH (>=2 gap), MEDIUM (>=1), LOW (<1).
create_assessment_template(output_file) — Generate blank assessment CSV
Produces CSV with all 23 CSF categories, score/target/evidence columns.
generate_executive_summary(assessment_file) — Board-level report
NIST CSF Functions & Categories (23 total)
| Function |
Categories |
| IDENTIFY |
ID.AM, ID.BE, ID.GV, ID.RA, ID.RM, ID.SC |
| PROTECT |
PR.AC, PR.AT, PR.DS, PR.IP, PR.MA, PR.PT |
| DETECT |
DE.AE, DE.CM, DE.DP |
| RESPOND |
RS.RP, RS.CO, RS.AN, RS.MI, RS.IM |
| RECOVER |
RC.RP, RC.IM, RC.CO |
Maturity Levels
| Level |
Name |
Description |
| 1 |
Partial |
Not formalized |
| 2 |
Risk Informed |
Approved but not org-wide |
| 3 |
Repeatable |
Formally expressed as policy |
| 4 |
Adaptive |
Continuous improvement |
Dependencies
No external packages — Python standard library only.
references/standards.md (verbatim)
NIST CSF 2.0 Standards Reference
Primary Standard
NIST Cybersecurity Framework (CSF) Version 2.0
- Published: February 26, 2024
- Publisher: National Institute of Standards and Technology (NIST)
- Document: NIST CSWP 29
- Scope: Applicable to all organizations regardless of size, sector, or maturity
- Key Change: Added Govern function as central pillar; expanded from 5 to 6 functions
CSF 2.0 Core Structure
GV - Govern
- GV.OC-01 to GV.OC-05: Organizational context understood
- GV.RM-01 to GV.RM-07: Risk management strategy established
- GV.RR-01 to GV.RR-04: Roles, responsibilities, and authorities
- GV.PO-01 to GV.PO-02: Cybersecurity policy established
- GV.OV-01 to GV.OV-03: Cybersecurity strategy oversight
- GV.SC-01 to GV.SC-10: Supply chain risk management
ID - Identify
- ID.AM-01 to ID.AM-08: Asset management
- ID.RA-01 to ID.RA-10: Risk assessment
- ID.IM-01 to ID.IM-04: Improvement
- ID.BE (removed in 2.0, moved to GV)
PR - Protect
- PR.AA-01 to PR.AA-06: Identity management, authentication, access control
- PR.AT-01 to PR.AT-02: Awareness and training
- PR.DS-01 to PR.DS-10: Data security
- PR.PS-01 to PR.PS-06: Platform security
- PR.IR-01 to PR.IR-02: Technology infrastructure resilience
DE - Detect
- DE.CM-01 to DE.CM-09: Continuous monitoring
- DE.AE-01 to DE.AE-08: Adverse event analysis
RS - Respond
- RS.MA-01 to RS.MA-05: Incident management
- RS.AN-01 to RS.AN-08: Incident analysis
- RS.CO-01 to RS.CO-03: Incident response reporting and communication
- RS.MI-01 to RS.MI-02: Incident mitigation
RC - Recover
- RC.RP-01 to RC.RP-06: Incident recovery plan execution
Implementation Tiers Detail
Tier 1: Partial
- Risk Management Process: Ad hoc; not formalized
- Integrated Risk Management: Limited awareness; irregular risk practices
- External Participation: No formal collaboration with external entities
- Governance: Cybersecurity not integrated into enterprise risk management
- Risk Management Process: Approved by management but may not be policy
- Integrated Risk Management: Awareness at organizational level; some sharing
- External Participation: Aware of ecosystem role; limited collaboration
- Governance: Some integration of cybersecurity into enterprise risk
Tier 3: Repeatable
- Risk Management Process: Formally approved policies; regularly updated
- Integrated Risk Management: Organization-wide approach; consistent implementation
- External Participation: Regular collaboration with partners and ecosystem
- Governance: Cybersecurity fully integrated into enterprise risk management
Tier 4: Adaptive
- Risk Management Process: Continuous improvement using advanced techniques
- Integrated Risk Management: Real-time shared awareness; dynamic risk response
- External Participation: Active leadership in ecosystem risk management
- Governance: Agile cybersecurity governance adapting to changes
- SP 800-53 Rev 5: Security and Privacy Controls (detailed control catalog)
- SP 800-37 Rev 2: Risk Management Framework (RMF)
- SP 800-30 Rev 1: Guide for Conducting Risk Assessments
- SP 800-171 Rev 3: Protecting CUI in Nonfederal Systems
- SP 800-207: Zero Trust Architecture
- SP 800-218: Secure Software Development Framework (SSDF)
The CSF references specific controls from:
- NIST SP 800-53 Rev 5
- ISO/IEC 27001:2022
- CIS Controls v8
- COBIT 2019
- ISA/IEC 62443 (Industrial Control Systems)
references/workflows.md (verbatim)
NIST CSF Maturity Assessment Workflows
Workflow 1: Assessment Planning
Start
|
v
[Define Assessment Scope]
- Enterprise-wide or business unit
- Include/exclude OT systems
- Include/exclude third parties
|
v
[Identify Stakeholders]
- CISO and security team
- IT leadership
- Business unit leaders
- Risk management
- Legal/compliance
- Executive sponsors
|
v
[Select Assessment Approach]
+--> Self-Assessment (internal team)
+--> Facilitated (consultant-guided)
+--> Third-Party (independent assessment)
|
v
[Gather Documentation]
- Security policies and procedures
- Risk assessments and registers
- Architecture diagrams
- Previous audit results
- Incident reports
- Training records
|
v
[Schedule Assessment Activities]
|
v
End
Workflow 2: Current State Scoring
Start
|
v
[For Each CSF Function (GV, ID, PR, DE, RS, RC)]
|
v
[For Each Category in Function]
|
v
[For Each Subcategory]
|
v
[Evaluate Against Tier Criteria]
|
+--> Tier 1 (Partial)?
| - No formal process
| - Ad hoc practices
| - Limited documentation
|
+--> Tier 2 (Risk-Informed)?
| - Approved by management
| - Inconsistent application
| - Some documentation
|
+--> Tier 3 (Repeatable)?
| - Formal policies
| - Consistent implementation
| - Regular updates
| - Metrics captured
|
+--> Tier 4 (Adaptive)?
- Continuous improvement
- Real-time adaptation
- Advanced automation
- Lessons learned integrated
|
v
[Document Score and Evidence]
|
v
[Record Strengths and Gaps]
|
v
[Calculate Category Average Score]
|
v
[Calculate Function Average Score]
|
v
[Generate Current Profile Heatmap]
|
v
End
Workflow 3: Gap Analysis
Start
|
v
[Define Target Profile]
- Executive input on risk appetite
- Industry benchmark comparison
- Regulatory requirements
- Available resources
|
v
[Compare Current vs Target for Each Subcategory]
Gap = Target Tier - Current Tier
|
v
[Classify Gaps]
|
+--> Critical (Gap >= 2 tiers, high-risk area)
+--> Significant (Gap = 1 tier, high-risk area)
+--> Moderate (Gap = 1 tier, medium-risk area)
+--> Minor (Gap = 1 tier, low-risk area)
+--> None (current meets or exceeds target)
|
v
[Prioritize Based On]
- Risk reduction impact
- Regulatory requirements
- Implementation effort
- Cost and resource availability
- Dependencies on other improvements
|
v
[Generate Prioritized Gap Report]
|
v
End
Workflow 4: Improvement Roadmap
Start
|
v
[Quick Wins (0-3 months)]
- Low effort, high impact
- Policy updates and documentation
- Enable existing but unused capabilities
- Awareness training refresh
|
v
[Medium-Term (3-12 months)]
- Tool deployment and configuration
- Process formalization
- Staff training and certification
- Vendor security programme establishment
|
v
[Long-Term (12-24 months)]
- Architecture redesign
- Advanced automation (SOAR, AI-driven)
- Cultural transformation
- Advanced threat detection capabilities
|
v
[Assign Ownership and Budget]
- Initiative owner for each item
- Resource allocation
- Budget approval
- Success metrics
|
v
[Track Progress Quarterly]
- Milestone reviews
- Reassess maturity scores
- Adjust roadmap as needed
|
v
End
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.