← Back to GRC Projects

PROJECT 03 / CONTROL ASSESSMENT

NIST CSF 2.0 Gap Assessment

A simulated cybersecurity control assessment comparing an organization's current security posture against target outcomes aligned with the NIST Cybersecurity Framework 2.0.

FRAMEWORK NIST CSF 2.0
ASSESSMENT Current vs. Target
FUNCTIONS 6
STATUS Complete

01 / EXECUTIVE SUMMARY

Security posture at a glance.

This assessment evaluates a fictional mid-sized organization against selected cybersecurity outcomes from the NIST Cybersecurity Framework 2.0.

The objective is to identify where cybersecurity practices are operating effectively, where implementation is incomplete, and where additional governance or technical controls are needed.

Each assessed area is assigned a current-state score and a target-state score. The difference between those values represents the identified gap.

Supporting evidence, risk implications, remediation recommendations, ownership, and priority are documented so that findings can be converted into actionable improvement plans.

All organizational information and assessment results in this portfolio project are simulated.

02 / NIST CSF 2.0

Six cybersecurity functions.

CSF 2.0 organizes cybersecurity outcomes around six high-level functions that support cybersecurity risk management across the organization.

GV

Govern

Establish cybersecurity strategy, policies, roles, responsibilities, oversight, and risk expectations.

ID

Identify

Understand assets, business environments, dependencies, vulnerabilities, and cybersecurity risk.

PR

Protect

Implement safeguards such as identity management, access control, training, data protection, and platform security.

DE

Detect

Monitor systems and analyze events to identify potential cybersecurity attacks and compromises.

RS

Respond

Contain, investigate, communicate, analyze, and mitigate detected cybersecurity incidents.

RC

Recover

Restore affected assets and operations while communicating recovery activities appropriately.

03 / METHODOLOGY

Assessment approach.

This portfolio exercise uses a simplified implementation scale to demonstrate current-state and target-state analysis.

0

Not Implemented

The expected cybersecurity practice is not currently established.

1

Initial

Activities occur informally or inconsistently without a repeatable process.

2

Developing

Processes exist but are not fully standardized, documented, or consistently executed.

3

Defined

Processes are documented, repeatable, assigned, and generally implemented.

4

Managed

Processes are measured, monitored, reviewed, and actively managed.

5

Optimized

Processes are continuously improved using metrics, automation, lessons learned, and risk information.

04 / FUNCTION SUMMARY

Current-state overview.

Average simulated current-state scores across the six CSF functions.

Govern 2.1
Identify 2.7
Protect 3.0
Detect 2.8
Respond 2.4
Recover 2.2

05 / GAP ANALYSIS

Current vs. target state.

Representative assessment areas are evaluated for current implementation, target implementation, supporting evidence, identified gaps, and remediation priority.

Function Assessment Area Current Target Gap Evidence Reviewed Priority
Govern Cybersecurity risk strategy and governance 2 4 2 Policies, risk register, governance documentation High
Govern Defined cybersecurity roles and responsibilities 2 4 2 Job roles, policies, responsibility matrix High
Govern Third-party cybersecurity risk management 2 4 2 Vendor questionnaires, contracts, review records High
Identify Hardware and software asset inventory 3 4 1 Asset inventory, discovery records Medium
Identify Cybersecurity risk assessment process 3 4 1 Risk assessments, risk register Medium
Protect Identity and access management 3 4 1 Access lists, MFA configuration, access reviews Medium
Protect Security awareness and training 3 4 1 Training records, phishing simulations Low
Protect Vulnerability and patch management 3 4 1 Scan reports, remediation tickets, patch records Medium
Detect Centralized security monitoring 3 4 1 SIEM sources, alerts, monitoring procedures Medium
Detect Detection coverage validation 2 4 2 Detection rules, testing records, alert metrics High
Respond Incident response plan 3 4 1 IR plan, escalation procedures Medium
Respond Incident response exercises 2 4 2 Tabletop records, lessons learned Medium
Respond Incident communication procedures 2 3 1 Communication plan, contact lists Low
Recover Recovery testing 2 4 2 Backup reports, restoration tests Medium
Recover Lessons learned and recovery improvement 2 3 1 After-action reports, improvement plans Low

06 / SAMPLE FINDING

Governance gap.

GV.RM / SAMPLE ASSESSMENT

Cybersecurity Risk Management Strategy

HIGH PRIORITY
CURRENT STATE

Cybersecurity risks are identified and discussed, but risk criteria, escalation requirements, ownership, and risk tolerance are not consistently documented across the organization.

TARGET STATE

A documented cybersecurity risk management strategy establishes consistent scoring criteria, ownership, escalation requirements, reporting expectations, and risk tolerance.

CURRENT SCORE

2 / Developing

TARGET SCORE

4 / Managed

GAP

2 maturity levels

PRIORITY

High

RECOMMENDED ACTIONS
  • Establish documented cybersecurity risk assessment criteria.
  • Define likelihood and impact scoring standards.
  • Establish organizational cybersecurity risk tolerance and escalation thresholds.
  • Assign accountable risk owners for material cybersecurity risks.
  • Establish a recurring cybersecurity risk reporting process.
  • Define requirements for formal risk acceptance and treatment.
EXPECTED RESULT CONSISTENT RISK GOVERNANCE

Establishing a formal risk management strategy provides a repeatable method for evaluating cybersecurity risks, assigning accountability, escalating significant exposure, and communicating risk to leadership.

07 / REMEDIATION ROADMAP

Prioritized improvement plan.

Gap assessments should result in an actionable roadmap rather than a static list of deficiencies.

0–30 DAYS

Governance Foundation

Define risk owners, establish risk scoring criteria, document governance responsibilities, and identify high-risk vendors.

30–60 DAYS

Control Validation

Validate privileged access, vulnerability remediation, detection coverage, and security evidence.

60–90 DAYS

Incident Readiness

Conduct incident response exercises and document identified lessons learned.

90–120 DAYS

Vendor Risk

Establish vendor risk tiers, recurring assessments, and cybersecurity requirements.

120–180 DAYS

Recovery Validation

Expand backup restoration testing and document recovery objectives and results.

ONGOING

Continuous Improvement

Track metrics, reassess gaps, monitor risk indicators, and update target states.

08 / EVIDENCE

Evidence-driven assessment.

A control should not be considered effective simply because a policy states that it exists. Assessment conclusions should be supported by appropriate evidence.

01 Policies & Procedures

Approved policies, standards, operating procedures, and governance documentation.

02 Technical Evidence

Configuration records, security settings, logs, reports, and system output.

03 Operational Records

Tickets, access reviews, vulnerability remediation, training records, and assessment results.

04 Interviews

Discussions with control owners and stakeholders to understand how processes operate in practice.

09 / GRC TAKEAWAY

What this project demonstrates.

01

Framework Interpretation

Translate cybersecurity framework outcomes into practical assessment questions and evidence requirements.

02

Control Assessment

Evaluate whether cybersecurity processes and controls are implemented and operating.

03

Gap Analysis

Compare current capabilities against a defined target state.

04

Evidence Review

Support assessment conclusions using documentation, technical evidence, records, and interviews.

05

Prioritization

Prioritize remediation according to risk and organizational impact.

06

Communication

Translate technical findings into actionable information for stakeholders and leadership.

PROJECT CONCLUSION

Frameworks become useful when they drive improvement.

This project demonstrates how a cybersecurity framework can be used to assess current capabilities, identify control gaps, evaluate evidence, establish target states, prioritize remediation, and communicate cybersecurity improvement opportunities.