Govern
Establish cybersecurity strategy, policies, roles, responsibilities, oversight, and risk expectations.
PROJECT 03 / CONTROL ASSESSMENT
A simulated cybersecurity control assessment comparing an organization's current security posture against target outcomes aligned with the NIST Cybersecurity Framework 2.0.
01 / EXECUTIVE SUMMARY
This assessment evaluates a fictional mid-sized organization against selected cybersecurity outcomes from the NIST Cybersecurity Framework 2.0.
The objective is to identify where cybersecurity practices are operating effectively, where implementation is incomplete, and where additional governance or technical controls are needed.
Each assessed area is assigned a current-state score and a target-state score. The difference between those values represents the identified gap.
Supporting evidence, risk implications, remediation recommendations, ownership, and priority are documented so that findings can be converted into actionable improvement plans.
All organizational information and assessment results in this portfolio project are simulated.
02 / NIST CSF 2.0
CSF 2.0 organizes cybersecurity outcomes around six high-level functions that support cybersecurity risk management across the organization.
Establish cybersecurity strategy, policies, roles, responsibilities, oversight, and risk expectations.
Understand assets, business environments, dependencies, vulnerabilities, and cybersecurity risk.
Implement safeguards such as identity management, access control, training, data protection, and platform security.
Monitor systems and analyze events to identify potential cybersecurity attacks and compromises.
Contain, investigate, communicate, analyze, and mitigate detected cybersecurity incidents.
Restore affected assets and operations while communicating recovery activities appropriately.
03 / METHODOLOGY
This portfolio exercise uses a simplified implementation scale to demonstrate current-state and target-state analysis.
The expected cybersecurity practice is not currently established.
Activities occur informally or inconsistently without a repeatable process.
Processes exist but are not fully standardized, documented, or consistently executed.
Processes are documented, repeatable, assigned, and generally implemented.
Processes are measured, monitored, reviewed, and actively managed.
Processes are continuously improved using metrics, automation, lessons learned, and risk information.
04 / FUNCTION SUMMARY
Average simulated current-state scores across the six CSF functions.
05 / GAP ANALYSIS
Representative assessment areas are evaluated for current implementation, target implementation, supporting evidence, identified gaps, and remediation priority.
| Function | Assessment Area | Current | Target | Gap | Evidence Reviewed | Priority |
|---|---|---|---|---|---|---|
| Govern | Cybersecurity risk strategy and governance | 2 | 4 | 2 | Policies, risk register, governance documentation | High |
| Govern | Defined cybersecurity roles and responsibilities | 2 | 4 | 2 | Job roles, policies, responsibility matrix | High |
| Govern | Third-party cybersecurity risk management | 2 | 4 | 2 | Vendor questionnaires, contracts, review records | High |
| Identify | Hardware and software asset inventory | 3 | 4 | 1 | Asset inventory, discovery records | Medium |
| Identify | Cybersecurity risk assessment process | 3 | 4 | 1 | Risk assessments, risk register | Medium |
| Protect | Identity and access management | 3 | 4 | 1 | Access lists, MFA configuration, access reviews | Medium |
| Protect | Security awareness and training | 3 | 4 | 1 | Training records, phishing simulations | Low |
| Protect | Vulnerability and patch management | 3 | 4 | 1 | Scan reports, remediation tickets, patch records | Medium |
| Detect | Centralized security monitoring | 3 | 4 | 1 | SIEM sources, alerts, monitoring procedures | Medium |
| Detect | Detection coverage validation | 2 | 4 | 2 | Detection rules, testing records, alert metrics | High |
| Respond | Incident response plan | 3 | 4 | 1 | IR plan, escalation procedures | Medium |
| Respond | Incident response exercises | 2 | 4 | 2 | Tabletop records, lessons learned | Medium |
| Respond | Incident communication procedures | 2 | 3 | 1 | Communication plan, contact lists | Low |
| Recover | Recovery testing | 2 | 4 | 2 | Backup reports, restoration tests | Medium |
| Recover | Lessons learned and recovery improvement | 2 | 3 | 1 | After-action reports, improvement plans | Low |
06 / SAMPLE FINDING
Cybersecurity risks are identified and discussed, but risk criteria, escalation requirements, ownership, and risk tolerance are not consistently documented across the organization.
A documented cybersecurity risk management strategy establishes consistent scoring criteria, ownership, escalation requirements, reporting expectations, and risk tolerance.
2 / Developing
4 / Managed
2 maturity levels
High
Establishing a formal risk management strategy provides a repeatable method for evaluating cybersecurity risks, assigning accountability, escalating significant exposure, and communicating risk to leadership.
07 / REMEDIATION ROADMAP
Gap assessments should result in an actionable roadmap rather than a static list of deficiencies.
Define risk owners, establish risk scoring criteria, document governance responsibilities, and identify high-risk vendors.
Validate privileged access, vulnerability remediation, detection coverage, and security evidence.
Conduct incident response exercises and document identified lessons learned.
Establish vendor risk tiers, recurring assessments, and cybersecurity requirements.
Expand backup restoration testing and document recovery objectives and results.
Track metrics, reassess gaps, monitor risk indicators, and update target states.
08 / EVIDENCE
A control should not be considered effective simply because a policy states that it exists. Assessment conclusions should be supported by appropriate evidence.
Approved policies, standards, operating procedures, and governance documentation.
Configuration records, security settings, logs, reports, and system output.
Tickets, access reviews, vulnerability remediation, training records, and assessment results.
Discussions with control owners and stakeholders to understand how processes operate in practice.
09 / GRC TAKEAWAY
Translate cybersecurity framework outcomes into practical assessment questions and evidence requirements.
Evaluate whether cybersecurity processes and controls are implemented and operating.
Compare current capabilities against a defined target state.
Support assessment conclusions using documentation, technical evidence, records, and interviews.
Prioritize remediation according to risk and organizational impact.
Translate technical findings into actionable information for stakeholders and leadership.
PROJECT CONCLUSION
This project demonstrates how a cybersecurity framework can be used to assess current capabilities, identify control gaps, evaluate evidence, establish target states, prioritize remediation, and communicate cybersecurity improvement opportunities.