From the course: NIST Cybersecurity Framework (CSF) 2.0 Primer: From Fundamentals to Implementation by Pearson

Unlock this course with a free trial

Join today to access over 25,200 courses taught by industry experts.

Key takeaways

Key takeaways

All right, let's just do a quick review of our key takeaways from this lesson. Specifically we'll talk about profiles, tiers, and then some related frameworks, specifically two related frameworks and standards to wrap up this lesson. So first off, profiles. we usually use them as kind of a tool for gap analysis and self-evaluation and determining where we wanna go. So it's very, very common with the use of profiles to create a current profile, which represents the current state of the organization. That's like a set of columns in an Excel spreadsheet. And then to the right of that, we have a target profile, which is an analogous set of columns, except it has our future desired state, like where we would like to be with respect to all these cybersecurity risk management outcomes. That's usually how profiles are used, but there are some other types of profiles. For instance, there's community profiles, and you might use them in the same way, you probably will, but these are published by…

Contents