CSF 2.0 Organizational Profile: Current vs Target and gap analysis
An Organizational Profile is how CSF 2.0 turns its outcomes into a plan specific to your organization. The assistant walks you through the five-step process from NIST SP 1301 and the CSF itself, from scoping to updating the profile.
Posez votre question
Compte gratuit requisLes réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.
The five-step profile process
The CSF describes five steps: scope the Organizational Profile, gather the information needed, create the profile, analyze the gaps between the Current and Target Profiles and create an action plan, then implement the plan and update the profile.
The scope records the high-level facts and assumptions behind the profile. You can have as many profiles as you like: one for the whole organization, one for financial systems, or one focused on ransomware affecting those systems. Scope can also follow technology (IT, OT), data types or users.
Current Profile, Target Profile and the action plan
A Current Profile shows which Core outcomes you achieve today and to what extent. A Target Profile lists the outcomes you have selected and prioritized, taking into account expected changes such as new requirements, new technology or threat trends.
The gap analysis compares current practices, across people, process and technology, with the CSF outcome descriptions, Informative References and Implementation Examples. The action plan then lists pending improvements, each with an action, priority, owner, deadline and resources.
NIST provides an Organizational Profile template as a spreadsheet on the CSF 2.0 website for side-by-side comparison of Current and Target Profiles.
Questions fréquentes
What is a Community Profile?
It is a baseline of CSF outcomes published for organizations that share interests, typically a sector, a technology or a threat type. You can copy it into your Organizational Profile as the basis of your Target Profile and adjust priorities or add your own Subcategories and guidance.
What are the four CSF Tiers?
Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3) and Adaptive (Tier 4). They describe how rigorous your risk governance and management practices are, from informal and ad hoc to agile and continuously improving.
Must every organization aim for Tier 4?
No. The CSF encourages moving to a higher Tier when risks or mandates are greater, or when a cost-benefit analysis shows a feasible and cost-effective reduction of risk. Tiers should complement your risk management methodology, not replace it.
Intégrer / API / MCP
Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.
MCP pour vos agents
Adresse du serveur MCP de cette base (outils ask_base et search_base) :
https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurityClaude Code, Cursor et autres clients
claude mcp add --transport http kopik-nist-csf-2-small-business-cybersecurity "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-nist-csf-2-small-business-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}API REST pour vos applications
mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.
curl -X POST https://kopik.io/api/v1/bases/nist-csf-2-small-business-cybersecurity/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Votre question ici", "mode": "answer"}'Pour commencer
- Créez une clé dans votre tableau de bord et rechargez votre crédit.
- Remplacez
kpk_…par votre clé. - Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.