The Current Profile must be evidence-based
The baseline should describe outcomes actually achieved today, including inconsistent operation, exceptions, known weaknesses, and uncertain evidence.
Build NIST CSF Current and Target Profiles that connect cybersecurity outcomes to business requirements, risk tolerance, resources, and remediation priorities.
A Profile selects and prioritizes outcomes according to mission, stakeholders, risk tolerance, obligations, technology, and available resources.
The baseline should describe outcomes actually achieved today, including inconsistent operation, exceptions, known weaknesses, and uncertain evidence.
The target is not a wish list. It should show which outcomes matter, why they matter, and what future state leadership is prepared to support.
NIST SP 1301 describes an Organizational Profile as a current and/or target cybersecurity posture expressed using CSF Core outcomes. The Profile is tailored by mission, stakeholder expectations, threats, and requirements. Its value comes from documenting how outcomes relate to real services, risks, practices, goals, and evidence.
| Column | Purpose | Example |
|---|---|---|
| Outcome ID | Maintains traceability | PR.PS-01 — configuration management is established and applied |
| Scope | Shows where the statement applies | Microsoft 365 and managed Windows endpoints |
| Current practice | Describes what actually occurs | Intune baseline assigned; servers managed separately |
| Evidence | Supports the current statement | Policy export, assignment report, exception register |
| Status | Summarizes achievement | Partial — unmanaged devices excluded |
| Target priority | Expresses importance | High due to sensitive customer data |
| Target goal | Defines the desired state | Approved baselines cover supported devices with documented exceptions |
| Owner and date | Creates accountability | IT Manager; Q4 |
| Validation | Defines proof of completion | Coverage report, sample, exception approval, retest |
Define the purpose, scope, stakeholders, sources, risk context, approval, and maintenance process.
Review practices and evidence. Record inconsistency, exceptions, inherited controls, and uncertainty.
Select outcomes using mission, threats, requirements, risk tolerance, planned technology, and resources.
Explain business impact, identify treatment options and dependencies, assign owners, and define validation.
Track action, monitor indicators, reassess risk, and refresh Profiles as conditions change.
Current practice: Six Microsoft 365 administrator accounts have standing roles. MFA is required, but quarterly certification and emergency-account testing are informal.
Evidence: Entra role export, Conditional Access policy, authentication report, and break-glass sign-in logs.
Gap and risk: Standing privilege and incomplete recertification increase the chance that unnecessary or compromised access persists.
Target: Time-bound eligible activation, documented emergency accounts, quarterly certification, alerts, and tested recovery.
Action: Inventory role dependencies, deploy privileged-role controls where licensed, remove unnecessary assignments, establish reviews, and test.
Validation: Role export, activation settings, completed review, emergency-account test, and approved exceptions.
Refer to NIST SP 1301 and NIST’s Organizational Profile template.
Define the organization, service, environment, or business process represented.
Interview owners and validate policies, settings, logs, records, diagrams, tests, and exceptions.
Use business requirements and risk decisions to select the desired state.
Assign risk, owner, dependency, due date, evidence, and validation criteria to each material difference.
A Current and Target Profile identifies differences. The next guide depends on whether the organization needs context for rigor, stronger evidence, or a funded action plan.
Continue to the NIST Implementation Tiers guide when leadership needs to discuss whether practices are partial, risk-informed, repeatable, or adaptive. The guide explains how to choose rigor proportionate to risk without turning Tiers into a score.
Use the control-evidence and documentation guide when evidence is missing, stale, poorly indexed, or unable to demonstrate recurring operation. It explains evidence families, quality tests, indexing, and what to do when proof is weak.
Use the NIST implementation roadmap to convert gaps into remediation waves with dependencies, owners, milestones, closure evidence, residual-risk decisions, and continuous improvement.
The Compliance Readiness Assessment Wizard provides an initial cross-framework perspective, and the free assessment tools can support technology-specific evidence gathering. Meet Ali Hassani, CISO for the experience behind the assessment approach.
A Profile should consider relevant outcomes and may be tailored to organizational context, requirements, and risk.
Yes. Different services, business units, technologies, or risk contexts may justify distinct Profiles.
Update them after material business, threat, technology, regulatory, contractual, or incident-driven changes and on an established review cycle.
Ali Hassani brings 25+ years of IT, cybersecurity, compliance, Microsoft infrastructure, cloud, network, firewall, vulnerability-management, and operational experience. OC Security Audit can work with leadership, internal IT, and MSP teams to assess NIST CSF alignment and build a practical roadmap.
When findings require technical implementation or ongoing IT operations, IT Perfection can support relevant Microsoft 365, Azure, endpoint, backup, server, network, monitoring, patching, and managed IT work.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.