Use Current and Target Profiles to Build a Defensible Roadmap

Build NIST CSF Current and Target Profiles that connect cybersecurity outcomes to business requirements, risk tolerance, resources, and remediation priorities.

Profiles Turn Framework Outcomes Into an Organization-Specific Plan

A Profile selects and prioritizes outcomes according to mission, stakeholders, risk tolerance, obligations, technology, and available resources.

The Current Profile must be evidence-based

The baseline should describe outcomes actually achieved today, including inconsistent operation, exceptions, known weaknesses, and uncertain evidence.

The Target Profile expresses a risk decision

The target is not a wish list. It should show which outcomes matter, why they matter, and what future state leadership is prepared to support.

Profiles Translate the Core Into Your Operating Environment

NIST SP 1301 describes an Organizational Profile as a current and/or target cybersecurity posture expressed using CSF Core outcomes. The Profile is tailored by mission, stakeholder expectations, threats, and requirements. Its value comes from documenting how outcomes relate to real services, risks, practices, goals, and evidence.

Recommended Profile Columns

ColumnPurposeExample
Outcome IDMaintains traceabilityPR.PS-01 — configuration management is established and applied
ScopeShows where the statement appliesMicrosoft 365 and managed Windows endpoints
Current practiceDescribes what actually occursIntune baseline assigned; servers managed separately
EvidenceSupports the current statementPolicy export, assignment report, exception register
StatusSummarizes achievementPartial — unmanaged devices excluded
Target priorityExpresses importanceHigh due to sensitive customer data
Target goalDefines the desired stateApproved baselines cover supported devices with documented exceptions
Owner and dateCreates accountabilityIT Manager; Q4
ValidationDefines proof of completionCoverage report, sample, exception approval, retest

Five Steps From Scope to Action

  1. Prepare

    Define the purpose, scope, stakeholders, sources, risk context, approval, and maintenance process.

  2. Create the Current Profile

    Review practices and evidence. Record inconsistency, exceptions, inherited controls, and uncertainty.

  3. Create the Target Profile

    Select outcomes using mission, threats, requirements, risk tolerance, planned technology, and resources.

  4. Analyze gaps

    Explain business impact, identify treatment options and dependencies, assign owners, and define validation.

  5. Implement and update

    Track action, monitor indicators, reassess risk, and refresh Profiles as conditions change.

Example Profile Row: Privileged Access

Current practice: Six Microsoft 365 administrator accounts have standing roles. MFA is required, but quarterly certification and emergency-account testing are informal.

Evidence: Entra role export, Conditional Access policy, authentication report, and break-glass sign-in logs.

Gap and risk: Standing privilege and incomplete recertification increase the chance that unnecessary or compromised access persists.

Target: Time-bound eligible activation, documented emergency accounts, quarterly certification, alerts, and tested recovery.

Action: Inventory role dependencies, deploy privileged-role controls where licensed, remove unnecessary assignments, establish reviews, and test.

Validation: Role export, activation settings, completed review, emergency-account test, and approved exceptions.

Profile Quality Problems

  • Marking outcomes implemented because a policy or product exists without testing operation and coverage.
  • Using one Profile for unrelated environments with different risks or owners.
  • Creating a Target Profile that ignores risk tolerance, cost, dependencies, or planned change.
  • Assigning priorities without business rationale.
  • Failing to define evidence and validation before remediation.
  • Letting the Profile become stale after projects, incidents, or acquisitions.

Refer to NIST SP 1301 and NIST’s Organizational Profile template.

Develop Profiles That Teams Can Maintain

1. Choose the Profile scope

Define the organization, service, environment, or business process represented.

2. Gather and test evidence

Interview owners and validate policies, settings, logs, records, diagrams, tests, and exceptions.

3. Approve target outcomes

Use business requirements and risk decisions to select the desired state.

4. Convert gaps into work

Assign risk, owner, dependency, due date, evidence, and validation criteria to each material difference.

Use the Profile to Select the Next Kind of Work

A Current and Target Profile identifies differences. The next guide depends on whether the organization needs context for rigor, stronger evidence, or a funded action plan.

When Profile status needs context about operating rigor

Continue to the NIST Implementation Tiers guide when leadership needs to discuss whether practices are partial, risk-informed, repeatable, or adaptive. The guide explains how to choose rigor proportionate to risk without turning Tiers into a score.

When Current Profile claims need stronger support

Use the control-evidence and documentation guide when evidence is missing, stale, poorly indexed, or unable to demonstrate recurring operation. It explains evidence families, quality tests, indexing, and what to do when proof is weak.

When Profile differences are ready to become projects

Use the NIST implementation roadmap to convert gaps into remediation waves with dependencies, owners, milestones, closure evidence, residual-risk decisions, and continuous improvement.

The Compliance Readiness Assessment Wizard provides an initial cross-framework perspective, and the free assessment tools can support technology-specific evidence gathering. Meet Ali Hassani, CISO for the experience behind the assessment approach.

Questions This Page Should Resolve

Does a Profile need every CSF Subcategory?

A Profile should consider relevant outcomes and may be tailored to organizational context, requirements, and risk.

Can an organization maintain several Profiles?

Yes. Different services, business units, technologies, or risk contexts may justify distinct Profiles.

How often should Profiles be updated?

Update them after material business, threat, technology, regulatory, contractual, or incident-driven changes and on an established review cycle.

NIST CSF Guidance Led by Ali Hassani, CISO

Ali Hassani brings 25+ years of IT, cybersecurity, compliance, Microsoft infrastructure, cloud, network, firewall, vulnerability-management, and operational experience. OC Security Audit can work with leadership, internal IT, and MSP teams to assess NIST CSF alignment and build a practical roadmap.

When findings require technical implementation or ongoing IT operations, IT Perfection can support relevant Microsoft 365, Azure, endpoint, backup, server, network, monitoring, patching, and managed IT work.