Outcome-Based Cybersecurity Risk Management
Navigate the complete NIST CSF 2.0 Core.
Move from six high-level Functions to 22 Categories and 106 specific Subcategory outcomes. Each profile preserves the official NIST outcome and adds original Bare Metal Cyber guidance for implementation, evidence, Profiles, and common failure modes.
Choose a Function
Begin with the risk question you need to answer.
The Functions operate together. Use them as concurrent lenses, not a fixed sequence or a maturity ladder.
Govern
The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
Identify
The organization’s current cybersecurity risks are understood.
Protect
Safeguards to manage the organization’s cybersecurity risks are used.
Detect
Possible cybersecurity attacks and compromises are found and analyzed.
Respond
Actions regarding a detected cybersecurity incident are taken.
Recover
Assets and operations affected by a cybersecurity incident are restored.
Complete Core Directory
Find an outcome by ID, name, or plain-language subject.
Search the entire hierarchy or narrow the directory to one Function.
GVGovernThe organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
The circumstances — mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements — surrounding the organization’s cybersecurity risk management decisions are understood.
The organizational mission is understood and informs cybersecurity risk management
Open outcome profile →GV.OC-02Stakeholder Needs and ExpectationsInternal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood
Open outcome profile →GV.OC-03Legal, Regulatory, and Contractual RequirementsLegal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
Open outcome profile →GV.OC-04External Stakeholder DependenciesCritical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
Open outcome profile →GV.OC-05Organizational DependenciesOutcomes, capabilities, and services that the organization depends on are understood and communicated
Open outcome profile →The organization’s priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions.
Risk management objectives are established and agreed to by organizational stakeholders
Open outcome profile →GV.RM-02Risk Appetite and ToleranceRisk appetite and risk tolerance statements are established, communicated, and maintained
Open outcome profile →GV.RM-03Cybersecurity in Enterprise Risk ManagementCybersecurity risk management activities and outcomes are included in enterprise risk management processes
Open outcome profile →GV.RM-04Strategic Risk Response DirectionStrategic direction that describes appropriate risk response options is established and communicated
Open outcome profile →GV.RM-05Cybersecurity Risk CommunicationLines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
Open outcome profile →GV.RM-06Standardized Risk MethodA standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Open outcome profile →GV.RM-07Strategic OpportunitiesStrategic opportunities — positive risks — are characterized and are included in organizational cybersecurity risk discussions
Open outcome profile →Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated.
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Open outcome profile →GV.RR-02Roles, Responsibilities, and AuthoritiesRoles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Open outcome profile →GV.RR-03Risk-Commensurate ResourcesAdequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
Open outcome profile →GV.RR-04Cybersecurity in Human ResourcesCybersecurity is included in human resources practices
Open outcome profile →Policy
Organizational cybersecurity policy is established, communicated, and enforced.
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Open outcome profile →GV.PO-02Review and Update Cybersecurity PolicyPolicy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
Open outcome profile →Oversight
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy.
Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
Open outcome profile →GV.OV-02Adjust Strategy CoverageThe cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
Open outcome profile →GV.OV-03Evaluate Cybersecurity PerformanceOrganizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
Open outcome profile →Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders.
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Open outcome profile →GV.SC-02Supply Chain Roles and ResponsibilitiesCybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
Open outcome profile →GV.SC-03Integrate C-SCRM with Risk ManagementCybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
Open outcome profile →GV.SC-04Prioritize Suppliers by CriticalitySuppliers are known and prioritized by criticality
Open outcome profile →GV.SC-05Supply Chain Requirements in AgreementsRequirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Open outcome profile →GV.SC-06Supplier Due DiligencePlanning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
Open outcome profile →GV.SC-07Monitor Supplier and Third-Party RiskThe risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
Open outcome profile →GV.SC-08Include Suppliers in Incident ActivitiesRelevant suppliers and other third parties are included in incident planning, response, and recovery activities
Open outcome profile →GV.SC-09Life-Cycle Supply Chain SecuritySupply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
Open outcome profile →GV.SC-10Post-Relationship Supply Chain ProvisionsCybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
Open outcome profile →IDIdentifyThe organization’s current cybersecurity risks are understood.
Asset Management
Assets — data, hardware, software, systems, facilities, services, and people — that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization’s risk strategy.
Inventories of hardware managed by the organization are maintained
Open outcome profile →ID.AM-02Software, Service, and System InventoriesInventories of software, services, and systems managed by the organization are maintained
Open outcome profile →ID.AM-03Network Communication and Data Flow RepresentationsRepresentations of the organization’s authorized network communication and internal and external network data flows are maintained
Open outcome profile →ID.AM-04Supplier-Provided Service InventoriesInventories of services provided by suppliers are maintained
Open outcome profile →ID.AM-05Asset PrioritizationAssets are prioritized based on classification, criticality, resources, and impact on the mission
Open outcome profile →ID.AM-07Data and Metadata InventoriesInventories of data and corresponding metadata for designated data types are maintained
Open outcome profile →ID.AM-08Asset Life-Cycle ManagementSystems, hardware, software, services, and data are managed throughout their life cycles
Open outcome profile →Risk Assessment
The cybersecurity risk to the organization, assets, and individuals is understood by the organization.
Vulnerabilities in assets are identified, validated, and recorded
Open outcome profile →ID.RA-02Receive Cyber Threat IntelligenceCyber threat intelligence is received from information sharing forums and sources
Open outcome profile →ID.RA-03Identify Internal and External ThreatsInternal and external threats to the organization are identified and recorded
Open outcome profile →ID.RA-04Estimate Threat Likelihood and ImpactPotential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
Open outcome profile →ID.RA-05Understand Inherent RiskThreats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Open outcome profile →ID.RA-06Select and Track Risk ResponsesRisk responses are chosen, prioritized, planned, tracked, and communicated
Open outcome profile →ID.RA-07Manage Changes and ExceptionsChanges and exceptions are managed, assessed for risk impact, recorded, and tracked
Open outcome profile →ID.RA-08Vulnerability Disclosure ProcessesProcesses are established for receiving, analyzing, and responding to vulnerability disclosures
Open outcome profile →ID.RA-09Assess Hardware and Software AuthenticityThe authenticity and integrity of hardware and software are assessed prior to acquisition and use
Open outcome profile →ID.RA-10Assess Critical Suppliers Before AcquisitionCritical suppliers are assessed prior to acquisition
Open outcome profile →Improvement
Improvements to organizational cybersecurity risk management processes, procedures, and activities are identified across all CSF Functions.
Improvements are identified from evaluations
Open outcome profile →ID.IM-02Improvements from Tests and ExercisesImprovements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Open outcome profile →ID.IM-03Improvements from OperationsImprovements are identified from execution of operational processes, procedures, and activities
Open outcome profile →ID.IM-04Improve Incident Response and Cybersecurity PlansIncident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
Open outcome profile →PRProtectSafeguards to manage the organization’s cybersecurity risks are used.
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access.
Identities and credentials for authorized users, services, and hardware are managed by the organization
Open outcome profile →PR.AA-02Identity Proofing and Credential BindingIdentities are proofed and bound to credentials based on the context of interactions
Open outcome profile →PR.AA-03Authenticate Users, Services, and HardwareUsers, services, and hardware are authenticated
Open outcome profile →PR.AA-04Protect and Verify Identity AssertionsIdentity assertions are protected, conveyed, and verified
Open outcome profile →PR.AA-05Manage Permissions and AuthorizationsAccess permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Open outcome profile →PR.AA-06Risk-Based Physical AccessPhysical access to assets is managed, monitored, and enforced commensurate with risk
Open outcome profile →The organization’s personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks.
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Open outcome profile →PR.AT-02Specialized Role TrainingIndividuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
Open outcome profile →Data Security
Data are managed consistent with the organization’s risk strategy to protect the confidentiality, integrity, and availability of information.
The confidentiality, integrity, and availability of data-at-rest are protected
Open outcome profile →PR.DS-02Protect Data in TransitThe confidentiality, integrity, and availability of data-in-transit are protected
Open outcome profile →PR.DS-10Protect Data in UseThe confidentiality, integrity, and availability of data-in-use are protected
Open outcome profile →PR.DS-11Create, Protect, Maintain, and Test BackupsBackups of data are created, protected, maintained, and tested
Open outcome profile →Platform Security
The hardware, software, and services of physical and virtual platforms are managed consistent with the organization’s risk strategy to protect their confidentiality, integrity, and availability.
Configuration management practices are established and applied
Open outcome profile →PR.PS-02Software Maintenance and RemovalSoftware is maintained, replaced, and removed commensurate with risk
Open outcome profile →PR.PS-03Hardware Maintenance and RemovalHardware is maintained, replaced, and removed commensurate with risk
Open outcome profile →PR.PS-04Generate and Provide Log RecordsLog records are generated and made available for continuous monitoring
Open outcome profile →PR.PS-05Prevent Unauthorized SoftwareInstallation and execution of unauthorized software are prevented
Open outcome profile →PR.PS-06Secure Software DevelopmentSecure software development practices are integrated, and their performance is monitored throughout the software development life cycle
Open outcome profile →Security architectures are managed with the organization’s risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience.
Networks and environments are protected from unauthorized logical access and usage
Open outcome profile →PR.IR-02Protect Technology from Environmental ThreatsThe organization’s technology assets are protected from environmental threats
Open outcome profile →PR.IR-03Resilience MechanismsMechanisms are implemented to achieve resilience requirements in normal and adverse situations
Open outcome profile →PR.IR-04Maintain Resource CapacityAdequate resource capacity to ensure availability is maintained
Open outcome profile →DEDetectPossible cybersecurity attacks and compromises are found and analyzed.
Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events.
Networks and network services are monitored to find potentially adverse events
Open outcome profile →DE.CM-02Monitor the Physical EnvironmentThe physical environment is monitored to find potentially adverse events
Open outcome profile →DE.CM-03Monitor Personnel Activity and Technology UsePersonnel activity and technology usage are monitored to find potentially adverse events
Open outcome profile →DE.CM-06Monitor External Service ProvidersExternal service provider activities and services are monitored to find potentially adverse events
Open outcome profile →DE.CM-09Monitor Computing and Runtime EnvironmentsComputing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Open outcome profile →Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents.
Potentially adverse events are analyzed to better understand associated activities
Open outcome profile →DE.AE-03Correlate Information from Multiple SourcesInformation is correlated from multiple sources
Open outcome profile →DE.AE-04Understand Event Impact and ScopeThe estimated impact and scope of adverse events are understood
Open outcome profile →DE.AE-06Provide Event Information to Authorized Staff and ToolsInformation on adverse events is provided to authorized staff and tools
Open outcome profile →DE.AE-07Integrate Threat Intelligence and ContextCyber threat intelligence and other contextual information are integrated into the analysis
Open outcome profile →DE.AE-08Declare Incidents Using Defined CriteriaIncidents are declared when adverse events meet the defined incident criteria
Open outcome profile →RSRespondActions regarding a detected cybersecurity incident are taken.
Incident Management
Responses to detected cybersecurity incidents are managed.
The incident response plan is executed in coordination with relevant third parties once an incident is declared
Open outcome profile →RS.MA-02Triage and Validate Incident ReportsIncident reports are triaged and validated
Open outcome profile →RS.MA-03Categorize and Prioritize IncidentsIncidents are categorized and prioritized
Open outcome profile →RS.MA-04Escalate or Elevate IncidentsIncidents are escalated or elevated as needed
Open outcome profile →RS.MA-05Apply Recovery Initiation CriteriaThe criteria for initiating incident recovery are applied
Open outcome profile →Incident Analysis
Investigations are conducted to ensure effective response and support forensics and recovery activities.
Analysis is performed to establish what has taken place during an incident and the root cause of the incident
Open outcome profile →RS.AN-06Preserve Investigation Action RecordsActions performed during an investigation are recorded, and the records’ integrity and provenance are preserved
Open outcome profile →RS.AN-07Preserve Incident Data and MetadataIncident data and metadata are collected, and their integrity and provenance are preserved
Open outcome profile →RS.AN-08Estimate and Validate Incident MagnitudeAn incident’s magnitude is estimated and validated
Open outcome profile →Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies.
Incident Mitigation
Activities are performed to prevent expansion of an event and mitigate its effects.
RCRecoverAssets and operations affected by a cybersecurity incident are restored.
Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents.
The recovery portion of the incident response plan is executed once initiated from the incident response process
Open outcome profile →RC.RP-02Select and Perform Recovery ActionsRecovery actions are selected, scoped, prioritized, and performed
Open outcome profile →RC.RP-03Verify Backups and Restoration AssetsThe integrity of backups and other restoration assets is verified before using them for restoration
Open outcome profile →RC.RP-04Establish Post-Incident Operational NormsCritical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
Open outcome profile →RC.RP-05Verify Restored Assets and Normal OperationsThe integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
Open outcome profile →RC.RP-06Declare the End of RecoveryThe end of incident recovery is declared based on criteria, and incident-related documentation is completed
Open outcome profile →Restoration activities are coordinated with internal and external parties.
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
Open outcome profile →RC.CO-04Share Public Recovery UpdatesPublic updates on incident recovery are shared using approved methods and messaging
Open outcome profile →No CSF Core outcomes matched that search.
Put the Core to Work
Turn outcomes into a Current Profile, a Target Profile, and an owned improvement plan.
Use the companion planner to document evidence, priorities, owners, gaps, and status for each Subcategory without changing NIST’s outcome language.