Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

Outcome-Based Cybersecurity Risk Management

Navigate the complete NIST CSF 2.0 Core.

Move from six high-level Functions to 22 Categories and 106 specific Subcategory outcomes. Each profile preserves the official NIST outcome and adds original Bare Metal Cyber guidance for implementation, evidence, Profiles, and common failure modes.

Choose a Function

Begin with the risk question you need to answer.

The Functions operate together. Use them as concurrent lenses, not a fixed sequence or a maturity ladder.

Complete Core Directory

Find an outcome by ID, name, or plain-language subject.

Search the entire hierarchy or narrow the directory to one Function.

GVGovernThe organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.

The circumstances — mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements — surrounding the organization’s cybersecurity risk management decisions are understood.

The organization’s priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions.

Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated.

GV.PO

Policy

Organizational cybersecurity policy is established, communicated, and enforced.

Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy.

Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders.

GV.SC-01C-SCRM Program and Strategy

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

Open outcome profile →
GV.SC-02Supply Chain Roles and Responsibilities

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally

Open outcome profile →
GV.SC-03Integrate C-SCRM with Risk Management

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

Open outcome profile →
GV.SC-04Prioritize Suppliers by Criticality

Suppliers are known and prioritized by criticality

Open outcome profile →
GV.SC-05Supply Chain Requirements in Agreements

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

Open outcome profile →
GV.SC-06Supplier Due Diligence

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

Open outcome profile →
GV.SC-07Monitor Supplier and Third-Party Risk

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

Open outcome profile →
GV.SC-08Include Suppliers in Incident Activities

Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

Open outcome profile →
GV.SC-09Life-Cycle Supply Chain Security

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

Open outcome profile →
GV.SC-10Post-Relationship Supply Chain Provisions

Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

Open outcome profile →
IDIdentifyThe organization’s current cybersecurity risks are understood.

Assets — data, hardware, software, systems, facilities, services, and people — that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization’s risk strategy.

The cybersecurity risk to the organization, assets, and individuals is understood by the organization.

ID.RA-01Identify and Record Vulnerabilities

Vulnerabilities in assets are identified, validated, and recorded

Open outcome profile →
ID.RA-02Receive Cyber Threat Intelligence

Cyber threat intelligence is received from information sharing forums and sources

Open outcome profile →
ID.RA-03Identify Internal and External Threats

Internal and external threats to the organization are identified and recorded

Open outcome profile →
ID.RA-04Estimate Threat Likelihood and Impact

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

Open outcome profile →
ID.RA-05Understand Inherent Risk

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

Open outcome profile →
ID.RA-06Select and Track Risk Responses

Risk responses are chosen, prioritized, planned, tracked, and communicated

Open outcome profile →
ID.RA-07Manage Changes and Exceptions

Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

Open outcome profile →
ID.RA-08Vulnerability Disclosure Processes

Processes are established for receiving, analyzing, and responding to vulnerability disclosures

Open outcome profile →
ID.RA-09Assess Hardware and Software Authenticity

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

Open outcome profile →
ID.RA-10Assess Critical Suppliers Before Acquisition

Critical suppliers are assessed prior to acquisition

Open outcome profile →

Improvements to organizational cybersecurity risk management processes, procedures, and activities are identified across all CSF Functions.

PRProtectSafeguards to manage the organization’s cybersecurity risks are used.

Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access.

The organization’s personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks.

Data are managed consistent with the organization’s risk strategy to protect the confidentiality, integrity, and availability of information.

The hardware, software, and services of physical and virtual platforms are managed consistent with the organization’s risk strategy to protect their confidentiality, integrity, and availability.

Security architectures are managed with the organization’s risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience.

DEDetectPossible cybersecurity attacks and compromises are found and analyzed.

Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events.

Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents.

RSRespondActions regarding a detected cybersecurity incident are taken.

Responses to detected cybersecurity incidents are managed.

Investigations are conducted to ensure effective response and support forensics and recovery activities.

Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies.

Activities are performed to prevent expansion of an event and mitigate its effects.

RCRecoverAssets and operations affected by a cybersecurity incident are restored.

Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents.

Restoration activities are coordinated with internal and external parties.

Put the Core to Work

Turn outcomes into a Current Profile, a Target Profile, and an owned improvement plan.

Use the companion planner to document evidence, priorities, owners, gaps, and status for each Subcategory without changing NIST’s outcome language.

Start with Govern →