April 16, 2018
Cybersecurity Framework
Version 1.1
Subcategories to account for unique organizational risks. The organization may also consider
influences and requirements of external stakeholders such as sector entities, customers, and
business partners when creating a Target Profile. The Target Profile should appropriately reflect
criteria within the target Implementation Tier.
Step 6: Determine, Analyze, and Prioritize Gaps. The organization compares the Current
Profile and the Target Profile to determine gaps. Next, it creates a prioritized action plan to
address gaps – reflecting mission drivers, costs and benefits, and risks – to achieve the outcomes
in the Target Profile. The organization then determines resources, including funding and
workforce, necessary to address the gaps. Using Profiles in this manner encourages the
organization to make informed decisions about cybersecurity activities, supports risk
management, and enables the organization to perform cost-effective, targeted improvements.
Step 7: Implement Action Plan. The organization determines which actions to take to address
the gaps, if any, identified in the previous step and then adjusts its current cybersecurity practices
in order to achieve the Target Profile. For further guidance, the Framework identifies example
Informative References regarding the Categories and Subcategories, but organizations should
determine which standards, guidelines, and practices, including those that are sector specific,
work best for their needs.
An organization repeats the steps as needed to continuously assess and improve its cybersecurity.
For instance, organizations may find that more frequent repetition of the orient step improves the
quality of risk assessments. Furthermore, organizations may monitor progress through iterative
updates to the Current Profile, subsequently comparing the Current Profile to the Target Profile.
Organizations may also use this process to align their cybersecurity program with their desired
Framework Implementation Tier.
3.3
Communicating Cybersecurity Requirements with Stakeholders
The Framework provides a common language to communicate requirements among
interdependent stakeholders responsible for the delivery of essential critical infrastructure
products and services. Examples include:
An organization may use a Target Profile to express cybersecurity risk management
requirements to an external service provider (e.g., a cloud provider to which it is
exporting data).
An organization may express its cybersecurity state through a Current Profile to report
results or to compare with acquisition requirements.
A critical infrastructure owner/operator, having identified an external partner on whom
that infrastructure depends, may use a Target Profile to convey required Categories and
Subcategories.
A critical infrastructure sector may establish a Target Profile that can be used among its
constituents as an initial baseline Profile to build their tailored Target Profiles.
An organization can better manage cybersecurity risk among stakeholders by assessing
their position in the critical infrastructure and the broader digital economy using
Implementation Tiers.
Communication is especially important among stakeholders up and down supply chains. Supply
chains are complex, globally distributed, and interconnected sets of resources and processes
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
15