Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Cybersecurity

NIST Cybersecurity Framework profiles for a real target.

F Creative Studio 360 maps how organisations in any country manage cyber risk today, then writes the gap to the target they have chosen.

A framework only helps if the target is yours.

The work follows the NIST Cybersecurity Framework, including the Govern function in CSF 2.0. Where risk needs to be written as likelihood and impact, the method can use NIST SP 800-30.

F Creative Studio 360 does not claim the organisation is certified to the framework, or to ISO/IEC 27001.

A common language, not a certificate
The NIST Cybersecurity Framework gives a board and a technical team the same words for risk. Alignment with it is not a certification, and F Creative Studio 360 does not issue one.
Current profile, then a target
The useful comparison is what you do today against what the organisation has decided it needs. A long list of categories, with no target, does not change a decision.
It travels
The framework was published in the United States and is used by organisations in any country. A local rule is added only when that organisation is actually subject to it.
This is not a penetration test
The work reads how the programme is run. Systems are not attacked. Authorised testing is a separate engagement, and only when it is written into scope.

The six functions

Each function is described for the organisation in front of you. The same map works in any country. The obligations inside it change with where you are governed.

Govern
Who decides, what risk is accepted, and how the programme is overseen. This is the function added in CSF 2.0.
Identify
The assets, suppliers and risks the organisation needs to see before it can protect them.
Protect
The safeguards that keep a critical service running: access, data, training and the controls around change.
Detect
How the organisation notices that something has happened, and how it tells a real event from noise.
Respond
What happens after detection: who is told, what is contained, and who speaks for the organisation.
Recover
How a service is restored, and what is written down so the same gap is not met twice.

How a profile is built

The same shape works on site or remotely, including when the systems sit in more than one country.

  1. 1

    Set the scope

    Which entities, which countries, and which systems the profile will cover.

  2. 2

    Write the current profile

    Map what is already in place to the functions and categories in scope.

  3. 3

    Name the risk

    Use NIST SP 800-30 where the organisation wants likelihood and impact written that way.

  4. 4

    Agree the target

    The outcomes the organisation actually wants. The target is a decision, not a slogan.

  5. 5

    Hand back the gaps

    What sits between the two profiles, in an order a leadership team can fund. Implementation stays with your team unless it is written in separately.

What you receive

  • A current profile mapped to the functions in scope.
  • A target profile the organisation has agreed.
  • A risk note, when that was in scope.
  • A prioritised gap list between the two profiles.
  • A record of what was reviewed, without a claim that you comply.

Rules that can sit beside it

Examples include PCI DSS, GDPR and the HIPAA Security Rule. For an organisation that is actually subject to them, the profile can also note CPS 234 and the Essential Eight. Naming a rule is not a statement that you comply with it.

Common questions

What is the NIST Cybersecurity Framework?+

It is a voluntary framework from the US National Institute of Standards and Technology for managing cybersecurity risk. CSF 2.0 is organised as Govern, Identify, Protect, Detect, Respond and Recover. F Creative Studio 360 uses it as a map. We do not certify you against it.

Where do you deliver this?+

For organisations in any country. The framework is not limited to one jurisdiction. A local rule, such as the Essential Eight or CPS 234, is used only when that organisation is actually subject to it.

How is this different from a cybersecurity audit or a risk assessment?+

An audit checks controls against a stated baseline. A risk assessment ranks findings by business effect. This work builds a current profile and a target profile in the language of the NIST Cybersecurity Framework. They can be scoped together, and they are not the same engagement.

Does this replace ISO/IEC 27001 or SOC 2?+

No. The framework can sit beside ISO/IEC 27001, SOC 2 or PCI DSS, because many outcomes overlap. Overlap does not mean one assessment certifies the others. The certificate or attestation, where one exists, is issued by someone else.

How much does it cost, and how long does it take?+

It depends on how many entities are in the profile and whether you want an assessment only or help moving toward the target. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Start with the profile you can defend.

F Creative Studio 360 will look at the entities and the target, then say what a sensible profile includes.