/nist-csf-20-expert
NIST Cybersecurity Framework v2.0 expert. Reference-depth knowledge of the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Profiles (Current vs Target), Tiers, Implementation Examples, and the practitioner workflow of using CSF
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill nist-csf-20-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/nist-csf-20-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
NIST Cybersecurity Framework v2.0 expert. Reference-depth knowledge of the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Profiles (Current vs Target), Tiers, Implementation Examples, and the practitioner workflow of using CSF
SKILL.md
nist-csf-20-expert.SKILL.mdname: nist-csf-20-expert
description: NIST Cybersecurity Framework v2.0 expert. Reference-depth knowledge of the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Profiles (Current vs Target), Tiers, Implementation Examples, and the practitioner workflow of using CSF as a board-readable cybersecurity outcomes language. Backed by the SCF crosswalk for control-by-control mechanics.
allowed-tools: Read, Glob, Grep, Write
NIST Cybersecurity Framework (v2.0) Expert
Reference-depth expertise for **NIST Cybersecurity Framework v2.0** — the cross-sector outcomes-based framework published by the U.S. National Institute of Standards and Technology. CSF 2.0 is the most widely adopted cybersecurity framework in the United States and is increasingly used worldwide as a common vocabulary for board-level and regulator-facing cybersecurity discussions.
This plugin bundles the SCF crosswalk (250 SCF controls → 134 CSF Subcategories) with framework-specific scope, assessment, and evidence guidance.
Framework identity
- **SCF framework ID**: `general-nist-csf-2-0`
- **Publisher**: NIST (National Institute of Standards and Technology), U.S. Department of Commerce
- **Version**: 2.0 (final)
- **Released**: February 26, 2024 (supersedes CSF 1.1, April 2018)
- **Region**: Global (U.S.-published, used internationally)
- **Country origin**: United States
- **Status**: Voluntary — not a regulation, but referenced by U.S. federal contracts, sector regulators (FERC/NERC, FFIEC, HHS/HPH), and Executive Orders (notably EO 14028 on improving the nation's cybersecurity)
- **Cost**: Free of charge; CSF Core, Quick Start Guides, and Implementation Examples are public-domain U.S. government works
- **Successor relationship**: CSF 2.0 supersedes CSF 1.1, but transition is not mandated — many organizations and contracts still reference 1.1 in 2026
Framework in plain language
CSF 2.0 is a cybersecurity outcomes framework, not a control catalog. Its job is to give an organization a small, common vocabulary it can use to (a) describe what cybersecurity outcomes it currently achieves, (b) describe what it wants to achieve, and (c) plan the gap between the two. The framework deliberately avoids prescribing *how* to achieve outcomes — that's what control catalogs like NIST SP 800-53, ISO 27001 Annex A, and CIS Controls are for. CSF cites those catalogs as **Informative References**.
The headline change in CSF 2.0 is the addition of the **Govern (GV)** Function. CSF 1.1 had five Functions — Identify, Protect, Detect, Respond, Recover — which describe the lifecycle of a cybersecurity event. CSF 2.0 adds Govern as a cross-cutting Function that holds the board, executives, and risk-management processes accountable for the cybersecurity program itself, not just for responding to events. This change reflects what regulators, boards, and the SEC's 2023 cybersecurity disclosure rule have been pushing for years.
Territorial scope and applicability
CSF is **voluntary** and **cross-sector**. It does not impose territorial obligations on its own. Practical sweet spots where it's the right framework to reach for:
- **U.S. federal contractors** before they're mature enough for full NIST SP 800-53 compliance — CSF gives them a defensible structure and a glide path
- **Critical infrastructure operators** under EO 14028 and sector-specific guidance (energy, water, transportation, healthcare, financial services) — CSF is the U.S. government's preferred shared vocabulary
- **Healthcare and finance** organizations that already comply with HIPAA, GLBA, or PCI DSS and want a board-readable summary that maps cleanly to those underlying frameworks
- **Mid-market organizations** building a first formal cybersecurity program — CSF Tier 1 → Tier 2 → Tier 3 progression scales gracefully
- **International organizations** using CSF as a U.S.-aligned reference alongside ISO/IEC 27001 (Informative References include ISO 27001:2022 mappings)
- **Private-sector boards and audit committees** who want a single page of "what we do for cybersecurity" that is not a 1,200-control spreadsheet
CSF is **not** a substitute for sectoral regulation. A hospital still owes HIPAA Security Rule compliance regardless of its CSF posture; a bank still owes GLBA Safeguards Rule; a defense contractor still owes CMMC. CSF sits *above* those — it's the shared language a CISO uses to explain the program to a board that doesn't read CFR citations.
The CSF Core: Functions, Categories, Subcategories
CSF is organized hierarchically. The Core has three layers:
1. Functions (6)
The Functions are the highest-level grouping and the single most important thing to memorize. CSF 2.0 has six:
| Code | Function | What it covers | |---|---|---| | **GV** | **Govern** | Cybersecurity strategy, expectations, policy, roles, risk tolerance, supply chain risk management, oversight. New in 2.0. | | **ID** | **Identify** | Asset management, business environment, risk assessment, improvement. Understand your context. | | **PR** | **Protect** | Identity management and access control, awareness and training, data security, platform security, technology infrastructure resilience. | | **DE** | **Detect** | Continuous monitoring, adverse event analysis. | | **RS** | **Respond** | Incident management, analysis, response reporting and communication, mitigation. | | **RC** | **Recover** | Incident recovery plan execution, recovery communication. |
The mnemonic the community uses is **GIPDRR** (or **G + IPDRR**, since IPDRR was the CSF 1.x ordering). Note that **Govern is not the first Function executed during an incident** — it's the wrapper around all the others. In Profile work and assessments, Govern outcomes are typically written and approved *before* the Identify/Protect/Detect/Respond/Recover capabilities are stood up, but in continuous operation Govern runs in parallel with everything else.
2. Categories
Each Fun
Read more
name: nist-csf-20-expert description: NIST Cybersecurity Framework v2.0 expert. Reference-depth knowledge of the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Profiles (Current vs Target), Tiers, Implementation Examples, and the practitioner workflow of using CSF as a board-readable cybersecurity outcomes language. Backed by the SCF crosswalk for control-by-control mechanics. allowed-tools: Read, Glob, Grep, Write
NIST Cybersecurity Framework (v2.0) Expert
Reference-depth expertise for **NIST Cybersecurity Framework v2.0** — the cross-sector outcomes-based framework published by the U.S. National Institute of Standards and Technology. CSF 2.0 is the most widely adopted cybersecurity framework in the United States and is increasingly used worldwide as a common vocabulary for board-level and regulator-facing cybersecurity discussions.
This plugin bundles the SCF crosswalk (250 SCF controls → 134 CSF Subcategories) with framework-specific scope, assessment, and evidence guidance.
Framework identity
- **SCF framework ID**: `general-nist-csf-2-0`
- **Publisher**: NIST (National Institute of Standards and Technology), U.S. Department of Commerce
- **Version**: 2.0 (final)
- **Released**: February 26, 2024 (supersedes CSF 1.1, April 2018)
- **Region**: Global (U.S.-published, used internationally)
- **Country origin**: United States
- **Status**: Voluntary — not a regulation, but referenced by U.S. federal contracts, sector regulators (FERC/NERC, FFIEC, HHS/HPH), and Executive Orders (notably EO 14028 on improving the nation's cybersecurity)
- **Cost**: Free of charge; CSF Core, Quick Start Guides, and Implementation Examples are public-domain U.S. government works
- **Successor relationship**: CSF 2.0 supersedes CSF 1.1, but transition is not mandated — many organizations and contracts still reference 1.1 in 2026
Framework in plain language
CSF 2.0 is a cybersecurity outcomes framework, not a control catalog. Its job is to give an organization a small, common vocabulary it can use to (a) describe what cybersecurity outcomes it currently achieves, (b) describe what it wants to achieve, and (c) plan the gap between the two. The framework deliberately avoids prescribing *how* to achieve outcomes — that's what control catalogs like NIST SP 800-53, ISO 27001 Annex A, and CIS Controls are for. CSF cites those catalogs as **Informative References**.
The headline change in CSF 2.0 is the addition of the **Govern (GV)** Function. CSF 1.1 had five Functions — Identify, Protect, Detect, Respond, Recover — which describe the lifecycle of a cybersecurity event. CSF 2.0 adds Govern as a cross-cutting Function that holds the board, executives, and risk-management processes accountable for the cybersecurity program itself, not just for responding to events. This change reflects what regulators, boards, and the SEC's 2023 cybersecurity disclosure rule have been pushing for years.
Territorial scope and applicability
CSF is **voluntary** and **cross-sector**. It does not impose territorial obligations on its own. Practical sweet spots where it's the right framework to reach for:
- **U.S. federal contractors** before they're mature enough for full NIST SP 800-53 compliance — CSF gives them a defensible structure and a glide path
- **Critical infrastructure operators** under EO 14028 and sector-specific guidance (energy, water, transportation, healthcare, financial services) — CSF is the U.S. government's preferred shared vocabulary
- **Healthcare and finance** organizations that already comply with HIPAA, GLBA, or PCI DSS and want a board-readable summary that maps cleanly to those underlying frameworks
- **Mid-market organizations** building a first formal cybersecurity program — CSF Tier 1 → Tier 2 → Tier 3 progression scales gracefully
- **International organizations** using CSF as a U.S.-aligned reference alongside ISO/IEC 27001 (Informative References include ISO 27001:2022 mappings)
- **Private-sector boards and audit committees** who want a single page of "what we do for cybersecurity" that is not a 1,200-control spreadsheet
CSF is **not** a substitute for sectoral regulation. A hospital still owes HIPAA Security Rule compliance regardless of its CSF posture; a bank still owes GLBA Safeguards Rule; a defense contractor still owes CMMC. CSF sits *above* those — it's the shared language a CISO uses to explain the program to a board that doesn't read CFR citations.
The CSF Core: Functions, Categories, Subcategories
CSF is organized hierarchically. The Core has three layers:
1. Functions (6)
The Functions are the highest-level grouping and the single most important thing to memorize. CSF 2.0 has six:
| Code | Function | What it covers | |---|---|---| | **GV** | **Govern** | Cybersecurity strategy, expectations, policy, roles, risk tolerance, supply chain risk management, oversight. New in 2.0. | | **ID** | **Identify** | Asset management, business environment, risk assessment, improvement. Understand your context. | | **PR** | **Protect** | Identity management and access control, awareness and training, data security, platform security, technology infrastructure resilience. | | **DE** | **Detect** | Continuous monitoring, adverse event analysis. | | **RS** | **Respond** | Incident management, analysis, response reporting and communication, mitigation. | | **RC** | **Recover** | Incident recovery plan execution, recovery communication. |
The mnemonic the community uses is **GIPDRR** (or **G + IPDRR**, since IPDRR was the CSF 1.x ordering). Note that **Govern is not the first Function executed during an incident** — it's the wrapper around all the others. In Profile work and assessments, Govern outcomes are typically written and approved *before* the Identify/Protect/Detect/Respond/Recover capabilities are stood up, but in continuous operation Govern runs in parallel with everything else.
2. Categories
Each Fun
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

