What is the difference between CSF Tiers and CSF Profiles?
CSF Tiers characterise an organisation's cybersecurity risk management maturity, ranging from Partial to Adaptive, indicating the rigour and integration of practices. CSF Profiles, conversely, are custom alignments of an organisation's specific cybersecurity requirements and current or target posture with the Framework's Categories and Subcategories. Tiers describe *how* risk is managed, while Profiles define *what* cybersecurity outcomes are relevant and achieved for a given context.
CSF Tiers provide a qualitative measure of an organisation's cybersecurity risk management practices, indicating the degree to which those practices are integrated into overall risk management, are informed by risk, and adapt to changing threats. There are four Tiers: Partial, Risk Informed, Repeatable, and Adaptive. These Tiers are not a pass/fail assessment but rather a tool for organisations to understand and communicate the sophistication of their cybersecurity programme. A higher Tier indicates more formalised processes, greater integration of cybersecurity risk into enterprise-wide risk management, and a proactive approach to continuous improvement and adaptation to the evolving threat landscape. Practitioners should use Tiers to benchmark their current state, set target maturity levels, and articulate the resources required to achieve those targets, recognising that the 'optimal' Tier depends on an organisation's risk appetite, regulatory requirements, and operational context.
CSF Profiles are unique alignments of an organisation's business requirements, risk appetite, and resources with the desired outcomes of the Framework's Categories and Subcategories. An organisation develops a Profile by selecting specific Subcategories from the Framework that are most relevant to its mission, business objectives, and operating environment. Profiles can be used to describe an organisation's 'Current Profile' (its existing cybersecurity posture) and its 'Target Profile' (the desired cybersecurity posture). The gap between these two Profiles helps identify areas for improvement and prioritise actions. Practitioners leverage Profiles to customise the CSF, making it relevant to their specific context, and to integrate other standards, guidelines, and practices (e.g., ISO 27001, HIPAA, CMMC) by mapping them to the CSF's core. This customisation ensures that cybersecurity investments are aligned with business priorities and risk management strategies.
Sources
- NIST Cybersecurity Framework Version 1.1, Section 2.1 (Tiers)
- NIST Cybersecurity Framework Version 1.1, Section 2.2 (Profiles)