Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).

MITAuto-check: notesSecurity

Install Csf Mapping

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills csf-mapping --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/csf-mapping .claude/skills/csf-mapping && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
csf-mapping
GitHub stars
413
Token cost
~3k tokens
SKILL.md length
1,305 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).

  • Works in 5 steps: Establish scope → Choose your CSF profile → Assess each Subcategory → …
  • The user mentions NIST CSF
  • SKILL.md covers Methodology, Subcategory cross-references…, High-impact gaps most orgs have and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Csf Mapping is an agent skill from briiirussell/cybersecurity-skills. Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). Produce a gap analysis, current/target tier assessment, and roadmap in the governance language that boards, auditors, and CISOs actually use. Use when the user mentions 'NIST CSF,' 'CSF 2.0,' 'cybersecurity framework,' 'security posture,' 'governance mapping,' 'CSF gap analysis,' 'CSF tiers,' 'cybersecurity maturity,' 'security roadmap,' 'CISO report,' 'board reporting,' 'security…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions NIST CSF
  • Cybersecurity framework
  • Security posture
  • Governance mapping

Example prompts

  • “NIST CSF,”
  • “CSF 2.0,”
  • “cybersecurity framework,”
  • “/csf-mapping”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, WebSearch

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Establish scope
  2. Choose your CSF profile
  3. Assess each Subcategory
  4. Identify gaps and prioritize
  5. Build the roadmap

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Csf Mapping loads about 3k tokens when it runs. Until then it costs about 150 tokens; SKILL.md has 1,305 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~150
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,305 words, ~3,038 tokens.

Download SKILL.mdSave it as .claude/skills/csf-mapping/SKILL.md (or your agent's skills folder).
name
csf-mapping
description
Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). Produce a gap analysis, current/target tier assessment, and roadmap in the governance language that boards, auditors, and CISOs actually use. Use when the user mentions 'NIST CSF,' 'CSF 2.0,' 'cybersecurity framework,' 'security posture,' 'governance mapping,' 'CSF gap analysis,' 'CSF tiers,' 'cybersecurity maturity,' 'security roadmap,' 'CISO report,' 'board reporting,' 'security program,' or needs to translate technical findings into governance language.
allowed-tools
Read, Grep, Glob, Bash, WebSearch

CSF Mapping — NIST Cybersecurity Framework 2.0 Posture Assessment

Translate your security posture into the language every CISO, board, auditor, and insurer already speaks. Distinct from the audit skills (which find specific issues); this skill assesses your program against a recognized framework and produces governance-ready output.

NIST CSF 2.0 is the framework that, as of 2024, replaced CSF 1.1. It added a sixth function — Govern — recognizing that the others can't work without governance backing.

The six functions:

FunctionWhat it covers
Govern (GV)Cybersecurity strategy, roles, policies, oversight, supply chain risk
Identify (ID)Asset inventory, business environment, risk assessment, supply chain
Protect (PR)Access control, awareness, data security, baseline configurations, maintenance, protective tech
Detect (DE)Continuous monitoring, anomaly detection, adverse event analysis
Respond (RS)Incident management, analysis, mitigation, reporting, comms
Recover (RC)Recovery planning, improvements, communications

Each function contains Categories (e.g., PR.AA — Identity Management, Authentication, and Access Control), and each category contains Subcategories (e.g., PR.AA-01 — Identities and credentials for authorized users, services, and hardware are managed).

This skill maps your reality to those Subcategories.

Cross-references: every audit skill in this repo (they produce evidence that becomes the "current state" entries here), iam-audit (most of PR.AA), siem-detection (most of DE), incident-triage (most of RS), threat-modeling (informs ID.RA risk assessment), breach-patterns (informs ID.IM improvements from lessons learned).

Methodology

Step 1 — Establish scope

CSF assessments are scope-bounded. Decide which of these you're assessing:

  • Whole organization — every system, every business unit
  • One product / service — for vendor due-diligence questionnaires (SIG, CAIQ)
  • One environment — production cloud only, or PCI-in-scope only
  • Regulatory scope — HIPAA-covered systems, FedRAMP boundary, etc.

Write down what's in and what's out. Most CSF assessments fail at scope drift.

Step 2 — Choose your CSF profile

CSF 2.0 introduced Organizational Profiles — instead of "score every Subcategory equally," you tailor based on what matters.

  • Current Profile — where you actually are
  • Target Profile — where you want to be (informed by business goals, regulatory requirements, risk appetite)
  • Community Profile — pre-built profile for your sector (manufacturing, healthcare, financial services — published by NIST and others)

For a first-pass assessment, start with a Community Profile if one exists for your sector, then tailor.

Step 3 — Assess each Subcategory

For each Subcategory in scope:

FieldWhat to record
IDe.g., PR.AA-05
Subcategory textVerbatim from NIST or paraphrased
Current stateWhat you actually do today (evidence, not aspiration)
EvidenceDocument / system / process that proves the current state
TierPartial / Risk-Informed / Repeatable / Adaptive (1-4)
Target tierWhat you're aiming for
GapThe delta
PlanWhat closes the gap
OwnerWho's accountable
TimelineWhen
CSF Implementation Tiers
TierNameCharacteristic
1PartialAd-hoc, reactive, undocumented; awareness is informal
2Risk-InformedRisk management is approved but not org-wide; processes are repeatable for some teams
3RepeatableDocumented org-wide policies; consistent processes; risk-informed budgeting
4AdaptiveContinuous improvement; quantitative risk; learning from incidents (yours and peers'); cybersecurity culture

Tier 4 is rare and expensive. Most mature SaaS orgs target Tier 3 across most subcategories. Set targets based on what the business actually needs, not what looks good.

Step 4 — Identify gaps and prioritize

For each gap, ask:

  • Impact if exploited / not addressed (regulatory, reputational, financial)
  • Likelihood given current threat landscape and your specific exposure
  • Cost to close (engineering hours, tooling, headcount)
  • Dependencies on other gaps closing first

Prioritize by Risk × Cost-to-close — not just by risk. Some critical-risk items take a year and three vendors; some quick wins reduce real risk in a sprint.

Step 5 — Build the roadmap

CSF roadmaps usually run in quarters with annual targets. A useful structure:

  • Next 30 days — immediate gaps (quick wins, low-cost high-risk items)
  • Next 90 days — medium effort, named owners, defined success criteria
  • Next 12 months — strategic gaps requiring budget approval, tooling decisions, headcount
  • Annual review — full reassessment; profile refresh; tier movement

Each item on the roadmap names: the Subcategory it closes, the owner, the budget, the success metric, the review date.

Subcategory cross-references to skills in this repo

A useful shortcut — these are the audit skills that produce evidence for which CSF Subcategories.

CSF SubcategoryAudit skillType of evidence
GV.SC (Supply Chain Risk)dependency-auditCVE inventory, vendor list, supply chain risk register
ID.AM (Asset Management)cloud-audit, container-audit, reconAsset inventory output
ID.RA (Risk Assessment)threat-modeling, breach-patternsThreat models, breach-pattern coverage doc
ID.IM (Improvement from past incidents)incident-triage post-mortems, breach-patternsPost-incident reviews, lessons-learned applied
PR.AA (Identity & Access Control)iam-auditIAM audit reports, role inventory
PR.DS (Data Security)crypto-audit, secrets-auditCrypto posture, secrets management posture
PR.PS (Platform Security)container-audit, cloud-auditK8s hardening, cloud posture
PR.IR (Infrastructure Resilience)container-audit, cloud-auditNetwork policy, segmentation, backup posture
DE.CM (Continuous Monitoring)siem-detection, soc-operationsSIEM coverage, ATT&CK Navigator export
DE.AE (Anomaly & Event Analysis)siem-detection, threat-huntingDetection rule inventory, hunt findings
RS.MA (Incident Management)incident-triage, soc-operationsIR plan, runbooks, recent incident reports
RS.AN (Analysis)disk-forensics, incident-triageForensic analysis outputs
RS.MI (Mitigation)finding-triage, incident-triageTriage decisions, mitigation tracking
RC.RP (Recovery Plan)(not directly covered — separate BCP/DR work)BCP / DR plans, tested recovery

For Subcategories without direct skill coverage, the gap is usually "we have technical depth but not the program-level artifact." E.g., RC.RP-01 (Recovery plan is executed during or after an incident) needs an actual documented and tested BCP/DR plan — running incident-triage doesn't automatically produce one.

Show full SKILL.md (446 more words)Show less

High-impact gaps most orgs have

Patterns I see repeatedly in CSF assessments. Not universal, but starting points:

  • GV.OC-04 (Critical objectives, capabilities, and services are identified and communicated) — Most orgs can't name their crown-jewel systems consistently across security, IT, and engineering
  • GV.SC (Supply Chain Risk Management category) — Either no vendor risk program at all, or one that exists on paper but doesn't actually gate procurement
  • ID.AM-08 (Systems, hardware, software, services, and data are managed throughout their life cycles) — Asset inventory is "the SaaS vendor's list" plus "what we remember"
  • ID.IM-04 (Incident response plans are exercised) — Plan exists, last tested three years ago
  • PR.AA-05 (Access permissions and authorizations are managed, incorporating the principles of least privilege) — Quarterly access review exists in policy, not in practice
  • PR.DS-01 (The confidentiality, integrity, and availability of data-at-rest are protected) — Encryption at rest "yes," but key management is "ask AWS"
  • DE.AE-08 (Incidents are declared when adverse events meet defined criteria) — Criteria not actually defined; "we'll know when we see it"
  • RS.CO-02 (Internal and external stakeholders are notified of incidents) — Notification matrix is in someone's head
  • RC.RP-01 (Recovery plan is executed) — Documented, never tested

Output Format

markdown
# NIST CSF 2.0 Posture Assessment
## Organization: [name]
## Scope: [what's in / out]
## Date: [date]
## Assessor: [name]

## Executive summary
[2-3 paragraphs in plain English — overall posture, top 3 risks, top 3 wins, recommended 90-day priorities]

## Profile

### Tier summary across functions
| Function | Current tier | Target tier |
|----------|--------------|-------------|
| GV | 2 | 3 |
| ID | 2 | 3 |
| PR | 3 | 3 |
| DE | 2 | 3 |
| RS | 3 | 3 |
| RC | 1 | 2 |

### Per-Subcategory detail
| Subcategory | Current state | Evidence | Tier | Target | Gap | Owner | Timeline |
|-------------|---------------|----------|------|--------|-----|-------|----------|

## Prioritized roadmap

### Next 30 days
- [Item, owner, success metric]

### Next 90 days
- [Item, owner, success metric]

### Next 12 months
- [Item, owner, success metric]

## Cross-references
[Links to evidence — audit reports, IR plans, IAM reports, etc.]

Translating to board language

Boards don't want Subcategory IDs. They want answers to three questions:

  1. Where are we exposed? (Top 3-5 material risks)
  2. What are we doing about it? (Specific investments, named owners, dates)
  3. How will we know we're better? (Quantitative metrics, target dates)

Use the CSF assessment as the backing detail. The board view is a one-page heatmap and three slides of priorities. The assessment goes in the appendix.

Boundaries

  • This skill produces governance artifacts and roadmaps — not exploitation
  • CSF assessments are not audits in the regulatory sense (SOC 2 audit, FedRAMP assessment, ISO 27001 certification audit are all separate processes); CSF mapping informs those but doesn't replace them
  • For audited environments (PCI, HIPAA, FedRAMP), the auditor's specific framework is authoritative; CSF mapping is a useful complement
  • Refuse to inflate tier ratings without evidence — Tier 3 means "evidence of documented org-wide processes," not "we hope to do this someday"
  • Where the assessment surfaces a finding that needs immediate action (active incident, exposed system), hand off to incident-triage or the relevant audit skill

References

  • NIST Cybersecurity Framework 2.0 (nist.gov/cyberframework)
  • NIST CSF 2.0 Quick Start Guides
  • NIST CSF Community Profiles (sector-specific starting points)
  • NIST SP 800-53 (controls catalog — provides specific controls that map to CSF Subcategories)
  • ISO 27001:2022 (alternative ISMS framework — frequently mapped against CSF for organizations doing both)
  • CIS Critical Security Controls v8 (alternative prioritized framework — strong overlap with CSF)
  • Cybersecurity Maturity Model Certification (CMMC) — for DoD contractors; uses CSF + NIST 800-171
  • "Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework" — Cynthia Brumfield

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/csf-mapping of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Csf Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Csf Mapping compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Csf Mapping this skillbriiirussell/cybersecurity-skills413—~3kAutomated safety check: NotesMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Categories

Questions about Csf Mapping

What does Csf Mapping do?

Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). Csf Mapping is an agent skill from briiirussell/cybersecurity-skills.0 (Govern, Identify, Protect, Detect, Respond, Recover).

When should I use Csf Mapping?

Csf Mapping fits situations like: the user mentions NIST CSF; cybersecurity framework; security posture; governance mapping.

How do I install Csf Mapping in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a claude-code`. Or copy the skill folder (skills/csf-mapping in briiirussell/cybersecurity-skills) into .claude/skills/csf-mapping in your project. Claude Code loads it when a task matches its description.

How do I install Csf Mapping in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a codex`. Or copy the skill folder (skills/csf-mapping in briiirussell/cybersecurity-skills) into .agents/skills/csf-mapping in your project. Codex loads it when a task matches its description.

Can I use Csf Mapping in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/csf-mapping, .gemini/skills/csf-mapping, .github/skills/csf-mapping and .opencode/skills/csf-mapping in your project.

What does Csf Mapping need to run?

SKILL.md names no scripts, command-line tools or credentials: Csf Mapping is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebSearch.

Does Csf Mapping access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Csf Mapping safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Csf Mapping use?

Csf Mapping is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Csf Mapping use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Csf Mapping?

Skills that share tags, products or a category with Csf Mapping: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Csf Mapping?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.