mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-24 13:40:57 +03:00
Add launch content: HN post, Reddit posts, Twitter thread, LinkedIn, Dev.to article
This commit is contained in:
@@ -0,0 +1,133 @@
|
||||
# NIST Cybersecurity Framework 2.0 Mapping
|
||||
|
||||
This directory maps the cybersecurity skills in this repository to the [NIST Cybersecurity Framework (CSF) 2.0](https://www.nist.gov/cyberframework), published February 2024.
|
||||
|
||||
## Overview
|
||||
|
||||
NIST CSF 2.0 organizes cybersecurity activities into 6 core functions that represent the full lifecycle of managing cybersecurity risk. This mapping enables organizations to:
|
||||
|
||||
- **Align skill development** to their CSF implementation tier
|
||||
- **Identify training gaps** across the CSF functions
|
||||
- **Build role-based learning paths** using CSF categories
|
||||
- **Automate compliance mapping** through AI agent queries
|
||||
|
||||
## CSF 2.0 Functions and Skill Alignment
|
||||
|
||||
### Govern (GV) -- Cybersecurity Risk Management Strategy
|
||||
|
||||
Establishing and monitoring the organization's cybersecurity risk management strategy, expectations, and policy.
|
||||
|
||||
| Category | ID | Mapped Subdomains | Skills |
|
||||
|----------|-----|-------------------|--------|
|
||||
| Organizational Context | GV.OC | compliance-governance | 5 |
|
||||
| Risk Management Strategy | GV.RM | compliance-governance, vulnerability-management | 29 |
|
||||
| Roles, Responsibilities, and Authorities | GV.RR | compliance-governance, identity-access-management | 38 |
|
||||
| Policy | GV.PO | compliance-governance, zero-trust-architecture | 18 |
|
||||
| Oversight | GV.OV | compliance-governance, soc-operations | 38 |
|
||||
| Cybersecurity Supply Chain Risk Management | GV.SC | devsecops, container-security | 42 |
|
||||
|
||||
**Primary subdomains:** compliance-governance (5), identity-access-management (33), devsecops (16)
|
||||
|
||||
### Identify (ID) -- Understanding Organizational Cybersecurity Risk
|
||||
|
||||
Understanding the organization's current cybersecurity risks.
|
||||
|
||||
| Category | ID | Mapped Subdomains | Skills |
|
||||
|----------|-----|-------------------|--------|
|
||||
| Asset Management | ID.AM | cloud-security, container-security, network-security | 107 |
|
||||
| Risk Assessment | ID.RA | vulnerability-management, threat-intelligence | 67 |
|
||||
| Improvement | ID.IM | soc-operations, compliance-governance | 38 |
|
||||
|
||||
**Primary subdomains:** vulnerability-management (24), threat-intelligence (43), cloud-security (48)
|
||||
|
||||
### Protect (PR) -- Safeguarding Assets
|
||||
|
||||
Using safeguards to prevent or reduce cybersecurity risk.
|
||||
|
||||
| Category | ID | Mapped Subdomains | Skills |
|
||||
|----------|-----|-------------------|--------|
|
||||
| Identity Management, Authentication, and Access Control | PR.AA | identity-access-management, zero-trust-architecture | 46 |
|
||||
| Awareness and Training | PR.AT | phishing-defense, compliance-governance | 21 |
|
||||
| Data Security | PR.DS | cryptography, cloud-security, api-security | 89 |
|
||||
| Platform Security | PR.PS | endpoint-security, container-security, devsecops | 58 |
|
||||
| Technology Infrastructure Resilience | PR.IR | network-security, zero-trust-architecture | 46 |
|
||||
|
||||
**Primary subdomains:** zero-trust-architecture (13), devsecops (16), identity-access-management (33), cryptography (13)
|
||||
|
||||
### Detect (DE) -- Finding and Analyzing Cybersecurity Events
|
||||
|
||||
Finding and analyzing possible cybersecurity compromises and anomalies.
|
||||
|
||||
| Category | ID | Mapped Subdomains | Skills |
|
||||
|----------|-----|-------------------|--------|
|
||||
| Continuous Monitoring | DE.CM | soc-operations, threat-hunting, network-security | 101 |
|
||||
| Adverse Event Analysis | DE.AE | threat-hunting, malware-analysis, soc-operations | 102 |
|
||||
|
||||
**Primary subdomains:** threat-hunting (35), soc-operations (33), malware-analysis (34)
|
||||
|
||||
### Respond (RS) -- Taking Action Regarding Detected Incidents
|
||||
|
||||
Managing and responding to detected cybersecurity incidents.
|
||||
|
||||
| Category | ID | Mapped Subdomains | Skills |
|
||||
|----------|-----|-------------------|--------|
|
||||
| Incident Management | RS.MA | incident-response, soc-operations | 57 |
|
||||
| Incident Analysis | RS.AN | digital-forensics, malware-analysis, threat-intelligence | 111 |
|
||||
| Incident Response Reporting and Communication | RS.CO | incident-response, compliance-governance | 29 |
|
||||
| Incident Mitigation | RS.MI | incident-response, endpoint-security, network-security | 73 |
|
||||
|
||||
**Primary subdomains:** incident-response (24), digital-forensics (34), malware-analysis (34)
|
||||
|
||||
### Recover (RC) -- Restoring Capabilities After an Incident
|
||||
|
||||
Restoring assets and operations affected by a cybersecurity incident.
|
||||
|
||||
| Category | ID | Mapped Subdomains | Skills |
|
||||
|----------|-----|-------------------|--------|
|
||||
| Incident Recovery Plan Execution | RC.RP | incident-response, ransomware-defense | 29 |
|
||||
| Incident Recovery Communication | RC.CO | incident-response, compliance-governance | 29 |
|
||||
|
||||
**Primary subdomains:** incident-response (24), ransomware-defense (5)
|
||||
|
||||
## Function Coverage Distribution
|
||||
|
||||
```
|
||||
Govern (GV): ████████████░░░░░░░░ ~54 skills (compliance, IAM, devsecops)
|
||||
Identify (ID): ██████████████████░░ ~115 skills (vuln-mgmt, threat-intel, cloud)
|
||||
Protect (PR): ████████████████████ ~160 skills (IAM, ZTA, devsecops, crypto)
|
||||
Detect (DE): ████████████████░░░░ ~102 skills (threat-hunting, SOC, malware)
|
||||
Respond (RS): ██████████████████░░ ~111 skills (IR, forensics, malware)
|
||||
Recover (RC): ████░░░░░░░░░░░░░░░░ ~29 skills (IR recovery, ransomware)
|
||||
```
|
||||
|
||||
## How to Use This Mapping
|
||||
|
||||
### For Organizations
|
||||
|
||||
1. Determine your target CSF implementation tier (Partial, Risk Informed, Repeatable, Adaptive)
|
||||
2. Identify your CSF function priorities
|
||||
3. Use the category tables above to find relevant skill subdomains
|
||||
4. Deploy skills from those subdomains to your team's training plan
|
||||
|
||||
### For AI Agents
|
||||
|
||||
Query skills by CSF function using subdomain filters:
|
||||
|
||||
```
|
||||
# Find all Detect (DE) function skills
|
||||
Filter: subdomain IN (threat-hunting, soc-operations, malware-analysis)
|
||||
|
||||
# Find all Protect (PR) function skills
|
||||
Filter: subdomain IN (identity-access-management, zero-trust-architecture, devsecops, cryptography)
|
||||
```
|
||||
|
||||
### For Security Teams
|
||||
|
||||
Use the alignment table in [`csf-alignment.md`](csf-alignment.md) for a complete subdomain-to-category cross-reference.
|
||||
|
||||
## References
|
||||
|
||||
- [NIST CSF 2.0 (February 2024)](https://www.nist.gov/cyberframework)
|
||||
- [NIST SP 800-53 Rev. 5 Control Mapping](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final)
|
||||
- [CSF 2.0 Quick Start Guides](https://www.nist.gov/cyberframework/getting-started)
|
||||
- [CSF 2.0 Reference Tool](https://csrc.nist.gov/Projects/Cybersecurity-Framework/Filters)
|
||||
@@ -0,0 +1,102 @@
|
||||
# NIST CSF 2.0 Alignment Table
|
||||
|
||||
Complete mapping of each skill subdomain to NIST CSF 2.0 functions and categories.
|
||||
|
||||
## Subdomain-to-CSF Alignment
|
||||
|
||||
| Subdomain | Skills | GV | ID | PR | PR | DE | RS | RC |
|
||||
|-----------|--------|-----|-----|-----|-----|-----|-----|-----|
|
||||
| | | Govern | Identify | Protect | Protect | Detect | Respond | Recover |
|
||||
|
||||
### Detailed Alignment
|
||||
|
||||
| Subdomain (Skills) | Primary CSF Function | CSF Categories | Alignment Rationale |
|
||||
|---------------------|---------------------|----------------|---------------------|
|
||||
| api-security (28) | Protect (PR) | PR.DS, PR.PS | API hardening, authentication, input validation |
|
||||
| cloud-security (48) | Identify (ID), Protect (PR) | ID.AM, PR.DS, PR.PS, PR.IR | Cloud asset management, data protection, infrastructure resilience |
|
||||
| compliance-governance (5) | Govern (GV) | GV.OC, GV.RM, GV.RR, GV.PO, GV.OV | Risk strategy, policy, organizational oversight |
|
||||
| container-security (26) | Protect (PR) | PR.PS, GV.SC | Platform security, supply chain risk management |
|
||||
| cryptography (13) | Protect (PR) | PR.DS | Data confidentiality and integrity at rest and in transit |
|
||||
| devsecops (16) | Protect (PR), Govern (GV) | PR.PS, GV.SC | Secure development lifecycle, supply chain security |
|
||||
| digital-forensics (34) | Respond (RS) | RS.AN, RS.MA | Incident analysis, evidence collection and examination |
|
||||
| endpoint-security (16) | Protect (PR), Detect (DE) | PR.PS, DE.CM, DE.AE | Endpoint hardening, continuous monitoring, threat detection |
|
||||
| identity-access-management (33) | Protect (PR), Govern (GV) | PR.AA, GV.RR | Identity lifecycle, authentication, authorization, access governance |
|
||||
| incident-response (24) | Respond (RS), Recover (RC) | RS.MA, RS.AN, RS.MI, RS.CO, RC.RP, RC.CO | Full incident lifecycle from detection through recovery |
|
||||
| malware-analysis (34) | Detect (DE), Respond (RS) | DE.AE, RS.AN | Adverse event analysis, reverse engineering, threat characterization |
|
||||
| mobile-security (12) | Protect (PR) | PR.PS, PR.DS | Mobile platform security, application data protection |
|
||||
| network-security (33) | Protect (PR), Detect (DE) | PR.IR, DE.CM | Network infrastructure resilience, traffic monitoring |
|
||||
| ot-ics-security (28) | Protect (PR), Detect (DE) | PR.PS, PR.IR, DE.CM | Industrial control system protection and monitoring |
|
||||
| penetration-testing (23) | Identify (ID) | ID.RA | Risk assessment through offensive security testing |
|
||||
| phishing-defense (16) | Protect (PR), Detect (DE) | PR.AT, DE.CM, DE.AE | Security awareness training, phishing detection |
|
||||
| ransomware-defense (5) | Respond (RS), Recover (RC) | RS.MI, RC.RP | Ransomware mitigation and recovery planning |
|
||||
| red-teaming (24) | Identify (ID) | ID.RA, ID.IM | Adversary simulation for risk assessment and program improvement |
|
||||
| soc-operations (33) | Detect (DE), Respond (RS) | DE.CM, DE.AE, RS.MA | Continuous monitoring, alert triage, incident management |
|
||||
| threat-hunting (35) | Detect (DE) | DE.CM, DE.AE | Proactive threat detection, hypothesis-driven analysis |
|
||||
| threat-intelligence (43) | Identify (ID), Detect (DE) | ID.RA, DE.AE | Threat landscape understanding, intelligence-driven detection |
|
||||
| vulnerability-management (24) | Identify (ID) | ID.RA, GV.RM | Vulnerability identification, risk assessment, remediation prioritization |
|
||||
| web-application-security (41) | Protect (PR), Identify (ID) | PR.DS, PR.PS, ID.RA | Application security testing and hardening |
|
||||
| zero-trust-architecture (13) | Protect (PR) | PR.AA, PR.IR | Zero trust access control and network segmentation |
|
||||
|
||||
## CSF Category Coverage Summary
|
||||
|
||||
### Govern (GV)
|
||||
|
||||
| Category | ID | Description | Subdomain Coverage |
|
||||
|----------|-----|------------|-------------------|
|
||||
| Organizational Context | GV.OC | Understanding the organizational mission and stakeholder expectations | compliance-governance |
|
||||
| Risk Management Strategy | GV.RM | Risk management priorities, constraints, and appetite | compliance-governance, vulnerability-management |
|
||||
| Roles, Responsibilities, and Authorities | GV.RR | Cybersecurity roles and authorities are established | compliance-governance, identity-access-management |
|
||||
| Policy | GV.PO | Organizational cybersecurity policy is established | compliance-governance, zero-trust-architecture |
|
||||
| Oversight | GV.OV | Results of cybersecurity activities are reviewed | compliance-governance, soc-operations |
|
||||
| Cybersecurity Supply Chain Risk Management | GV.SC | Supply chain risks are managed | devsecops, container-security |
|
||||
|
||||
### Identify (ID)
|
||||
|
||||
| Category | ID | Description | Subdomain Coverage |
|
||||
|----------|-----|------------|-------------------|
|
||||
| Asset Management | ID.AM | Assets that enable the organization are identified and managed | cloud-security, container-security, network-security |
|
||||
| Risk Assessment | ID.RA | The cybersecurity risk to the organization is understood | vulnerability-management, threat-intelligence, penetration-testing, red-teaming |
|
||||
| Improvement | ID.IM | Improvements to organizational cybersecurity are identified | soc-operations, red-teaming, compliance-governance |
|
||||
|
||||
### Protect (PR)
|
||||
|
||||
| Category | ID | Description | Subdomain Coverage |
|
||||
|----------|-----|------------|-------------------|
|
||||
| Identity Management, Authentication, and Access Control | PR.AA | Access is limited to authorized users, services, and hardware | identity-access-management, zero-trust-architecture |
|
||||
| Awareness and Training | PR.AT | Personnel are provided cybersecurity awareness and training | phishing-defense, compliance-governance |
|
||||
| Data Security | PR.DS | Data are managed consistent with the organization's risk strategy | cryptography, cloud-security, api-security |
|
||||
| Platform Security | PR.PS | Hardware, software, and services are managed consistent with risk strategy | endpoint-security, container-security, devsecops, ot-ics-security |
|
||||
| Technology Infrastructure Resilience | PR.IR | Security architectures are managed to protect asset confidentiality, integrity, and availability | network-security, zero-trust-architecture, ot-ics-security |
|
||||
|
||||
### Detect (DE)
|
||||
|
||||
| Category | ID | Description | Subdomain Coverage |
|
||||
|----------|-----|------------|-------------------|
|
||||
| Continuous Monitoring | DE.CM | Assets are monitored to find anomalies and indicators of compromise | soc-operations, threat-hunting, network-security, endpoint-security |
|
||||
| Adverse Event Analysis | DE.AE | Anomalies and potential adverse events are analyzed | threat-hunting, malware-analysis, soc-operations, threat-intelligence |
|
||||
|
||||
### Respond (RS)
|
||||
|
||||
| Category | ID | Description | Subdomain Coverage |
|
||||
|----------|-----|------------|-------------------|
|
||||
| Incident Management | RS.MA | Responses to detected incidents are managed | incident-response, soc-operations |
|
||||
| Incident Analysis | RS.AN | Investigations are conducted to understand the incident | digital-forensics, malware-analysis, threat-intelligence |
|
||||
| Incident Response Reporting and Communication | RS.CO | Response activities are coordinated with internal and external stakeholders | incident-response, compliance-governance |
|
||||
| Incident Mitigation | RS.MI | Activities are performed to prevent expansion and mitigate effects | incident-response, endpoint-security, network-security |
|
||||
|
||||
### Recover (RC)
|
||||
|
||||
| Category | ID | Description | Subdomain Coverage |
|
||||
|----------|-----|------------|-------------------|
|
||||
| Incident Recovery Plan Execution | RC.RP | Restoration activities are performed to ensure operational availability | incident-response, ransomware-defense |
|
||||
| Incident Recovery Communication | RC.CO | Restoration activities are coordinated with internal and external parties | incident-response, compliance-governance |
|
||||
|
||||
## Gap Analysis
|
||||
|
||||
| CSF Category | Current Coverage | Gap |
|
||||
|-------------|-----------------|-----|
|
||||
| GV.OC | Low (5 skills) | Need more organizational security context and mission alignment skills |
|
||||
| GV.PO | Low | Need dedicated policy development and management skills |
|
||||
| PR.AT | Moderate (16 skills) | Could expand security awareness training beyond phishing |
|
||||
| RC.RP | Low (29 skills) | Need more disaster recovery and business continuity skills |
|
||||
| RC.CO | Low | Need dedicated incident communication and stakeholder management skills |
|
||||
Reference in New Issue
Block a user