- Add validated mitre_attack frontmatter to all 754 skills (286 distinct
techniques), verified against MITRE ATT&CK v19.1 via the official
mitreattack-python library: 0 revoked, deprecated, or invalid IDs
- Curate precise per-skill technique IDs for forensics, malware-analysis,
threat-intel, and red-team skills (e.g. DCSync -> T1003.006,
Kerberoasting -> T1558.003, Pass-the-Ticket -> T1550.003)
- Reconcile v19.1 tactic restructuring: Defense Evasion split into
Stealth (TA0005) and Defense Impairment (TA0112); revoked T1562.*
family and T1070.001/.002 remapped to active equivalents (T1685.*)
- Normalize word-split tags across 35 skills (remove filename-derived
stopword tags, add semantic cybersecurity tags)
- Add api-reference.md for 3 skills that were missing it
- Update README ATT&CK section with accurate v19.1 tactic distribution
The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.
cybersecurity
compliance-governance
compliance
governance
nist
csf
maturity-assessment
risk-management
GV.OC-01
GV.RM-01
GV.PO-01
ID.RA-01
GV.OV-01
1.0
mahipal
Apache-2.0
T1078
T1530
T1685.002
Performing NIST CSF Maturity Assessment
Overview
The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions: Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF, using the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) to measure organizational cybersecurity posture and create improvement roadmaps.
When to Use
When conducting security assessments that involve performing nist csf maturity assessment
When following incident response procedures for related security events
When performing scheduled security testing or auditing activities
When validating security controls through hands-on testing
Prerequisites
Understanding of cybersecurity risk management principles
Access to NIST CSF 2.0 documentation and reference tool
Knowledge of organizational IT/OT environment and security controls
Stakeholder access across business units for assessment interviews
Core Concepts
CSF 2.0 Functions (6 Functions, 22 Categories)
Function
Code
Categories
Purpose
Govern
GV
6
Establish and monitor cybersecurity risk management strategy
Identify
ID
3
Determine current cybersecurity risk to the organization
Protect
PR
5
Implement safeguards to prevent or reduce risk
Detect
DE
2
Find and analyze possible cybersecurity attacks
Respond
RS
4
Take action regarding detected cybersecurity incidents
Recover
RC
2
Restore capabilities impaired by cybersecurity incidents
Govern Function (New in CSF 2.0)
GV.OC: Organizational Context
GV.RM: Risk Management Strategy
GV.RR: Roles, Responsibilities, and Authorities
GV.PO: Policy
GV.OV: Oversight
GV.SC: Cybersecurity Supply Chain Risk Management
Implementation Tiers
Tier
Name
Description
Tier 1
Partial
Ad hoc, reactive; limited awareness of cybersecurity risk
Tier 2
Risk-Informed
Risk-aware but not organization-wide; approved but may not be policy