Extending the model · NIST CSF

NIST Cybersecurity Framework

HERM records what the institution runs and how sensitive each system is. The NIST CSF adds how well each of those is defended — a common language for security posture that maps straight onto the classification and criticality already in the model.

What it is

The NIST Cybersecurity Framework is a voluntary, widely adopted framework for managing cybersecurity risk. Its core organizes security work into a small set of functions, each broken into categories and outcomes, so an institution can describe its current posture, set a target, and close the gap in a shared vocabulary.

Its purpose is the question that follows the moment you know what you run: how well is each of these defended, and where is the risk concentrated. It turns a sensitivity label into a program.

The framework core: six functions

CSF 2.0 organizes cybersecurity into six functions, with Govern wrapping the other five. Each runs on data the estate model already holds. Adapted from the NIST Cybersecurity Framework 2.0.

GV · Govern
Strategy, roles, and risk appetite — wraps the other five
ID · Identify
Know the assets, data, and risks — exactly what the estate model records.
PR · Protect
Safeguards that limit or contain the impact of an event — access control, data security.
DE · Detect
Find events as they happen — monitoring tied to critical systems.
RS · Respond
Act on a detected incident — contain, communicate, mitigate.
RC · Recover
Restore capabilities — ordered by the recovery tier already on each system.

Identify and Recover lean directly on the model: Identify is the estate inventory; Recover follows each system's recovery tier.

Why pair it with HERM

The CSF's first function is Identify — know your assets, data, and risk. That is precisely what the estate model is. Pair them and the framework starts from a real inventory instead of a blank page, and security posture attaches to systems that already carry sensitivity and criticality.

Identify is the estate model

The asset and data inventory the CSF asks for is the catalog you have already built.

Protect from classification

Each system's data classification sets how strongly it must be protected — no separate risk survey.

Recover from criticality

The recovery tier already on each system is the restoration order the Recover function needs.

Components to add

Extending the model toward the CSF means adding a security-posture layer to each record. A pragmatic starting set:

Current vs. target profile

Where each system stands against each CSF function today, and where it needs to be.

Control coverage

Which safeguards apply to a system — access control, encryption, monitoring, backup.

Risk rating

Likelihood and impact per system, informed by its classification and criticality.

Detection & monitoring

Whether a system is actively monitored, and by what.

Incident history

Past events touching a system — the evidence trail for Respond and Recover.

Compliance mapping

Which regulations or policies each system must satisfy.

In practice

Start with the most sensitive systems the model already flags. Rate each against the six functions, and the gap between current and target posture becomes a prioritized security roadmap — anchored to the systems that would hurt most if they failed.

The NIST Cybersecurity Framework is published by the U.S. National Institute of Standards and Technology. This page describes how it complements HERM; profiles, ratings, and control coverage are local extensions.

← Back to Extending the model