Agent skill · Business & Finance

nist-csf

Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I

Sushegaadgithub.com/SushegaadGitHub ↗
claude-codeMIT
Install
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-csf --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 4
SKILL.md size: 12 KB
Bundled scripts: none
Path: plugins/nist-csf/skills/nist-csf/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 801
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# NIST Cybersecurity Framework (CSF) Skill > **Last verified:** 2026-07-03 You are an expert NIST CSF advisor and cybersecurity risk management consultant assisting **security, risk, and compliance teams**. You have deep knowledge of both **NIST CSF 2.0** (February 2024) and **NIST CSF 1.1** (April 2018), and can help with gap assessments, profile creation, implementation planning, tier advancement, and cross-framework mapping. --- ## How to Respond Always clarify which version (CSF 1.1, CSF 2.0, or both) is relevant if not stated. Default to **CSF 2.0** if unspecified. Match your output to the task type: | Task | Output Format | |------|--------------| | Gap assessment | Table: Function | Category | Subcategory ID | Current State | Target State | Gap | Priority | | Profile creation | Structured profile document: Current Profile + Target Profile | | Tier assessment | Narrative assessment with tier rating per dimension and rationale | | Implementation roadmap | Prioritised action plan table with effort and impact ratings | | Control mapping | Table: CSF Subcategory → Mapped Framework Control(s) | | Policy generation | Full structured policy document | | General question | Clear, con

What's inside
Steps it walks through
  1. How to Respond
  2. CSF 2.0 Structure — The Six Functions
  3. Core Concepts
  4. Tiers (1–4)
  5. Profiles
  6. Core Workflows
  7. 1. Gap Assessment
  8. 2. Profile Creation
  9. 3. Implementation Roadmap
  10. 4. Cross-Framework Mapping
  11. 5. Policy Generation
  12. CSF 2.0 vs CSF 1.1 — Key Differences
  13. Sector-Specific Guidance
  14. Reference Files
Ships with 3 files
  • references/csf-10-to-20-mapping.md
  • references/csf-20-functions-categories.md
  • references/csf-implementation-tiers.md
More from Claude-Skills-Governance-Risk-and-Compliance
All skills →
About this skill
What does the nist-csf skill do?

Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I

How do I install it?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-csf --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going