skip to content

A hospital uses NIST CSF 2.0 to report cybersecurity posture to its board — what do Current and Target Profiles and the Tiers each express?

level: middleimportance: should knowfreq 42%

answer

  1. where we are, where we aim
  2. gap analysis feeds an action plan
  3. Partial to Adaptive
  4. rigor of practices, not a score

basics

~20 s

Under NIST CSF 2.0, a Current Profile states which Core outcomes the hospital achieves and how far; a Target Profile states the outcomes it has chosen to reach. Tiers 1-4 characterize how rigorous its risk governance and management practices are.

solid answer

~40 s

In NIST CSF 2.0 an **Organizational Profile** contains a **Current Profile** (the Core outcomes the organization achieves now, and to what extent), a **Target Profile** (the outcomes it has selected and prioritized, allowing for new requirements and threats), or both. The board story is the **gap** between them and a prioritized action plan such as a risk register or POA&M. A sector **Community Profile** can seed the Target. The **Tiers** - Partial (1), Risk Informed (2), Repeatable (3), Adaptive (4) - describe the rigor of the hospital's cybersecurity risk *governance and management practices*. CSF 2.0 says Tiers complement, not replace, a risk methodology, and encourages moving up only when risks or mandates are greater or cost-benefit supports it.

go deeper

for a junior

Recall the two Profile types, Current and Target, and the four Tier names from Partial to Adaptive.

for a middle

Explain the gap analysis between Profiles, how it produces an action plan, and why Tiers describe practice rigor rather than outcome coverage.

for a senior

Show how you would scope Profiles for a hospital, seed the Target from a Community Profile, and defend a Tier target by risk and cost instead of defaulting to Tier 4.

for a principal

Discuss how Profiles and Tiers become a board-level instrument: what gets funded, how progress is evidenced, and where regulatory duties sit outside the CSF.

## The reporting problem A hospital's board wants to know two things: how exposed the organization is and whether spending is moving it in the right direction. **NIST CSF 2.0** (CSWP 29, February 2024) offers two tools for this, and interviewers check that a candidate keeps them apart: **Organizational Profiles** and **Tiers**. ## Organizational Profiles An **Organizational Profile** describes the organization's current and/or target cybersecurity posture in terms of the CSF Core outcomes. Every Organizational Profile includes one or both of: - **Current Profile** - the Core outcomes the organization is currently achieving (or attempting to achieve), and how or to what extent each is being achieved. - **Target Profile** - the desired outcomes the organization has selected and prioritized for its cybersecurity risk management objectives. It considers anticipated changes such as new requirements, new technology adoption and threat intelligence trends. A **Community Profile** is different: a baseline of CSF outcomes created and published for shared interests among many organizations, typically for a sector, subsector, technology or threat type. An organization may use a Community Profile as the basis for its own Target Profile, so a hospital can start from a healthcare-sector profile rather than from a blank sheet. NIST sketches one way to use a Profile: 1. **Scope** the Organizational Profile (the whole hospital, or only its clinical systems, or ransomware against those systems). 2. **Gather** information: policies, risk priorities, business impact analyses, requirements and standards followed. 3. **Create** the Profile, considering the risk implications of the Current Profile when setting the Target. 4. **Analyze gaps** between Current and Target, and build a prioritized action plan such as a risk register, risk detail report or **Plan of Action and Milestones (POA&M)**. 5. **Implement** the plan and update the Profile, repeating as often as needed. For the board, the gap and the plan are the report: which outcomes matter most, which are unmet, and what is funded to close them. A Current Profile can also be shown to partners or prospective customers, and a Target Profile can express expectations to suppliers. ## Tiers **Tiers** characterize the **rigor of an organization's cybersecurity risk governance and management practices**. Each Tier is described along two columns, risk governance and risk management: | Tier | Name | Governance picture (abridged) | |---|---|---| | 1 | Partial | Strategy applied ad hoc; prioritization not formally based on objectives or threats | | 2 | Risk Informed | Practices approved by management but may not be organization-wide policy | | 3 | Repeatable | Practices formally approved and expressed as policy, regularly updated | | 4 | Adaptive | Organization-wide, risk-informed approach; executives weigh cyber risk like financial risk | Two statements in CSF 2.0 decide how Tiers should be used: - Tiers **complement** an organization's risk management methodology rather than replace it. - **Progression** to higher Tiers is encouraged when risks or mandates are greater, or when a cost-benefit analysis shows a feasible, cost-effective reduction of risk. Tier 4 is not declared a universal goal. An organization can choose to use Tiers to inform its Current and Target Profiles, for example stating that it runs at Tier 2 today and targets Tier 3. ## Common mistakes in board reporting - **Averaging Subcategories into one number** and calling it the Tier. Tiers describe practices across governance and management, not a percentage of outcomes met. - **Treating a Community Profile as a regulation.** It is a published baseline the hospital may adopt, not a legal mandate from the CSF. - **Claiming CSF certification.** The CSF defines no certificate; a hospital reports alignment and progress, while any legal duties (for example the HIPAA Security Rule) come from their own regimes. - **Setting Tier 4 everywhere.** The CSF ties higher Tiers to risk, mandates and cost-benefit, so a target should be argued, not assumed. One practical tip: report the Current and Target Profiles by Function, so the board sees Govern and Recover gaps next to Protect gaps instead of a single blended figure. A strong answer names both tools, keeps Profiles (what outcomes) separate from Tiers (how rigorous the practices), and shows how the gap analysis becomes a funded plan the board can track.

  • Can a hospital have more than one Organizational Profile?
    Yes. NIST CSF 2.0 says an organization can have as many Organizational Profiles as it wants, each with its own scope - for example one for the whole enterprise and another for ransomware affecting clinical systems.
  • How does a Community Profile relate to a Target Profile?
    A Community Profile is a published baseline of outcomes for shared interests, such as a sector. Under CSF 2.0 an organization may use it as the basis for its own Target Profile, then tailor it to its own risks.

A Profile is a route map showing where the hospital is and where it has chosen to go; the Tier describes how disciplined the driving is. Better driving does not change the destination, and not every trip needs a racing driver.

saying these in an interview costs you the question

  • Calls the Tier a score computed from Subcategories met
  • Says every organization must aim for Tier 4 Adaptive
  • Treats a Community Profile as a legally binding requirement
  • Confuses the Current Profile with the Target Profile
  • Claims the board report certifies the hospital against the CSF