A hospital uses NIST CSF 2.0 to report cybersecurity posture to its board — what do Current and Target Profiles and the Tiers each express?
answer
- where we are, where we aim
- gap analysis feeds an action plan
- Partial to Adaptive
- rigor of practices, not a score
basics
~20 sUnder NIST CSF 2.0, a Current Profile states which Core outcomes the hospital achieves and how far; a Target Profile states the outcomes it has chosen to reach. Tiers 1-4 characterize how rigorous its risk governance and management practices are.
solid answer
~40 sIn NIST CSF 2.0 an **Organizational Profile** contains a **Current Profile** (the Core outcomes the organization achieves now, and to what extent), a **Target Profile** (the outcomes it has selected and prioritized, allowing for new requirements and threats), or both. The board story is the **gap** between them and a prioritized action plan such as a risk register or POA&M. A sector **Community Profile** can seed the Target. The **Tiers** - Partial (1), Risk Informed (2), Repeatable (3), Adaptive (4) - describe the rigor of the hospital's cybersecurity risk *governance and management practices*. CSF 2.0 says Tiers complement, not replace, a risk methodology, and encourages moving up only when risks or mandates are greater or cost-benefit supports it.
go deeper
Recall the two Profile types, Current and Target, and the four Tier names from Partial to Adaptive.
Explain the gap analysis between Profiles, how it produces an action plan, and why Tiers describe practice rigor rather than outcome coverage.
Show how you would scope Profiles for a hospital, seed the Target from a Community Profile, and defend a Tier target by risk and cost instead of defaulting to Tier 4.
Discuss how Profiles and Tiers become a board-level instrument: what gets funded, how progress is evidenced, and where regulatory duties sit outside the CSF.
## The reporting problem A hospital's board wants to know two things: how exposed the organization is and whether spending is moving it in the right direction. **NIST CSF 2.0** (CSWP 29, February 2024) offers two tools for this, and interviewers check that a candidate keeps them apart: **Organizational Profiles** and **Tiers**. ## Organizational Profiles An **Organizational Profile** describes the organization's current and/or target cybersecurity posture in terms of the CSF Core outcomes. Every Organizational Profile includes one or both of: - **Current Profile** - the Core outcomes the organization is currently achieving (or attempting to achieve), and how or to what extent each is being achieved. - **Target Profile** - the desired outcomes the organization has selected and prioritized for its cybersecurity risk management objectives. It considers anticipated changes such as new requirements, new technology adoption and threat intelligence trends. A **Community Profile** is different: a baseline of CSF outcomes created and published for shared interests among many organizations, typically for a sector, subsector, technology or threat type. An organization may use a Community Profile as the basis for its own Target Profile, so a hospital can start from a healthcare-sector profile rather than from a blank sheet. NIST sketches one way to use a Profile: 1. **Scope** the Organizational Profile (the whole hospital, or only its clinical systems, or ransomware against those systems). 2. **Gather** information: policies, risk priorities, business impact analyses, requirements and standards followed. 3. **Create** the Profile, considering the risk implications of the Current Profile when setting the Target. 4. **Analyze gaps** between Current and Target, and build a prioritized action plan such as a risk register, risk detail report or **Plan of Action and Milestones (POA&M)**. 5. **Implement** the plan and update the Profile, repeating as often as needed. For the board, the gap and the plan are the report: which outcomes matter most, which are unmet, and what is funded to close them. A Current Profile can also be shown to partners or prospective customers, and a Target Profile can express expectations to suppliers. ## Tiers **Tiers** characterize the **rigor of an organization's cybersecurity risk governance and management practices**. Each Tier is described along two columns, risk governance and risk management: | Tier | Name | Governance picture (abridged) | |---|---|---| | 1 | Partial | Strategy applied ad hoc; prioritization not formally based on objectives or threats | | 2 | Risk Informed | Practices approved by management but may not be organization-wide policy | | 3 | Repeatable | Practices formally approved and expressed as policy, regularly updated | | 4 | Adaptive | Organization-wide, risk-informed approach; executives weigh cyber risk like financial risk | Two statements in CSF 2.0 decide how Tiers should be used: - Tiers **complement** an organization's risk management methodology rather than replace it. - **Progression** to higher Tiers is encouraged when risks or mandates are greater, or when a cost-benefit analysis shows a feasible, cost-effective reduction of risk. Tier 4 is not declared a universal goal. An organization can choose to use Tiers to inform its Current and Target Profiles, for example stating that it runs at Tier 2 today and targets Tier 3. ## Common mistakes in board reporting - **Averaging Subcategories into one number** and calling it the Tier. Tiers describe practices across governance and management, not a percentage of outcomes met. - **Treating a Community Profile as a regulation.** It is a published baseline the hospital may adopt, not a legal mandate from the CSF. - **Claiming CSF certification.** The CSF defines no certificate; a hospital reports alignment and progress, while any legal duties (for example the HIPAA Security Rule) come from their own regimes. - **Setting Tier 4 everywhere.** The CSF ties higher Tiers to risk, mandates and cost-benefit, so a target should be argued, not assumed. One practical tip: report the Current and Target Profiles by Function, so the board sees Govern and Recover gaps next to Protect gaps instead of a single blended figure. A strong answer names both tools, keeps Profiles (what outcomes) separate from Tiers (how rigorous the practices), and shows how the gap analysis becomes a funded plan the board can track.
- Can a hospital have more than one Organizational Profile?Yes. NIST CSF 2.0 says an organization can have as many Organizational Profiles as it wants, each with its own scope - for example one for the whole enterprise and another for ransomware affecting clinical systems.
- How does a Community Profile relate to a Target Profile?A Community Profile is a published baseline of outcomes for shared interests, such as a sector. Under CSF 2.0 an organization may use it as the basis for its own Target Profile, then tailor it to its own risks.
A Profile is a route map showing where the hospital is and where it has chosen to go; the Tier describes how disciplined the driving is. Better driving does not change the destination, and not every trip needs a racing driver.
saying these in an interview costs you the question
- Calls the Tier a score computed from Subcategories met
- Says every organization must aim for Tier 4 Adaptive
- Treats a Community Profile as a legally binding requirement
- Confuses the Current Profile with the Target Profile
- Claims the board report certifies the hospital against the CSF