Install any skill in seconds. Free to start, no credit card required.
Get Started Free →NIST Cybersecurity Framework 2.0 implementation, assessment, and compliance management. Use for CSF 2.0 gap analysis, cybersecurity risk management, maturity assessment, CSF profiles, and cross-framework compliance mapping.
.claude/skills/borghei-nist-csf-specialist/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | 14% | 0% |
| case-01 | ✗→✓ | ▲ Improved | -25% | 0% |
| case-02 | ✗→✓ | ▲ Improved | -23% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 41% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -15% | 0% |
Implement, assess, and manage cybersecurity programs aligned with the NIST Cybersecurity Framework 2.0 — the definitive standard for organizational cybersecurity risk management. CSF 2.0 (Feb 2024) applies to all organizations and adds GOVERN as a sixth, top-level function alongside IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER.
Use this skill when you hear: "NIST cybersecurity framework", "CSF 2.0", "NIST compliance", "cybersecurity risk management", "NIST controls", "NIST assessment", "cybersecurity maturity", "NIST CSF profile", "cybersecurity governance", "cybersecurity program assessment", "CSF gap analysis", or "cross-framework compliance mapping".
Before running the assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the maturity report.
bash# Assess cybersecurity maturity against a target tier python scripts/csf_maturity_assessor.py --input assessment.json --target-tier 3 --output maturity_report.json # Map controls across frameworks python scripts/csf_control_mapper.py --source-framework nist-csf --target-framework iso27001 --output mapping.json # Generate a markdown gap analysis python scripts/csf_maturity_assessor.py --input assessment.json --target-tier 4 --format markdown --output gap_analysis.md # Build a multi-framework unified matrix python scripts/csf_control_mapper.py --source-framework nist-csf --target-framework all --output unified_matrix.json
Load the reference that matches the task — keep this file lean and pull detail on demand:
In Scope:
Out of Scope:
| Skill | Integration | |-------|------------| | soc2-compliance-expert | SOC 2 TSC maps directly to CSF functions; use the control mapper to generate a unified control matrix reducing dual-audit burden | | information-security-manager-iso27001 | ISO 27001 Annex A controls are the implementation backbone for CSF categories; CSF maturity scores inform ISMS continual improvement | | infrastructure-compliance-auditor | Validates technical controls (access, encryption, monitoring, endpoints) that underpin PROTECT and DETECT function scores | | pci-dss-specialist | PCI-DSS v4.0 requirements map to CSF categories; use cross-framework mapper for payment environments | | nis2-directive-specialist | NIS2 Article 21 measures align to CSF functions; CSF maturity assessment benchmarks NIS2 compliance posture | | dora-compliance-expert | DORA ICT risk management pillars map to GOVERN and IDENTIFY functions; use CSF as the unifying assessment framework |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-03 | fail→pass | 11,035 | 3,280 | -70% | 1 | 1 | 0% | 1,808 | 2,055 | +14% | 0 | 0 | — |
case-01 | fail→pass | 21,694 | 10,539 | -51% | 1 | 1 | 0% | 4,550 | 3,424 | -25% | 0 | 0 | — |
case-02 | fail→pass | 15,973 | 5,811 | -64% | 1 | 1 | 0% | 3,367 | 2,579 | -23% | 0 | 0 | — |
case-04 | fail→pass | 10,327 | 4,753 | -54% | 1 | 1 | 0% | 1,626 | 2,299 | +41% | 0 | 0 | — |
case-05 | fail→pass | 18,438 | 6,994 | -62% | 1 | 1 | 0% | 3,060 | 2,615 | -15% | 0 | 0 | — |
case-06 | pass→pass | 30,658 | 29,990 | -2% | 1 | 1 | 0% | 3,522 | 6,747 | +92% | 0 | 0 | — |
case-07 | pass→pass | 11,289 | 11,544 | +2% | 1 | 1 | 0% | 1,859 | 3,447 | +85% | 0 | 0 | — |
case-08 | pass→pass | 3,628 | 3,275 | -10% | 1 | 1 | 0% | 589 | 2,011 | +241% | 0 | 0 | — |
case-09 | fail→pass | 11,098 | 3,879 | -65% | 1 | 1 | 0% | 1,860 | 2,172 | +17% | 0 | 0 | — |
case-10 | fail→pass | 14,603 | 3,342 | -77% | 1 | 1 | 0% | 2,400 | 1,991 | -17% | 0 | 0 | — |
case-11 | fail→pass | 7,982 | 7,852 | -2% | 1 | 1 | 0% | 1,196 | 2,886 | +141% | 0 | 0 | — |
case-12 | fail→pass | 14,623 | 3,372 | -77% | 1 | 1 | 0% | 2,433 | 2,061 | -15% | 0 | 0 | — |
case-13 | fail→pass | 10,794 | 3,870 | -64% | 1 | 1 | 0% | 1,749 | 2,199 | +26% | 0 | 0 | — |
case-14 | fail→fail | 19,783 | 16,279 | -18% | 1 | 1 | 0% | 3,298 | 4,470 | +36% | 0 | 0 | — |
case-15 | pass→pass | 18,657 | 16,984 | -9% | 1 | 1 | 0% | 3,167 | 4,561 | +44% | 0 | 0 | — |
case-16 | pass→pass | 16,027 | 12,380 | -23% | 1 | 1 | 0% | 2,395 | 3,421 | +43% | 0 | 0 | — |
case-17 | pass→pass | 7,363 | 7,433 | +1% | 1 | 1 | 0% | 1,535 | 2,900 | +89% | 0 | 0 | — |
case-18 | fail→pass | 16,406 | 12,677 | -23% | 1 | 1 | 0% | 2,632 | 3,696 | +40% | 0 | 0 | — |
case-19 | fail→fail | 24,714 | 18,778 | -24% | 1 | 1 | 0% | 3,909 | 4,548 | +16% | 0 | 0 | — |
case-20 | pass→pass | 11,059 | 9,391 | -15% | 1 | 1 | 0% | 1,680 | 2,994 | +78% | 0 | 0 | — |
case-21 | pass→pass | 12,707 | 10,630 | -16% | 1 | 1 | 0% | 1,994 | 3,138 | +57% | 0 | 0 | — |
case-22 | fail→pass | 18,681 | 7,250 | -61% | 1 | 1 | 0% | 2,927 | 2,709 | -7% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +55 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.