Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. NIST CYBERSECURITY FRAMEWORK
  3. NIST Cybersecurity Framework implementation

NIST CYBERSECURITY FRAMEWORK

What the CSF produces is the distance between two points

Where your company stands today and where the board decided it needs to stand. That difference, measured with method and revisited over time, is the only honest answer to the question every board asks and almost no security function can answer without a forty-page deck.

Talk to a specialistSee the other standards

The NIST CSF is a public framework adopted voluntarily. What DM11 delivers is the assessment, both profiles, the plan and the tracking routine, which is what answers the board. Where the goal also includes a document to send a customer, the ISO 27001 or SOC 2 pages explain that route, and the two pieces of work support each other.

Who runs the implementation

  • ISO/IEC 27001 Lead Auditor certified by BSI

  • CISA, information systems auditing

  • Specialists in risk management and business continuity

  • 17 years of governance, risk and compliance

WHAT IT IS

A common language between the people who operate and the people who decide

The Cybersecurity Framework is published by the United States standards and technology institute, and has been at version 2.0 since 26 February 2024. It organises security into functions, categories and subcategories, and each subcategory describes an outcome to reach. It is neither a certifiable standard nor a technical manual: it is the structure that lets you track security over time in vocabulary a board understands.

There are six functions, and the newest is govern

Identify, protect, detect, respond and recover already existed. Version 2.0 added govern, and placed it at the centre of the other five. The change has a practical consequence: govern deals with who decides, who answers and what the company's risk appetite is, which is precisely what was missing while the framework described activity without describing accountability. If the material you hold shows five functions, it belongs to the previous version.

The subcategories state the outcome, not the product

There are 22 categories and 106 subcategories, and each describes what has to be true without saying which technology gets you there. That is deliberate and it is the framework's greatest strength: it does not age alongside the tooling market, and no vendor can use it to argue that their product is mandatory.

The work becomes two profiles, and the gap between them

The current profile records where the company stands, subcategory by subcategory. The target profile records where it decided to stand, which is not the same as the maximum available. The distance between the two is the plan, the budget and the thing you put in front of the board. No other reference on this page produces that artefact.

The four tiers, and what they actually measure

The four tiers describe how rigorously a company governs and manages risk, and choosing a tier is a decision about risk appetite and resources, not a ladder to climb for sport. Most companies cannot justify the highest tier, and treating it as the target is the most common misreading. Because the framework is adopted voluntarily, it produces no certificate of conformity, which is why its value shows in the tracking over time.

WHO USUALLY NEEDS IT

Three situations where the CSF is the right tool

Note that none of them ends in a certificate. The CSF solves tracking and conversation; where the problem is proving something to a third party, the route is a different standard.

The board asks whether we are secure

And today the answer is a long presentation nobody can turn into a decision. With both profiles built, the question gets a one-page answer, with a measured distance and a cost attached to closing it, which is the format boards decide in.

There are several security efforts and no view of the whole

Penetration testing on one side, data protection work on another, a continuity project stalled somewhere in the middle and tools bought at different moments. The CSF is the umbrella that shows what those efforts cover together, and above all what none of them covers.

The parent company or a customer asked for NIST alignment

Common in subsidiaries of US companies and among suppliers to regulated sectors. The request usually arrives without detail, and the first useful deliverable is translating what it means: almost always a documented current profile, not a promise of Tier 4.

STORIES

Three situations we have already worked through

We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.

Financial services

The board's question came back every meeting

Situation

Each quarter the board asked whether the company was secure, and the technology function answered with a long pack full of tool metrics and no thread running through it. The question returned identical the following quarter, because the answer never turned into an investment decision.

What we did

We built the current CSF profile and ran a session with the executive team to define the target profile, function by function. The discussion was about risk appetite rather than technology, and it was the first time that group had explicitly stated how far it wanted to go on each front.

Outcome

The distance between the two profiles became a single page with a cost attached. The board started discussing how much of the gap to close instead of asking whether it was secure, and the technology function stopped defending a budget with no reference point.

Subsidiary of a multinational

It held ISO 27001 and the gap was in recover

Situation

The parent company asked for CSF alignment. The Brazilian operation held a current ISO 27001 certificate, and the internal reading was that the request was already satisfied: send the certificate and close the matter.

What we did

We mapped the existing controls against the six functions. Identify, protect and detect came out strong, as you would expect from a certified management system. Respond looked reasonable on paper and had never been exercised, and recover was practically empty: there were backups and there was no business resumption plan.

Outcome

The certificate did not answer the request, and that became clear in two weeks rather than after six months of misunderstanding with the parent company. The project that came out of it was continuity, which was the real gap, rather than one more security control.

Logistics

After the incident, they bought detection

Situation

The company suffered a serious incident and reacted by investing heavily in detection tooling, which was where the pain had been felt. A year later, with the money spent, nobody could say whether the company would hold up better against the same event.

What we did

We ran the assessment across the six functions and the wheel came out visibly lopsided: detect well above everything else, respond with no tested procedure, and recover with no defined timeframe for anything. We showed that the next unit of budget bought more outside detection than inside it.

Outcome

The incident had bought the right tool for the wrong problem. The company carried on detecting well and gained an answer for what to do after detecting, which was exactly what had been missing the first time.

HOW WE RUN IT

Current profile, target profile, and the plan that closes the gap

The step that separates this from an ordinary assessment is the second one. The target profile is not set by technology: it is an executive decision about risk appetite, and running that conversation is part of the delivery, because a target profile set by IT alone does not survive the first budget cut.

  1. 01

    Scope, context and the govern function

    We define what enters the assessment and start with govern, which is where version 2.0 placed the centre. Who decides on risk, who answers for each front, what has been formally decided and what exists only by habit. Without that, the rest of the assessment becomes a picture with no owner.

    • Assessment scope defined, with the units included

    • A map of who decides and who answers for each front

    • A record of what is a formal decision and what is informal practice

    • Stakeholders identified, inside and outside the company

    Delivery milestoneScope approved and accountability defined for each of the six functions.

  2. 02

    Current profile, subcategory by subcategory

    We assess the 106 subcategories against evidence, through interviews and verification, accepting no positive answer without proof. The result is a picture of the current state by function and by category, in the form that allows comparison later.

    • A documented current profile, subcategory by subcategory

    • Evidence attached to every positive assessment

    • A reading by function, with the asymmetries visible

    • Reuse of whatever exists from ISO 27001, CIS or earlier projects

    Delivery milestoneCurrent profile closed, with evidence for every subcategory assessed as met.

  3. 03

    Target profile, decided by the executive team

    We run the session where leadership defines where it wants to be, function by function, against risk appetite, contractual obligation and available resources. We bring sector reference points into the conversation, but the decision belongs to the company, and it has to be taken by whoever signs the budget.

    • A target profile defined and signed off by leadership

    • A tier chosen per category, with the rationale recorded

    • The distance between the two profiles quantified

    • Priorities set against risk and against cost

    Delivery milestoneTarget profile approved by leadership, with a recorded rationale for every choice.

  4. 04

    Plan, execution and the routine that keeps the number alive

    We turn the distance into a plan with owners and dates, executed with your team. And we set the reassessment cadence, because the CSF's value shows up on the second measurement rather than the first: an isolated picture shows no direction at all.

    • A closure plan with an owner and a date per item

    • Execution supported, with periodic progress review

    • Board-facing tracking material, free of jargon

    • A reassessment cadence defined, with who runs it and when

    Delivery milestoneSecond measurement completed with the same method, showing the direction of travel.

HOW LONG IT TAKES

The assessment is quick. Deciding the target is what tends to stall.

We do not publish a standard timeline, because a published timeline turns into a promise. There is a particularity here worth saying up front: gathering the current profile takes a predictable amount of time, and what stretches the project is almost always the executive calendar for deciding the target profile. These are the three factors that move the clock most.

How many units, and how many profiles

A single operation is one profile. A group with businesses of different kinds usually needs more than one, because the risk appetite of a manufacturer and of a finance arm in the same group are not the same, and forcing a single profile produces a number that serves neither.

Whether leadership takes part in setting the target

With calendar time secured, that stage takes weeks. When it is delegated to IT, the project moves faster and delivers less, because the target profile becomes a technical opinion rather than a business decision, and it will not carry a budget.

What has already been measured

A company holding a current ISO 27001 certificate, or with the CIS Controls implemented, assembles the current profile far faster, because the evidence already exists and only needs rereading in the CSF's structure. With nothing measured, the gathering is the longest stretch.

FREQUENTLY ASKED

What people ask before deciding

The questions that come up in almost every first meeting, answered straight.

No. The framework is voluntary, NIST issues no certificate of conformity and accredits nobody to issue one. There is a market selling what it calls NIST CSF certification: what gets delivered there is a third-party assessment report, which is legitimate and useful, and is not a recognised certificate. If your customer needs a document carrying third-party weight, the route is ISO 27001 or SOC 2.

Need to answer the board with more than a presentation?

The assessment across the six functions shows where your company stands and where the gaps concentrate. The next conversation, with your leadership, sets where it needs to stand. The distance between those two things is what becomes the plan.

Talk to a specialist

Comparisons on this subject

  • ISO 27001 vs NIST CSF
  • CIS Controls vs ISO 27001
  • ISO 42001 vs NIST AI RMF
See all 13 comparisons