Framework Profile
A Framework Profile is a customized selection of cybersecurity outcomes that an organization chooses from a broader framework to match its own business needs, risk tolerance, and resources. It shows which of the framework's goals an organization is focusing on, rather than treating every possible outcome as equally relevant. In this way, a Profile helps tailor a general framework to a specific system or organization.
In the context of the NIST Cybersecurity Framework, a Framework Profile is a representation of the outcomes that a particular system or organization has selected from the Framework Categories and Subcategories. It reflects the alignment of the Framework's Functions, Categories, and Subcategories with an organization's business requirements, risk tolerance, and resources. More generally, in NIST usage a profile defines conforming subsets or combinations of base standards used to provide specific functions; organizations may develop Profiles to describe a current state or a target state, or to address a defined focus area (for example, a sector- or technology-specific application). This entry does not cover implementation specifics, tooling, or the internal structure of any particular published profile, which varies by framework version and use case.
Why it matters
A general cybersecurity framework such as the NIST Cybersecurity Framework presents a broad set of outcomes across its Functions, Categories, and Subcategories. Without a mechanism to prioritize, an organization can be left treating every outcome as equally applicable, which rarely matches its actual business requirements, risk tolerance, or available resources. A Framework Profile addresses this by representing the specific subset of outcomes an organization has selected, making explicit where it is focusing effort and where a given outcome may be less relevant to its context.
Profiles also give organizations a common way to describe the difference between where they are and where they intend to be. Because a Profile can express a current state or a target state, it can support gap analysis and help stakeholders reason about the alignment between framework outcomes and organizational objectives. This tailoring matters because cybersecurity obligations and risk exposures vary considerably by sector, technology, and organizational context, and a single undifferentiated application of a framework does not reflect those differences.
Profiles can further be scoped to a defined focus area, such as a sector- or technology-specific application. For example, NIST has developed profile-style guidance addressing AI-related cybersecurity risk, organized around distinct focus areas. This illustrates how the Profile concept extends the framework to particular domains without changing the underlying framework structure. Note that this entry does not address implementation specifics or the internal structure of any particular published profile, which varies by framework version and use case.
Who it's relevant to
Inside Framework Profile
Common questions
Answers to the questions practitioners most commonly ask about Framework Profile.
