Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Align and prioritize cybersecurity activities

Within the NIST CSF application, the Framework Profiling section is used to help an organization to align and prioritize its cybersecurity activities with its requirements, risk tolerances, and resources.

First, a target is created from a entity or entity type. The application flow begins at Orient Targets. The user locates a target and sets it up for use with NIST CSF providing basic information. Next, the user identifies if the target is critical and establishes a tier for the target per NIST guidelines.

Note: NIST recommends focusing on critical targets for prioritizing the Cybersecurity risks.

Next, users log their cybersecurity activities. The activities require users to identify targets, functions, and categories that are associated with it.

Note: These activities are uniquely created to avoid creating duplicate activities for the same targets.

As the activities are created, users then determine the implementation state of these activities.

Next, users perform gap analysis on the cybersecurity activities. The analysis gives a detailed insight into the security position and evaluates the target for a specific cybersecurity activity.

The ServiceNow® GRC suite of applications play a crucial role in tracking the data that enables these metrics. The NIST CSF application is designed to provide the Cybersecurity framework, but it is completely enabled by the ServiceNow® GRC product.

  • Generate a target for an entity
    Generate a target record for an entity to track NIST CSF attributes for that entity.
  • Set up target for NIST CSF framework
    Set up a target record to use with NIST CSF framework after you've identified a target.
  • Orient target
    After you've identified a target, orient the target to use with the NIST CSF framework.
  • Create activity
    Create a cybersecurity activity for a target.
  • Perform gap analysis
    Perform a Gap analysis of cybersecurity activities.
  • Review action plan
    Review the remediation tasks created for the controls or risks associated with cybersecurity activities. You can only edit or update action plans if you have sufficient privileges for the GRC suite.

Parent Topic:NIST CSF process overview