RAKSHA

NIST CSF 2.0 — Cybersecurity Framework Advisor

← Hub NIST CSF 2.0 v1.0

Client Profile

Foundation Building Required: Tier 1 (Partial) organizations have ad hoc cybersecurity practices. Significant effort needed to establish formal risk management processes, governance structures, and repeatable practices.
WHY

NIST Cybersecurity Framework (CSF) is the most widely adopted security framework globally. Even in India, organizations use NIST CSF to structure their cybersecurity programs — especially those serving US clients or seeking alignment with international best practices. NIST provides the language for boards and CISOs to discuss cyber risk consistently.

WHAT

NIST CSF 2.0 organizes cybersecurity into 6 functions — Govern, Identify, Protect, Detect, Respond, and Recover. Each function contains categories and subcategories that map to specific security controls. NIST also provides implementation tiers (Partial, Risk Informed, Repeatable, Adaptive) to measure maturity.

HOW

We assess your current cybersecurity posture against NIST CSF, identify gaps at each function level, and build a prioritized remediation roadmap. We help establish governance structures, implement controls, and measure maturity over time. Typical advisory: ₹6-25 lakh depending on assessment depth.

Available OEM Vendors (9)

1

IBM

GRC & QRadar — OEM 360: 95 · Platinum · grc:silver

2

OPTIZ

GRC Platform — OEM 360: 94 · Platinum · grc:platinum

3

CrowdStrike

Endpoint & Threat Intel — OEM 360: 93 · Platinum

4

Microsoft

Sentinel & Compliance — OEM 360: 70 · Silver

5

SAFE Security

Cyber Risk Quantification — OEM 360: 69 · Silver · grc:silver

6

Qualys

Cloud Security & Compliance — OEM 360: 64 · Silver

7

Tenable

Vulnerability & Risk Management — OEM 360: 60 · Silver

8

RSA

Archer GRC Platform — OEM 360: 47 · Bronze · grc:bronze

9

Scrut Automation

Compliance Automation — OEM 360: 37 · Bronze · grc:bronze

Vendor-neutral. Customer-first. We recommend what you need — nothing more.

Compliance Dashboard
Overall Compliance Score 0%
0
Compliant
0
In Progress
0
Not Started
0
Non-Compliant
Critical Domains Loading...
High Priority Domains Loading...
Compliance Requirements — 6 Domains
Solution Mapping Matrix
NIST CSF 2.0 Requirement → Raksha Domain Advisor Mapping
NIST CSF 2.0 DomainEDREmailNGFWSIEMZTIAMDLPCloudDevSecBackupGRCNetMDR
GV. Govern
ID. Identify
PR. Protect
DE. Detect
RS. Respond
RC. Recover
Implementation Roadmap
1
Organizational Profile
Weeks 1–4
  • Establish organizational context and scope
  • Create Current Profile (as-is assessment)
  • Define Target Profile (desired state)
  • Gap analysis between Current and Target profiles
  • Prioritize improvement actions
2
Govern & Identify
Weeks 5–12
  • Governance structure and policy establishment
  • Risk management strategy development
  • Asset inventory and classification
  • Comprehensive risk assessment
  • Supply chain risk management program
3
Protect & Detect
Weeks 13–24
  • Identity and access management deployment
  • Data security controls implementation
  • SIEM and continuous monitoring setup
  • Security awareness training launch
  • Platform hardening and patch management
4
Respond & Recover
Weeks 25–32
  • Incident response plan development and testing
  • Recovery planning and BCP alignment
  • Communication protocols establishment
  • Tabletop exercises and simulations
  • Detection rule tuning and optimization
5
Continuous Improvement
Ongoing
  • Regular profile reassessment
  • Continuous monitoring and threat adaptation
  • Periodic risk reassessment
  • Improvement tracking against Target Profile
  • Annual framework review and maturity advancement
Impact Reference — NIST CSF 2.0
Non-compliance for federal contractors (DFARS/CMMC)Contract termination + False Claims Act liability
Critical infrastructure non-complianceRegulatory enforcement actions
Cyber incident without documented frameworkIncreased liability in litigation
Insurance claim denial due to inadequate controlsFull loss exposure
Customer/partner contract requirement failureBusiness relationship termination
Raksha Technologies
Cybersecurity Procurement Advisory · www.raksha.co.in