Enter your keyword

← All Projects  ›  NIST CSF Implementation Workbook - v1.1 & v2.0
Project 07 - NIST CSF Implementation

NIST CSF Implementation Workbook - v1.1 & v2.0

108 Subcategories · Govern Function · Evidence Register

Designed and built a comprehensive NIST CSF 2.0 implementation workbook covering all six functions including the new Govern function - used as the governance instrument for the flagship program build.

NIST CSF 2.0108 subcategoriesGovern functionISO 27001 mapped37 evidence artifactsBoard dashboard
108
Subcategories covered
6
CSF 2.0 functions
37
Evidence artifacts
2
Framework versions
The Challenge
Problem Statement

The flagship program build (Project 00) required a rigorous assessment and governance instrument that could track maturity across the full NIST CSF, map to ISO 27001 controls, generate gap analysis automatically, and produce board-presentable output. Commercial GRC platforms were out of budget. NIST CSF 1.1 had just been superseded by version 2.0, which added the Govern function - meaning off-the-shelf workbooks were already outdated.

The Approach
How I Solved It

I built a comprehensive Excel-based implementation workbook from scratch covering NIST CSF v1.1 (five functions, 108 subcategories) and v2.0 (six functions including Govern). Each subcategory has a maturity score (1–5), implementation status, responsible owner, target date, and evidence artifact reference. The workbook includes automated gap analysis generating a prioritized remediation roadmap, cross-reference columns mapping to ISO 27001:2022 Annex A controls, a board-presentable executive dashboard showing function-level maturity scores and trend, and a 37-item evidence register linking each artifact to the subcategories it satisfies.

Frameworks & Standards
NIST CSF 2.0 (all 6 functions)
NIST CSF v1.1
ISO 27001:2022
NIST SP 800-53 Rev 5
Tools & Platforms
Microsoft Excel · NIST CSF 2.0 · ISO 27001:2022 · Power Query · Conditional formatting
Category
GRC · NIST CSF 2.0 · Governance Tool
What Was Delivered
Outcomes & Results
Complete NIST CSF 2.0 implementation workbook built covering all six functions including the new Govern function
108 subcategories covered with maturity scoring, ownership assignment, and evidence linking
37 evidence artifacts catalogued and mapped to the subcategories they satisfy
Automated gap analysis and remediation roadmap generated from maturity scores
ISO 27001:2022 Annex A cross-reference enabling concurrent framework assessment
Board-presentable executive dashboard showing function-level maturity and trajectory
Used as the governance instrument underpinning the flagship OCC-examined program build
Key Lesson
The Govern function in CSF 2.0 is not just a new category - it is the foundation that contextualizes every other function. Organisations that assess Identify through Recover without assessing Govern are measuring controls without measuring accountability. The workbook revealed that Govern consistently scores lower than the other five functions in initial assessments - which is the right finding, because it drives the board governance improvement work that makes everything else sustainable.
// Evidence artifact - downloadable
Documented. Verifiable. Downloadable.
This project has a corresponding evidence artifact available in the Evidence Vault.