Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideCreate Organizational Profiles, assess Current and Target outcomes across the complete CSF 2.0 Core, reuse PurpleWASP Controls, analyse gaps, plan improvements, record Implementation Tiers and report progress.
PurpleWASP implements the complete CSF 2.0 Core with 6 Functions, 22 Categories and 106 Subcategory outcomes. The workspace uses Organizational Profiles to compare the organisation's Current and Target position, connects applicable outcomes to shared PurpleWASP Controls and assurance records, and turns gaps into owned improvement work.
| Workspace | Purpose |
|---|---|
| Profile & Scope | Create multiple Organizational Profiles and define the business/system/service/custom boundary. |
| Current & Target | Record applicability, Current state, Target state, priority and management notes for CSF outcomes. |
| CSF Core | Browse/search Govern, Identify, Protect, Detect, Respond and Recover down to the 106 outcomes. |
| Gap Analysis | Identify applicable outcomes where Target is above Current and review mapped-Control context. |
| Improvement Plan | Create owned, dated actions linked to one or more Profile outcomes. |
| Implementation Tiers | Record Current/Target Tier 1–4 with rationale and evidence summary. |
| Reports | Present Profile context, Function roll-ups, gaps, assurance drivers, Tiers and improvement actions. |
Create a Profile for the organisation, business unit, system, service or other bounded context you want to assess. PurpleWASP supports multiple Profiles so different environments do not need to be forced into one enterprise-wide view.
When a Profile is created, PurpleWASP seeds the CSF outcomes so the assessment starts from the full Core rather than a manually assembled list.
For each applicable Subcategory, record the organisation's Current state, Target state, priority and notes. Use the Target Profile to express the desired outcome rather than simply marking every item as 100%.
The CSF Core browser organises the complete outcome set under the six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Use search/filter to locate a requirement and then review the selected organisation-Control coverage and Profile context.
NIST does not create a second copy of the organisation's Controls. PurpleWASP uses the shared canonical/control-mapping architecture so a Control that already supports ISO 27001, SOC 2 or another framework can also support the relevant NIST outcome.
The Current & Target workspace can surface:
The NIST workspace does not silently create or rewrite organisation Controls. Control Management remains authoritative.
Gap Analysis focuses on applicable outcomes where the Target state is above the Current state. Use priority and assurance context to distinguish strategic gaps from outcomes that are already supported by strong Controls but have not yet been reassessed.
Create improvement actions directly from identified gaps or from the Improvement Plan workspace. Assign owner, priority, due date, status, expected benefit and notes, and link each action to the outcomes it is intended to improve.
Record the Current and Target Implementation Tier with rationale, governance notes, risk-management notes and evidence summary. PurpleWASP keeps the four Tiers—Partial, Risk Informed, Repeatable and Adaptive—separate from the Profile percentage visualisation.
The dashboard and report views summarise Current/Target Profile state by Function and show operational drivers such as outcomes with no selected Controls, Controls not fully implemented, missing current evidence and open Control issues. Use those drivers to navigate back to the records that need work.
NIST CSF 2.0 is not treated as a certification scheme inside PurpleWASP. The Current/Target percentages are PurpleWASP internal visualisations of the Profile assessment states; they are not NIST compliance, certification, conformance or maturity scores. Implementation Tiers are also not converted into percentages.
Use the first-time handbook for organisations adopting NIST CSF 2.0 and the technical guide for PurpleWASP developers, administrators and implementation partners.
Download the NIST CSF 2.0 first-time implementation handbook
Review the canonical suggestions and the organisation's existing Controls. If an appropriate Control exists, explicitly map it; otherwise use Control Management to determine whether a new/adopted Control is needed.
Current state is an explicit Profile assessment. Review the Control assurance context, then update the outcome assessment when management concludes the outcome is being achieved.
Gap Analysis compares Current with Target. Confirm the Target represents the desired cybersecurity outcome rather than changing it only to remove a gap.