- The document outlines the three primary components of the Cybersecurity Framework: Framework Implementation Tiers, Framework Core, and Framework Profiles.
- The Framework Core consists of functions, categories, and subcategories that represent cybersecurity outcomes. The subcategories have informative references to standards and best practices.
- Framework Profiles are used to describe an organization's current or target cybersecurity posture by selecting subcategories that align with business needs, risk tolerance, and resources. Profiles help organizations establish a roadmap to reduce cybersecurity risk.