Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: GRC Governance Frameworks

Current Profile

Also known as: As-Is Profile
Simply put

In the context of the NIST Cybersecurity Framework, a Current Profile is a snapshot of the cybersecurity outcomes an organization is presently achieving, essentially a description of where it stands today. Organizations often compare this present-state view against a desired future state (a Target Profile) to identify gaps and prioritize improvements. The evidence packet provided does not contain the primary NIST source text, so the specific wording and framework edition should be verified against official NIST documentation.

Formal definition

Within the NIST Cybersecurity Framework, a Current Profile is commonly understood to represent the 'as-is' alignment of the framework's cybersecurity outcomes with an organization's present activities and results, that is, the outcomes currently being achieved. It typically serves as a baseline that practitioners compare against a Target Profile (the desired future state) to perform gap analysis, prioritize remediation, and inform risk-based resource allocation. The term reflects voluntary framework guidance rather than a binding legal obligation, and its precise definition may vary across framework editions; because the supplied evidence does not include the authoritative NIST glossary text, the exact definitional language and applicable version should be confirmed against the primary NIST Cybersecurity Framework source before use.

Why it matters

A Current Profile matters because it converts an abstract question, "how are we doing on cybersecurity?", into a structured, framework-aligned snapshot that stakeholders can review and act upon. Within the NIST Cybersecurity Framework, this present-state view establishes a common reference point that boards, executives, risk managers, and technical teams can all interpret against the same set of outcomes. Without such a baseline, improvement efforts risk becoming ad hoc, and it becomes difficult to demonstrate whether investments are actually closing meaningful gaps.

The practical value emerges most clearly when a Current Profile is compared against a Target Profile representing the desired future state. That comparison surfaces the distance between where an organization stands and where it aims to be, enabling gap analysis and risk-based prioritization of remediation and resources. Because the NIST framework is voluntary guidance rather than a binding legal obligation, a Current Profile is typically used to inform and defend management decisions rather than to satisfy a specific statutory requirement, though organizations should confirm how it fits within any sector-specific expectations that apply to them.

Practitioners should note that a Current Profile is only as reliable as the assessment behind it; an overly optimistic or incomplete self-appraisal can understate real exposure. The framework's specific definitional language has also evolved across editions, so teams should verify the exact wording and scope against official NIST documentation for the version they are applying.

Who it's relevant to

Chief Information Security Officers and Security Leaders
CISOs use a Current Profile to establish an evidence-based snapshot of present cybersecurity outcomes and to frame improvement roadmaps against a Target Profile. It gives them a structured way to communicate present-state posture and justify prioritized investment.
Risk Managers
Risk managers rely on the Current Profile as a baseline for gap analysis and risk-based prioritization, using the distance between present and desired outcomes to inform where treatment and resources should be focused.
Internal Auditors and Assurance Functions
Auditors can reference a Current Profile as a documented account of the outcomes an organization claims to be achieving, testing whether the stated present-state alignment is supported by actual activities and results, while noting that framework use is voluntary guidance rather than a binding obligation.
Boards and Executive Management
Boards and executives use the comparison between Current and Target Profiles to understand where the organization stands today, oversee prioritization of remediation, and support resource allocation decisions in framework-aligned terms.
Governance, Compliance, and Legal Teams
These functions should confirm how a Current Profile fits within any sector-specific or jurisdictional expectations that apply to their organization, and verify definitional wording against the official NIST source for the framework edition in use, since precise language has evolved across editions.

Inside Current Profile

Present-State Outcome Alignment
In the NIST Cybersecurity Framework, a Current Profile represents the 'as-is' state, capturing which Framework outcomes an organization is currently achieving and to what degree. It documents the present alignment of cybersecurity activities against the Framework's Functions, Categories, and Subcategories rather than a desired future state.
Scope and Boundary Definition
A Current Profile is typically scoped to a defined portion of the organization, such as a business unit, system, or set of assets, so that the outcomes assessed correspond to a specific context. Clear scoping helps ensure the profile reflects a coherent set of processes and risks rather than an undifferentiated whole.
Basis for Gap Analysis
The Current Profile is commonly compared against a Target Profile (the desired 'to-be' state) to identify gaps between present and intended outcomes. This comparison supports prioritization of remediation and resource allocation, though the Framework itself is voluntary guidance rather than a binding regulatory requirement.
Evidence of Existing Practices and Controls
A Current Profile draws on information about the organization's existing policies, processes, and controls to characterize which outcomes are currently met. It reflects the present treatment of risk but does not itself eliminate risk or guarantee compliance; it is a descriptive snapshot rather than an assurance instrument.

Common questions

Answers to the questions practitioners most commonly ask about Current Profile.

Is a Current Profile just a wish list of the cybersecurity outcomes an organization wants to achieve?
No. In the NIST Cybersecurity Framework, a Current Profile describes the present, "as-is" state of an organization's cybersecurity outcomes, what is actually being achieved at a given point in time. It is distinct from a Target Profile, which represents the desired, "to-be" state. Confusing the two undermines the framework's core use case: comparing a Current Profile against a Target Profile to reveal gaps that inform prioritization and remediation. When practitioners describe aspirational outcomes, they are typically documenting a Target Profile, not a Current Profile.
Does having a Current Profile mean an organization is compliant with a specific regulation?
Not necessarily. The NIST Cybersecurity Framework is a voluntary framework rather than a binding regulation in most contexts, so documenting a Current Profile is generally a leading-practice activity rather than a compliance obligation in itself. A Current Profile records the present state of cybersecurity outcomes; it does not, on its own, establish adherence to any particular law or regulatory requirement. Whether a Current Profile supports a compliance obligation depends on jurisdiction, sector, and any regulatory mandates that reference the framework, which should be verified against the applicable primary sources.
How does an organization develop a Current Profile in practice?
In many implementations, an organization develops a Current Profile by assessing which cybersecurity outcomes defined in the NIST Cybersecurity Framework are currently being achieved, and to what degree. This typically involves reviewing existing controls, processes, and evidence against the framework's outcomes, then documenting the present state. The assessment often draws on input from control owners, risk and security teams, and available documentation. Because framework language evolves across editions, organizations should confirm the outcome categories against the version of the framework they are using.
How is a Current Profile used together with a Target Profile?
A common practice is to compare the Current Profile against a Target Profile to identify differences between the present and desired states of cybersecurity outcomes. The gaps revealed by this comparison can help an organization prioritize actions, allocate resources, and build a plan to move toward its target state. The comparison supports risk-informed decision-making, but the framework does not prescribe a single method for closing gaps, and prioritization typically reflects the organization's own risk appetite and objectives.
How often should a Current Profile be updated?
The framework does not mandate a fixed update frequency, so timing generally depends on organizational context. Many organizations refresh a Current Profile when significant changes occur, such as changes to systems, the threat environment, business objectives, or the control set, or on a periodic cadence aligned with governance and risk review cycles. Because a Current Profile represents a point-in-time "as-is" state, it can become outdated as conditions change, so organizations often treat it as a living document rather than a one-time deliverable.
Who is typically responsible for maintaining the Current Profile?
Responsibility varies by organization and is generally assigned through governance structures rather than dictated by the framework. In practice, the effort is often coordinated by a security, risk, or GRC function, with input from control owners and other stakeholders who can attest to the present state of specific outcomes. Clear decision rights and accountability for maintaining and approving the Current Profile help ensure it remains accurate and useful for gap analysis and prioritization.

Common misconceptions

A Current Profile is a formal control or a compliance requirement organizations must file.
In the NIST Cybersecurity Framework, a Current Profile is a descriptive tool that characterizes present-state outcomes, not a control that modifies risk. The Framework is voluntary guidance in most contexts, and applicability as a mandate depends on jurisdiction, sector, and any contractual or regulatory adoption. Specific obligations should be verified against the primary source and applicable law.
The Current Profile describes the desired or ideal cybersecurity posture.
The Current Profile captures the 'as-is' present state of achieved outcomes. The desired state is typically documented separately in a Target Profile, and the two are compared to reveal gaps. Conflating the two undermines the gap analysis the Framework is designed to support.
Once a Current Profile is documented, it remains valid indefinitely.
A Current Profile is a point-in-time snapshot. Because organizational systems, threats, and controls change, the profile typically requires periodic reassessment to remain an accurate reflection of the present state. Framework language and editions also evolve, so terminology should be checked against the version in use.

Best practices

Reference the applicable edition of the NIST Cybersecurity Framework (for example, CSF v1.1 or v2.0) when defining or building a Current Profile, and verify terminology against the primary source, since Framework language evolves across editions.
Clearly define the scope and boundary of the Current Profile, such as the business unit, system, or asset set it covers, so the assessed outcomes correspond to a coherent context.
Base the Current Profile on verifiable evidence of existing policies, processes, and controls, rather than aspirational or intended practices, to keep it an accurate 'as-is' snapshot.
Maintain the Current Profile as a distinct artifact from any Target Profile so that the gap analysis between present and desired outcomes stays meaningful.
Reassess and update the Current Profile periodically and after significant changes to systems, threats, or controls, treating it as a point-in-time snapshot rather than a permanent record.
Confirm whether and how the Framework applies in your jurisdiction, sector, and any contractual settings before treating a Current Profile as a compliance obligation, seeking professional advice where legal interpretation is required.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide