Skip to content

Conducting Tiers

Conducting Tier Assessments

Tier assessments are a critical component of implementing the NIST Cybersecurity Framework 1.1 (CSF 1.1), enabling organizations to evaluate their current cybersecurity maturity. However, it is important to clarify that the tier model (Tier 1 to Tier 4) described in this guide is not part of the NIST CSF 1.1 framework. Instead, this tier model is commonly associated with other frameworks such as NIST Special Publication 800-53 or the Center for Internet Security (CIS) Critical Security Controls. These assessments provide a structured approach to identify gaps, prioritize improvements, and ensure alignment with risk management goals.


1. Define Assessment Scope and Objectives

Before initiating a tier assessment, clearly define the scope, including systems, processes, and stakeholders involved. Objectives should focus on evaluating compliance with specific CSF 1.1 categories (e.g., Identify, Protect, Detect, Respond, Recover) and determining the organization’s tier level.

Example:

# Use a script to inventory systems and identify critical assets  
python3 asset_inventory.py --scope "internal_network" --output "assessment_scope.md"  
# The script scans the specified network scope to catalog assets and generates a markdown file outlining the assessment boundaries.  

Diagram:
A flowchart showing the tier assessment workflow, from scope definition to final reporting.


2. Gather Data and Evidence

Collect data from existing controls, policies, and incident records. Use automated tools to assess compliance with CSF 1.1 subcategories.

Tools and Commands:
- Vulnerability Scanning:

nmap --script vuln <target_ip>  # Identifies unpatched systems by scanning for known vulnerabilities.  
- Policy Compliance Check:
python3 compliance_checker.py --policy "NIST_CSF_1.1" --controls "Protect-1-2"  
# Verifies adherence to specific controls (e.g., Protect-1-2) within the NIST CSF 1.1 framework.  

Diagram:
A maturity model diagram illustrating how data collection maps to tier levels (e.g., Tier 1: Reactive, Tier 4: Proactive).


3. Evaluate Against Tier Criteria

Compare findings against the criteria for each tier:
- Tier 1: Basic risk management (e.g., foundational policies, minimal monitoring).
- Tier 2: Defined risk management (e.g., documented processes, periodic assessments).
- Tier 3: Quantitative risk management (e.g., metrics, continuous monitoring).
- Tier 4: Adaptive risk management (e.g., real-time analytics, automated responses).

Example:

# Sample code to calculate tier score based on control maturity  
def calculate_tier(score):  
    if score <= 40:  
        return "Tier 1"  
    elif score <= 70:  
        return "Tier 2"  
    elif score <= 90:  
        return "Tier 3"  
    else:  
        return "Tier 4"  
# This function maps a numerical score (derived from control maturity) to the corresponding tier level.  


4. Identify Gaps and Prioritize Improvements

Highlight discrepancies between current practices and tier requirements. Use risk-based prioritization to address high-impact gaps first.

Example:

# Generate a prioritized remediation plan  
python3 gap_analysis.py --tier "Tier 3" --output "remediation_plan.xlsx"  
# The script analyzes gaps relative to the specified tier and exports a prioritized action plan in Excel format.  

Diagram:
A risk matrix diagram showing gap severity vs. likelihood, with prioritization categories.


5. Document and Report Findings

Compile results into a structured report, including:
- Current tier level.
- Key findings and gaps.
- Recommendations for advancing to higher tiers.
- Actionable steps for implementation.


Key takeaways

  • Tier assessments align with tier models from frameworks like NIST SP 800-53 or CIS Critical Security Controls to evaluate maturity and risk management.
  • Use automated tools and scripts to streamline data collection and analysis.
  • Prioritize gaps based on risk impact and alignment with organizational goals.
  • Continuous monitoring and iterative assessments ensure long-term compliance and improvement.
  • Document findings clearly to guide decision-making and stakeholder communication.