// NIST.jsx — Verigo Global: dedicated NIST CSF + RMF advisory page const { V: NV, MAXW: NMW, FONT: NFT } = window; /* ── DATA ─────────────────────────────────────────────────── */ const PILLARS = [ { code: 'CSF 2.0', icon: 'compass', name: 'Cybersecurity Framework', kind: 'Voluntary · risk communication', desc: 'A flexible, outcome-based framework for understanding, managing, and communicating cybersecurity risk in plain language. Organized into six Functions, it gives leadership and technical teams a shared way to talk about posture — and a Profile to express where you are and where you want to be.', points: ['Six Functions, Categories & Subcategories', 'Current and Target Profiles', 'Four Implementation Tiers', 'Maps to 800-53, CSF, ISO 27001 & more'], }, { code: 'RMF', icon: 'refresh', name: 'Risk Management Framework', kind: 'Mandated · authorization process', desc: 'The disciplined, seven-step process (SP 800-37) for building security and privacy into federal information systems and granting them an Authorization to Operate. Where the CSF communicates risk, the RMF operationalizes it — categorize, select, implement, assess, authorize, and monitor.', points: ['Seven-step lifecycle (SP 800-37)', 'Control selection from SP 800-53', 'Assessment under SP 800-53A', 'Drives the Authorization to Operate (ATO)'], }, ]; const FUNCTIONS = [ ['scale', 'Govern', 'GV', 'Establish and monitor the cybersecurity risk strategy, expectations, roles, and policy. New in CSF 2.0.', true], ['search', 'Identify', 'ID', 'Understand the assets, data, suppliers, and risks that make up your environment.'], ['shield', 'Protect', 'PR', 'Put safeguards in place to manage risk and limit the impact of potential events.'], ['activity', 'Detect', 'DE', 'Find and analyze possible attacks and compromises in a timely way.'], ['zap', 'Respond', 'RS', 'Take action on a detected incident to contain and mitigate its effect.'], ['refresh', 'Recover', 'RC', 'Restore assets and operations affected by an incident and return to normal.'], ]; const TIERS = [ { n: 1, name: 'Partial', tone: '#C9C2DE', short: 'Ad hoc, reactive', desc: 'Risk is managed in an ad hoc, sometimes reactive way. There is limited awareness of cyber risk at the organizational level.' }, { n: 2, name: 'Risk Informed', tone: '#A99BCE', short: 'Aware, not org-wide', desc: 'Risk-management practices are approved but may not be established organization-wide. Awareness exists but is inconsistent.' }, { n: 3, name: 'Repeatable', tone: '#8159B5', short: 'Formal, organization-wide', desc: 'Formal policies are defined and practiced consistently across the organization, with regular updates as risk changes — a common target.' }, { n: 4, name: 'Adaptive', tone: '#3F1E68', short: 'Adaptive, continuous', desc: 'The organization adapts practices in near real time from lessons learned and predictive indicators, continuously improving.' }, ]; const RMF_STEPS = [ ['clipboard', 'Prepare', 'Ready the organization to manage security and privacy risks.'], ['layers', 'Categorize', 'Categorize the system and information by impact level (FIPS 199).'], ['target', 'Select', 'Select an appropriate control baseline from SP 800-53.'], ['cpu', 'Implement', 'Deploy the selected controls and document how they are applied.'], ['check', 'Assess', 'Test the controls for effectiveness under SP 800-53A.'], ['award', 'Authorize', 'A senior official accepts residual risk and grants the ATO.'], ['activity', 'Monitor', 'Continuously monitor controls and risk posture over time.'], ]; const APPLIES = [ ['building', 'Federal agencies', 'For federal information systems, the RMF and an Authorization to Operate are mandated under FISMA — NIST is not optional, it is the law of the land.'], ['network', 'Federal contractors & supply chain', 'Organizations handling federal data inherit NIST obligations — SP 800-171 for Controlled Unclassified Information, and the control language beneath CMMC.'], ['zap', 'Critical infrastructure operators', 'Energy, water, healthcare, and financial operators adopt the CSF to manage and communicate risk across sectors where disruption has outsized consequences.'], ['globe', 'Private-sector organizations', 'CSF 2.0 was broadened explicitly for organizations of every size and sector — a common, vendor-neutral language for cyber risk that boards and partners understand.'], ]; const ROADMAP = [ ['compass', 'Scope & frame', '2–3 wks', 'Decide CSF, RMF, or both; define the systems, organizational scope, and risk context that frame the work.'], ['search', 'Current Profile / categorize', '3–5 wks', 'Build a CSF Current Profile and, for RMF, categorize systems by impact to set the right control baseline.'], ['target', 'Target Profile & control selection', '2–4 wks', 'Define the Target Profile and tier, and select the SP 800-53 controls that close the gap to it.'], ['layers', 'Implement & remediate', '3–9 mo', 'Deploy controls, write policies, and build the evidence and System Security Plan the framework expects.'], ['check', 'Assess', '4–8 wks', 'Independently assess control effectiveness under SP 800-53A and resolve findings into a POA&M.'], ['award', 'Authorize & monitor', '4–8 wks', 'Support the ATO decision and stand up the continuous-monitoring program that keeps the authorization alive.'], ]; const SEEKING = [ ['compass', 'Decide CSF, RMF, or both', 'They solve different problems. The CSF communicates and prioritizes risk in plain language; the RMF authorizes a system to operate. Many organizations need both — CSF to set direction, RMF to satisfy a federal mandate. Naming the goal first keeps the effort focused.'], ['layers', 'Categorize before you select controls', 'In the RMF, impact categorization drives everything downstream — get it wrong and you either over-control a low-impact system or under-protect a high-impact one. We anchor the baseline to a defensible categorization so control selection is right-sized from the start.'], ['activity', 'Build monitoring in, not on', 'An ATO is not a finish line — it is sustained by continuous monitoring. The organizations that renew cleanly are the ones that instrument evidence from day one. We design the monitoring program alongside the controls, not as an afterthought.'], ]; const PREPARE = [ 'A decision on CSF, RMF, or both', 'A defined system boundary and organizational scope', 'Impact categorization for in-scope systems', 'A CSF Current Profile of where you stand today', 'A target tier / Target Profile to aim for', 'Named system and control owners for assessment', ]; const OUTPUTS = [ ['compass', 'Current & Target Profiles', 'CSF Profiles that document where your cybersecurity posture stands today and where it needs to be — the gap, prioritized and made legible to leadership.'], ['layers', 'Categorization & control baseline', 'A defensible system impact categorization (FIPS 199) and the tailored SP 800-53 control baseline selected to match it.'], ['file', 'System Security Plan (SSP)', 'The authoritative document describing your system, its boundary, and how each selected control is implemented — the backbone of any authorization package.'], ['check', 'Assessment report & POA&M', 'A Security Assessment Report on control effectiveness plus a Plan of Action & Milestones tracking every gap to a named owner and date.'], ['award', 'Authorization (ATO) support', 'A complete authorization package and the risk narrative an Authorizing Official needs to make — and defend — the decision to grant an ATO.'], ['activity', 'Continuous-monitoring program', 'The metrics, cadence, and tooling that keep your controls effective and your authorization current long after assessment day.'], ]; const TESTIMONIALS = [ { quote: 'Verigo ran our RMF authorization end to end — categorization through ATO — and made the System Security Plan something our Authorizing Official could actually read. We received our authorization without a single blocking finding.', name: 'Grace Okafor', role: 'CISO', org: 'Federal systems integrator', initials: 'GO', }, { quote: 'We adopted the CSF to get our board and our engineers speaking the same language about risk. The Current and Target Profiles Verigo built turned a vague worry into a funded, prioritized plan everyone understood.', name: 'Daniel Whitfield', role: 'Director of Security', org: 'Regional energy utility', initials: 'DW', }, { quote: 'As a private fintech we weren\u2019t mandated to use NIST, but our partners expected it. Verigo mapped the CSF to controls we already had and showed us exactly where the real gaps were — no boilerplate, no busywork.', name: 'Sofia Mendez', role: 'VP of Risk', org: 'Payments platform', initials: 'SM', }, ]; const NIST_FAQ = [ ['What is the difference between the NIST CSF and the RMF?', 'They serve different purposes. The Cybersecurity Framework (CSF) is a voluntary, outcome-based framework for understanding, prioritizing, and communicating cyber risk — a common language for leadership and technical teams. The Risk Management Framework (RMF) is a prescriptive, seven-step process for building security into systems and granting them an Authorization to Operate, and it is mandated for federal systems. Many organizations use the CSF to set direction and the RMF to satisfy a compliance obligation.'], ['What are the CSF Functions, and what changed in version 2.0?', 'The CSF organizes outcomes into Functions. CSF 2.0, released in 2024, defines six: Govern, Identify, Protect, Detect, Respond, and Recover. The headline change from 1.1 was the addition of Govern, which elevates cybersecurity risk management to a leadership and strategy concern rather than a purely technical one. CSF 2.0 also broadened the framework\u2019s audience from critical infrastructure to organizations of every size and sector.'], ['Are the CSF Implementation Tiers maturity levels?', 'Not exactly — and the distinction matters. The four Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe the rigor and consistency of your risk-management practices, much like a maturity scale. But NIST is clear that higher Tiers are not always the goal: the right Tier is the one that reduces risk cost-effectively for your organization. We help you choose and reach a target Tier deliberately rather than chasing Tier 4 for its own sake.'], ['Who is required to use the NIST RMF?', 'The RMF is mandated for US federal agencies and their information systems under FISMA, where an Authorization to Operate is required before a system goes live. Federal contractors and the broader supply chain inherit related NIST obligations — most commonly SP 800-171 for Controlled Unclassified Information, which also underpins CMMC. Private-sector organizations adopt NIST voluntarily, usually via the CSF.'], ['What is an ATO, and who grants it?', 'An Authorization to Operate (ATO) is a formal decision by a senior official — the Authorizing Official — to accept the residual risk of operating a system and permit it to go live. It is the culmination of the RMF: the Authorizing Official reviews the System Security Plan, the assessment results, and the Plan of Action & Milestones before granting authorization, which is then sustained through continuous monitoring.'], ['How does NIST relate to CMMC, ISO 27001, and SOC 2?', 'NIST is the foundation beneath much of the compliance landscape. SP 800-171 and SP 800-53 provide the control language that CMMC builds on directly, and CSF outcomes map cleanly to ISO 27001 and the SOC 2 Trust Services Criteria. That makes NIST work highly reusable — control evidence developed once can accelerate several certifications. We design NIST engagements with that cross-framework reuse in mind.'], ]; /* ── BREADCRUMB ───────────────────────────────────────────── */ const NCrumb = ({ onNav }) => (
The control language and risk discipline beneath US government compliance — and a common framework the whole market trusts. Verigo takes you from a CSF Profile and risk picture through the RMF lifecycle to an Authorization to Operate and continuous monitoring.
NIST does not sell certifications — it publishes the control catalogs and risk language that nearly everything else is built on. CMMC inherits its controls from NIST; ISO 27001 and SOC 2 map cleanly to it. Get NIST right and the rest gets dramatically easier.
The two pillars do different jobs. The CSF communicates and prioritizes risk in language a board understands; the RMF operationalizes it into a system that earns an Authorization to Operate. Together they cover strategy and execution.
For federal agencies the RMF is mandatory; for everyone else the CSF has become the vendor-neutral common language of cyber risk.
Because NIST is the source the other frameworks reference, control evidence developed for NIST is highly reusable — the same work that earns an ATO can accelerate CMMC, ISO 27001, and SOC 2. NIST is the highest-leverage place to start.
{d}
{p.desc}
{d}
{tr.desc}
{d}
{d}
NIST rewards clarity of intent. Decide what you are trying to achieve, categorize honestly, and instrument from the start — and the framework becomes a steady engine rather than a paperwork exercise. These are the three things to get right first.
{d}
{d}
{t.quote}
Questions on CSF Profiles, Implementation Tiers, or the RMF and ATO process? A senior practitioner will walk you through it.
{a}