The Organization That Mapped to NIST and Still Had the Incident

The NIST CSF mapping was comprehensive. Every subcategory was assessed. Gaps were documented. A roadmap was developed. Progress was reported to the board quarterly.

RCDr. Richard Chingombe · Founder, Verisq·4 min read·Practitioner perspective, not legal advice

The maturity scores improved year over year. The organization was, by every reasonable measure of framework adoption, a mature NIST CSF implementer. Then the incident happened. And the post-incident review found that the controls the framework had assessed as implemented were not operating in the way the assessment assumed.

The Gap Between Mapping and Operating

Framework mapping is an assessment activity. It evaluates whether the organization has implemented the practices and controls that the framework prescribes. The assessment answer — implemented, partially implemented, not implemented — reflects the assessor's judgment about the state of implementation at assessment time, based on the evidence reviewed. The assessment is not a measurement of operational effectiveness. It is a structured evaluation of implementation state.

The difference matters because implementation state and operational effectiveness are different things. A control can be fully implemented — deployed, configured, documented, and assessed as meeting the framework requirement — and still fail to operate effectively in practice. The SIEM is deployed and feeds into the Detect function. The detection rules have not been updated in eighteen months and are generating alerts that the security team has learned to suppress. The control is implemented. The detection is not effective.

NIST CSF maturity scores measure the organization's implementation of the framework's prescribed practices. They do not measure whether those practices are producing the outcomes the framework designed them to produce. These are different measurements that require different assessment approaches.

What the Incident Revealed

Post-incident reviews of organizations with mature framework implementations typically reveal the same pattern: the controls that were implemented and assessed as such were operating at a lower level of effectiveness than the assessment indicated. The specific failures vary. The structural cause is consistent: the assessment measured implementation. Nobody was measuring outcomes.

In this case, the Protect function controls assessed as implemented included network segmentation that had been modified during a cloud migration eighteen months prior. The migration had required temporary exceptions to the segmentation policy. The exceptions were documented as temporary. They had not been removed when the migration was complete. The segmentation that the assessment had evaluated as implemented was the designed segmentation. The actual segmentation was the modified version with the temporary exceptions still in place.

The Detect function had SIEM coverage assessed at 94 percent of critical systems. The 6 percent not covered included the systems affected in the incident — systems that had been added to the environment during the cloud migration and had not been added to the SIEM monitoring scope. The coverage percentage was accurate for the systems in scope when the assessment was conducted. It was not accurate for the systems added after the assessment scope was defined.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

Using the Framework More Effectively

Outcome Metrics Alongside Implementation Metrics

The NIST CSF's Govern function in CSF 2.0 explicitly includes organizational outcomes as a governance objective. Implementing outcome measurement alongside implementation assessment means asking not only 'is the control implemented?' but 'is the control producing its intended outcome?' For detection controls: what percentage of test attack techniques are detected within the required timeframe? For protection controls: what is the configuration drift rate from the assessed baseline? For response controls: what is the mean time to contain against the target?

Assessment Scope That Keeps Pace with the Environment

Assessment scope that was defined at the beginning of a multi-year framework adoption program may not reflect the current environment. Systems added, cloud environments expanded, vendor integrations added — the environment grows. The assessment scope needs to grow with it. An annual scope review that explicitly asks what has been added to the environment since the last assessment, and whether the additions are within assessment scope, prevents the accumulation of unassessed environment that the incident revealed.

Exception Management Integrated with Framework Assessments

Exceptions to implemented controls — temporary modifications, policy deviations, environments that have not yet met the control standard — should be visible in the framework assessment rather than hidden by assessments that evaluate the designed control rather than the operating control. An assessment process that includes exception inventory as part of the evidence review produces a more accurate view of the operating control environment than one that assesses design documentation without checking whether exceptions are current.

The Framework's Actual Value

None of this diminishes the value of the NIST CSF as a governance instrument. It is the most widely adopted cybersecurity framework for good reasons: it is comprehensive, adaptable, and provides a structured vocabulary for governance conversations that is understood across organizations and sectors. The framework's value is in the structure it provides for systematic governance — identifying what matters, assessing the current state, and driving improvement.

The failure mode is not using the framework. The failure mode is confusing framework maturity scores with security outcomes. The scores measure adoption. The outcomes require additional measurement investment that the framework assessment does not automatically produce.

Implement the framework. Then measure whether it is working. Both investments are required.

The framework maps the governance territory. Whether the controls that map to it are operating effectively in your specific environment requires measurement that the map does not provide. Build the measurement program alongside the framework program.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.