RSA Archer NIST-Aligned Cybersecurity Framework App-Pack 

Document created by Susan Read-Miller Employee on Aug 16, 2017Last modified by Gloria Higley on Aug 18, 2020
Version 24Show Document
  • View in full screen mode

RSA Archer Suite Logo


Cybersecurity threats exploit the increased complexity and connectivity of critical infrastructure systems, which places national security, the economy, and public safety at risk. To combat these cyber risks, NIST (National Institute of Standards and Technology) has developed a risk-based Cybersecurity Framework to provide government agencies and the private sector with industry standards and best practices to help manage cybersecurity risks. In May 2017, the U.S. Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure was signed, holding agencies, as well as owners and operators of critical infrastructure in the U.S., accountable for managing cybersecurity risks.


RSA Archer NIST-Aligned Cybersecurity Framework app-pack provides straightforward guidelines for addressing and managing cybersecurity risks. Profile owners can catalog the current state, prioritize and scope profile elements, and define their desired or targeted state outcomes for their organization’s cybersecurity program. Assessors then evaluate these profiles against the Cybersecurity Framework categories. Previous assessments can be archived for comparison with current Profile and measure progress. Reports and dashboards provide clear insight to the cybersecurity current state and progress being made toward the desired cybersecurity state. 


With the RSA Archer NIST-Aligned Cybersecurity Framework offering, government agencies and private sector businesses can assess and measure their cybersecurity posture, address gaps, and report on cybersecurity posture in a meaningful way that is understood by all stakeholders.


NIST has developed the NIST Privacy Framework which utilizes the same methodology and process to evaluate an organizations implementation to protect individuals’ privacy. The NIST Privacy Framework contains Core Activities that overlap with the NIST Cybersecurity Framework. With RSA Archer NIST-Aligned Cybersecurity Framework release 6.8, the offering has been combined with the RSA Archer NIST-Aligned Privacy Framework to allow you to assess both privacy and cybersecurity practices within your organization. Check out the RSA Archer NIST-Aligned Privacy Framework app-pack, to gain a better understanding of how this offering can augment your RSA Archer NIST-Aligned Cybersecurity Framework implementation.

Key Features

  • Prioritize and scope the organization's business objectives and priorities
  • Create a Current Profile that indicates progress being made toward target outcomes
  • Track NIST Cybersecurity Framework library versions for cybersecurity assessments
  • Risk assess the operational environment and identify the likelihood and impact of a cybersecurity event
  • Identify a Target Profile that describes the organization's desired cybersecurity outcomes
  • Analyze the Current Profile against  the Target Profile by function, category, level or business process to determine gaps
  • Implement an Action Plan to identify necessary steps  to remediate gaps
  • Ability to conduct assessments against NIST Privacy Framework with RSA Archer NIST-Aligned Cybersecurity Framework release 6.8


  • Concise methodology allows organizations to understand  how your cybersecurity efforts stack up relative to NIST’s guidance and authoritative sources
  • Common language ensure clear communication of requirements and progress across all  stakeholders, including the IT security team, management, partners, contractors, suppliers, and others
  • Application of NIST Cybersecurity Framework version 1.1, released in April 2018, and risk management best practices improve cybersecurity and resiliency of critical infrastructure, regardless of organization size or level of cybersecurity sophistication
  • Designed to assist government and critical infrastructure entities manage cybersecurity requirements in keeping with the U.S. Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure



  • RSA Archer NIST-Aligned Cybersecurity Framework 6.4 SP1 offering requires several applications including:
    • Business Units
    • Business Processes
    • Applications
    • Devices
    • Authoritative Sources


  • RSA Archer NIST-Aligned Cybersecurity Framework 6.8 and above does not require any prerequisite applications.


Prerequisite applications can be found in several Use Case offerings. Please review the implementation guide for a full list of the applications, use cases and prerequisite dependencies that are required for this offering.


Supported Platform Version

RSA Archer NIST-Aligned Cybersecurity Framework was developed for and validated on:

  • RSA Archer Platform release 6.4 SP1
  • RSA Archer Platform release 6.8 and above


RSA Archer On-Demand Application (ODA) Licenses

  • Three (3) RSA Archer On-Demand Application (ODA) licenses are required for RSA Archer NIST-Aligned Cybersecurity Framework
  • For existing RSA Archer NIST-Aligned Cybersecurity Framework app-pack implementations, please review the implementation guide for information on-demand application requirements and upgrade best practices.  


For More Information

To learn more about RSA Archer NIST-Aligned Cybersecurity Framework:


For Additional Support

To learn more about this offering, please contact your Account Rep for additional details. For technical support questions regarding this offering, please open a support case or contact RSA Archer at for more information.


RSA Archer NIST-Aligned Cybersecurity Framework Release 6.8

Profile Owner Dashboard



RSA Archer NIST-Aligned Cybersecurity Framework Release 6.8

Profile Scorecard