Join our Newsletter — 33% off our NHI Course
Home Glossary Architecture & Implementation Current Profile
Architecture & Implementation

Current Profile

← Back to Glossary
By NHI Mgmt Group Updated September 1, 2026 Domain: Architecture & Implementation

The Current Profile describes the cybersecurity outcomes an organisation is achieving now, or is attempting to achieve. It captures the present state of controls, practices, and assumptions across selected CSF outcomes. Security teams use it as the baseline for identifying gaps, measuring maturity, and comparing actual capability with desired risk management goals.

Expanded Definition

The Current Profile in NIST Cybersecurity Framework usage is the organisation’s present-day cybersecurity posture: the outcomes it is actually achieving, not the outcomes it wishes it had. It is built by mapping real controls, practices, exceptions, and assumptions against selected CSF outcomes so teams can see where implementation is strong, partial, or absent. In practice, the Current Profile is less a static report and more a decision tool for comparing current capability with a Target Profile, prioritising remediation, and communicating risk in a common language. The concept is most useful when the organisation has mixed maturity across domains, because it makes gaps visible without requiring every control family to be expressed at the same level of detail. Guidance varies slightly across vendors and programmes, but the core idea is consistent: capture what is true today, not what policy says should be true. For a baseline framing of CSF outcomes, see NIST Cybersecurity Framework 2.0. The most common misapplication is treating the Current Profile as a policy checklist, which occurs when teams record intended controls instead of verifying operational evidence.

Examples and Use Cases

Implementing a Current Profile rigorously often introduces assessment overhead, requiring organisations to balance completeness against the time needed to validate evidence across systems and teams.

  • A security programme maps logging, access review, and incident response outcomes to show which CSF categories are actively achieved and which remain partial.
  • An identity team uses the profile to compare service-account governance against expected standards, especially where secrets, rotation, and offboarding are uneven. The Ultimate Guide to NHIs is a useful reference when the baseline involves non-human identities.
  • A board report uses the profile to translate technical gaps into risk language, making it clear where current controls do not support the intended risk posture.
  • A merger or acquisition team builds separate Current Profiles for each environment to identify control drift before systems are consolidated.
  • An engineering organisation repeats the profile quarterly to track whether remediation has actually improved the achieved outcome set.

For organisations aligning the profile to broader control outcomes, the NIST Cybersecurity Framework 2.0 helps anchor the comparison in a recognised structure rather than an ad hoc checklist.

Why It Matters in NHI Security

Current Profile matters in NHI security because non-human identities are often the gap between documented policy and real operational exposure. NHIMG reporting shows that only 5.7% of organisations have full visibility into their service accounts, and that visibility gap makes any baseline profile incomplete if NHIs are omitted. A Current Profile should therefore include service accounts, API keys, tokens, and other secrets-bearing identities where they affect CSF outcomes such as asset visibility, access control, and recovery. When that baseline is weak, organisations misjudge maturity and underestimate how much privilege, rotation debt, and secret sprawl already exists. The profile also helps reveal where NHI controls are inherited from human IAM processes that do not fit machine-to-machine access patterns. In NHI governance, the value of the Current Profile is that it exposes the difference between what security leadership assumes is being enforced and what is actually observable in production. Organisations typically encounter the full cost of an inaccurate Current Profile only after a compromise, audit failure, or incident review, at which point baseline accuracy becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0Current Profile is a core CSF concept for describing achieved outcomes today.
NIST Zero Trust (SP 800-207)Zero Trust assessments depend on knowing the current state of access and verification controls.
OWASP Non-Human Identity Top 10NHI-01NHI visibility and governance gaps affect whether the real identity posture is accurately profiled.

Document present control outcomes first, then compare them to the target state to prioritise gaps.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org