Civitas EPI Rail
Civitas Analytica — Engineered truth
trust_audit / nist_csf / acme / eng42

Trust Audit

Civitas Analytica — Engineered truth.

Executive Summary

Severity-weighted score0.0%
Total controls80
Met0
Partial0
Gap80

Key Gaps

Full Controls Table

control_idtitleobjectiveevidence expectationsstatusseverityevidence_count
NIST-001NIST CSF Control 001Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-002NIST CSF Control 002Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-003NIST CSF Control 003Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-004NIST CSF Control 004Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-005NIST CSF Control 005Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-006NIST CSF Control 006Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-007NIST CSF Control 007Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-008NIST CSF Control 008Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-009NIST CSF Control 009Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-010NIST CSF Control 010Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-011NIST CSF Control 011Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-012NIST CSF Control 012Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-013NIST CSF Control 013Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-014NIST CSF Control 014Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-015NIST CSF Control 015Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-016NIST CSF Control 016Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-017NIST CSF Control 017Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-018NIST CSF Control 018Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-019NIST CSF Control 019Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-020NIST CSF Control 020Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-021NIST CSF Control 021Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-022NIST CSF Control 022Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-023NIST CSF Control 023Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-024NIST CSF Control 024Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-025NIST CSF Control 025Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-026NIST CSF Control 026Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-027NIST CSF Control 027Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-028NIST CSF Control 028Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-029NIST CSF Control 029Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-030NIST CSF Control 030Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-031NIST CSF Control 031Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-032NIST CSF Control 032Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-033NIST CSF Control 033Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-034NIST CSF Control 034Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-035NIST CSF Control 035Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-036NIST CSF Control 036Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-037NIST CSF Control 037Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-038NIST CSF Control 038Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-039NIST CSF Control 039Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-040NIST CSF Control 040Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-041NIST CSF Control 041Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-042NIST CSF Control 042Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-043NIST CSF Control 043Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-044NIST CSF Control 044Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-045NIST CSF Control 045Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-046NIST CSF Control 046Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-047NIST CSF Control 047Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-048NIST CSF Control 048Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-049NIST CSF Control 049Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-050NIST CSF Control 050Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-051NIST CSF Control 051Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-052NIST CSF Control 052Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-053NIST CSF Control 053Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-054NIST CSF Control 054Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-055NIST CSF Control 055Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-056NIST CSF Control 056Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-057NIST CSF Control 057Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-058NIST CSF Control 058Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-059NIST CSF Control 059Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-060NIST CSF Control 060Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-061NIST CSF Control 061Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-062NIST CSF Control 062Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-063NIST CSF Control 063Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-064NIST CSF Control 064Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-065NIST CSF Control 065Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-066NIST CSF Control 066Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-067NIST CSF Control 067Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-068NIST CSF Control 068Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-069NIST CSF Control 069Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-070NIST CSF Control 070Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-071NIST CSF Control 071Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-072NIST CSF Control 072Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-073NIST CSF Control 073Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-074NIST CSF Control 074Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-075NIST CSF Control 075Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.gap50
NIST-076NIST CSF Control 076Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.gap10
NIST-077NIST CSF Control 077Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.gap20
NIST-078NIST CSF Control 078Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.gap30
NIST-079NIST CSF Control 079Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.gap40
NIST-080NIST CSF Control 080Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.gap50

Gap Register

control_idtitlestatusseverityevidence_countmissing_evidenceevidence expectations
NIST-001NIST CSF Control 001gap102Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-002NIST CSF Control 002gap202Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-003NIST CSF Control 003gap303Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.
NIST-004NIST CSF Control 004gap402Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
NIST-005NIST CSF Control 005gap502Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-006NIST CSF Control 006gap102Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-007NIST CSF Control 007gap202Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-008NIST CSF Control 008gap302Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-009NIST CSF Control 009gap402Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-010NIST CSF Control 010gap503Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-011NIST CSF Control 011gap102Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-012NIST CSF Control 012gap202Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.
NIST-013NIST CSF Control 013gap302Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-014NIST CSF Control 014gap402Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-015NIST CSF Control 015gap503Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.
NIST-016NIST CSF Control 016gap102Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
NIST-017NIST CSF Control 017gap202Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-018NIST CSF Control 018gap302Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-019NIST CSF Control 019gap402Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-020NIST CSF Control 020gap502Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-021NIST CSF Control 021gap102Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-022NIST CSF Control 022gap203Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-023NIST CSF Control 023gap302Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-024NIST CSF Control 024gap402Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.
NIST-025NIST CSF Control 025gap502Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-026NIST CSF Control 026gap102Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-027NIST CSF Control 027gap203Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.
NIST-028NIST CSF Control 028gap302Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
NIST-029NIST CSF Control 029gap402Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-030NIST CSF Control 030gap502Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-031NIST CSF Control 031gap102Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-032NIST CSF Control 032gap202Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-033NIST CSF Control 033gap302Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-034NIST CSF Control 034gap403Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-035NIST CSF Control 035gap502Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-036NIST CSF Control 036gap102Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.
NIST-037NIST CSF Control 037gap202Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-038NIST CSF Control 038gap302Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-039NIST CSF Control 039gap403Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.
NIST-040NIST CSF Control 040gap502Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
NIST-041NIST CSF Control 041gap102Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-042NIST CSF Control 042gap202Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-043NIST CSF Control 043gap302Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-044NIST CSF Control 044gap402Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-045NIST CSF Control 045gap502Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-046NIST CSF Control 046gap103Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-047NIST CSF Control 047gap202Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-048NIST CSF Control 048gap302Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.
NIST-049NIST CSF Control 049gap402Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-050NIST CSF Control 050gap502Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-051NIST CSF Control 051gap103Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.
NIST-052NIST CSF Control 052gap202Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
NIST-053NIST CSF Control 053gap302Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-054NIST CSF Control 054gap402Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-055NIST CSF Control 055gap502Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-056NIST CSF Control 056gap102Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-057NIST CSF Control 057gap202Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-058NIST CSF Control 058gap303Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-059NIST CSF Control 059gap402Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-060NIST CSF Control 060gap502Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.
NIST-061NIST CSF Control 061gap102Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-062NIST CSF Control 062gap202Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-063NIST CSF Control 063gap303Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.
NIST-064NIST CSF Control 064gap402Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
NIST-065NIST CSF Control 065gap502Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-066NIST CSF Control 066gap102Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-067NIST CSF Control 067gap202Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-068NIST CSF Control 068gap302Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-069NIST CSF Control 069gap402Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-070NIST CSF Control 070gap503Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-071NIST CSF Control 071gap102Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-072NIST CSF Control 072gap202Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.
NIST-073NIST CSF Control 073gap302Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-074NIST CSF Control 074gap402Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.
NIST-075NIST CSF Control 075gap503Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.
NIST-076NIST CSF Control 076gap102Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.
NIST-077NIST CSF Control 077gap202Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-078NIST CSF Control 078gap302Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.
NIST-079NIST CSF Control 079gap402Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.
NIST-080NIST CSF Control 080gap502Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.

Evidence Appendix

NIST-001 - NIST CSF Control 001

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-002 - NIST CSF Control 002

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-003 - NIST CSF Control 003

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-004 - NIST CSF Control 004

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-005 - NIST CSF Control 005

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-006 - NIST CSF Control 006

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-007 - NIST CSF Control 007

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-008 - NIST CSF Control 008

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-021 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-032 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-009 - NIST CSF Control 009

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-010 - NIST CSF Control 010

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-034 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-011 - NIST CSF Control 011

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-012 - NIST CSF Control 012

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-013 - NIST CSF Control 013

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-014 - NIST CSF Control 014

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-015 - NIST CSF Control 015

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-016 - NIST CSF Control 016

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-017 - NIST CSF Control 017

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-018 - NIST CSF Control 018

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-019 - NIST CSF Control 019

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-020 - NIST CSF Control 020

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-021 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-032 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-021 - NIST CSF Control 021

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-022 - NIST CSF Control 022

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-034 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-023 - NIST CSF Control 023

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-024 - NIST CSF Control 024

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-025 - NIST CSF Control 025

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-026 - NIST CSF Control 026

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-027 - NIST CSF Control 027

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-028 - NIST CSF Control 028

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-029 - NIST CSF Control 029

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-030 - NIST CSF Control 030

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-031 - NIST CSF Control 031

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-032 - NIST CSF Control 032

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-021 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-032 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-033 - NIST CSF Control 033

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-034 - NIST CSF Control 034

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-034 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-035 - NIST CSF Control 035

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-036 - NIST CSF Control 036

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-037 - NIST CSF Control 037

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-038 - NIST CSF Control 038

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-039 - NIST CSF Control 039

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-040 - NIST CSF Control 040

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-041 - NIST CSF Control 041

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-042 - NIST CSF Control 042

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-043 - NIST CSF Control 043

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-044 - NIST CSF Control 044

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-021 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-032 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-045 - NIST CSF Control 045

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-046 - NIST CSF Control 046

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-034 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-047 - NIST CSF Control 047

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-048 - NIST CSF Control 048

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-049 - NIST CSF Control 049

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-050 - NIST CSF Control 050

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-051 - NIST CSF Control 051

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-052 - NIST CSF Control 052

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-053 - NIST CSF Control 053

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-054 - NIST CSF Control 054

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-055 - NIST CSF Control 055

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-056 - NIST CSF Control 056

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-021 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-032 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-057 - NIST CSF Control 057

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-058 - NIST CSF Control 058

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-034 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-059 - NIST CSF Control 059

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-060 - NIST CSF Control 060

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-061 - NIST CSF Control 061

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-062 - NIST CSF Control 062

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-063 - NIST CSF Control 063

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-064 - NIST CSF Control 064

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-065 - NIST CSF Control 065

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-066 - NIST CSF Control 066

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-067 - NIST CSF Control 067

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-068 - NIST CSF Control 068

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-021 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-032 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-069 - NIST CSF Control 069

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/ANOMALY/ALERTING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/ANOMALY/ALERTING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/ANOMALY/ALERTING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-070 - NIST CSF Control 070

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/INCIDENT/PLANNING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/INCIDENT/PLANNING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/INCIDENT/PLANNING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-034 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-071 - NIST CSF Control 071

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for RESPOND/ANALYSIS/MITIGATION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RESPOND/ANALYSIS/MITIGATION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RESPOND/ANALYSIS/MITIGATION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-010 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-011 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-022 - respond incident planning controls evidence owner review register policy log

tags: respond, incident, planning | hits: 0

No direct evidence hits for this query.

NIST-Q-023 - respond analysis mitigation controls evidence owner review register policy log

tags: respond, analysis, mitigation | hits: 0

No direct evidence hits for this query.

NIST-072 - NIST CSF Control 072

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for RECOVER/CONTINUITY/IMPROVEMENT with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating RECOVER/CONTINUITY/IMPROVEMENT governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for RECOVER/CONTINUITY/IMPROVEMENT.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-012 - recover continuity improvement controls evidence owner review register policy log

tags: recover, continuity, improvement | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-073 - NIST CSF Control 073

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/ASSET/INVENTORY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/ASSET/INVENTORY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/ASSET/INVENTORY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-074 - NIST CSF Control 074

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/CONTEXT/DEPENDENCY with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/CONTEXT/DEPENDENCY governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/CONTEXT/DEPENDENCY.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-013 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-014 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-075 - NIST CSF Control 075

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for IDENTIFY/RISK/GOVERNANCE with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating IDENTIFY/RISK/GOVERNANCE governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for IDENTIFY/RISK/GOVERNANCE.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-001 - identify asset inventory controls evidence owner review register policy log

tags: identify, asset, inventory | hits: 0

No direct evidence hits for this query.

NIST-Q-002 - identify context dependency controls evidence owner review register policy log

tags: identify, context, dependency | hits: 0

No direct evidence hits for this query.

NIST-Q-003 - identify risk governance controls evidence owner review register policy log

tags: identify, risk, governance | hits: 0

No direct evidence hits for this query.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-076 - NIST CSF Control 076

gap | severity 1 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/IDENTITY/ACCESS with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/IDENTITY/ACCESS governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/IDENTITY/ACCESS.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-077 - NIST CSF Control 077

gap | severity 2 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/AWARENESS/TRAINING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/AWARENESS/TRAINING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/AWARENESS/TRAINING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-078 - NIST CSF Control 078

gap | severity 3 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/DATA/ENCRYPTION with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/DATA/ENCRYPTION governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/DATA/ENCRYPTION.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-016 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-079 - NIST CSF Control 079

gap | severity 4 | evidence_count 0

Ensure NIST CSF control coverage for PROTECT/CONFIGURATION/HARDENING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating PROTECT/CONFIGURATION/HARDENING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for PROTECT/CONFIGURATION/HARDENING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-004 - protect identity access controls evidence owner review register policy log

tags: protect, identity, access | hits: 0

No direct evidence hits for this query.

NIST-Q-005 - protect awareness training controls evidence owner review register policy log

tags: protect, awareness, training | hits: 0

No direct evidence hits for this query.

NIST-Q-006 - protect data encryption controls evidence owner review register policy log

tags: protect, data, encryption | hits: 0

No direct evidence hits for this query.

NIST-Q-007 - protect configuration hardening controls evidence owner review register policy log

tags: protect, configuration, hardening | hits: 0

No direct evidence hits for this query.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-080 - NIST CSF Control 080

gap | severity 5 | evidence_count 0

Ensure NIST CSF control coverage for DETECT/MONITORING/LOGGING with documented ownership and operating cadence.

Expected evidence: Policy/procedure artifact demonstrating DETECT/MONITORING/LOGGING governance and ownership.; Operational evidence (logs, reports, tickets, or records) proving control execution for DETECT/MONITORING/LOGGING.; Recent review evidence with remediation tracking where exceptions were found.

NIST-Q-008 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-009 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-020 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

NIST-Q-021 - detect anomaly alerting controls evidence owner review register policy log

tags: detect, anomaly, alerting | hits: 0

No direct evidence hits for this query.

NIST-Q-032 - detect monitoring logging controls evidence owner review register policy log

tags: detect, monitoring, logging | hits: 0

No direct evidence hits for this query.

Query Log

query_idquery_texttagshits
NIST-Q-001identify asset inventory controls evidence owner review register policy logidentify, asset, inventory0
NIST-Q-002identify context dependency controls evidence owner review register policy logidentify, context, dependency0
NIST-Q-003identify risk governance controls evidence owner review register policy logidentify, risk, governance0
NIST-Q-004protect identity access controls evidence owner review register policy logprotect, identity, access0
NIST-Q-005protect awareness training controls evidence owner review register policy logprotect, awareness, training0
NIST-Q-006protect data encryption controls evidence owner review register policy logprotect, data, encryption0
NIST-Q-007protect configuration hardening controls evidence owner review register policy logprotect, configuration, hardening0
NIST-Q-008detect monitoring logging controls evidence owner review register policy logdetect, monitoring, logging0
NIST-Q-009detect anomaly alerting controls evidence owner review register policy logdetect, anomaly, alerting0
NIST-Q-010respond incident planning controls evidence owner review register policy logrespond, incident, planning0
NIST-Q-011respond analysis mitigation controls evidence owner review register policy logrespond, analysis, mitigation0
NIST-Q-012recover continuity improvement controls evidence owner review register policy logrecover, continuity, improvement0
NIST-Q-013identify asset inventory controls evidence owner review register policy logidentify, asset, inventory0
NIST-Q-014identify context dependency controls evidence owner review register policy logidentify, context, dependency0
NIST-Q-015identify risk governance controls evidence owner review register policy logidentify, risk, governance0
NIST-Q-016protect identity access controls evidence owner review register policy logprotect, identity, access0
NIST-Q-017protect awareness training controls evidence owner review register policy logprotect, awareness, training0
NIST-Q-018protect data encryption controls evidence owner review register policy logprotect, data, encryption0
NIST-Q-019protect configuration hardening controls evidence owner review register policy logprotect, configuration, hardening0
NIST-Q-020detect monitoring logging controls evidence owner review register policy logdetect, monitoring, logging0
NIST-Q-021detect anomaly alerting controls evidence owner review register policy logdetect, anomaly, alerting0
NIST-Q-022respond incident planning controls evidence owner review register policy logrespond, incident, planning0
NIST-Q-023respond analysis mitigation controls evidence owner review register policy logrespond, analysis, mitigation0
NIST-Q-024recover continuity improvement controls evidence owner review register policy logrecover, continuity, improvement0
NIST-Q-025identify asset inventory controls evidence owner review register policy logidentify, asset, inventory0
NIST-Q-026identify context dependency controls evidence owner review register policy logidentify, context, dependency0
NIST-Q-027identify risk governance controls evidence owner review register policy logidentify, risk, governance0
NIST-Q-028protect identity access controls evidence owner review register policy logprotect, identity, access0
NIST-Q-029protect awareness training controls evidence owner review register policy logprotect, awareness, training0
NIST-Q-030protect data encryption controls evidence owner review register policy logprotect, data, encryption0
NIST-Q-031protect configuration hardening controls evidence owner review register policy logprotect, configuration, hardening0
NIST-Q-032detect monitoring logging controls evidence owner review register policy logdetect, monitoring, logging0
NIST-Q-033detect anomaly alerting controls evidence owner review register policy logdetect, anomaly, alerting0
NIST-Q-034respond incident planning controls evidence owner review register policy logrespond, incident, planning0
NIST-Q-035respond analysis mitigation controls evidence owner review register policy logrespond, analysis, mitigation0
NIST-Q-036recover continuity improvement controls evidence owner review register policy logrecover, continuity, improvement0
NIST-Q-037identify asset inventory controls evidence owner review register policy logidentify, asset, inventory0
NIST-Q-038identify context dependency controls evidence owner review register policy logidentify, context, dependency0
NIST-Q-039identify risk governance controls evidence owner review register policy logidentify, risk, governance0
NIST-Q-040protect identity access controls evidence owner review register policy logprotect, identity, access0
NIST-Q-041protect awareness training controls evidence owner review register policy logprotect, awareness, training0
NIST-Q-042protect data encryption controls evidence owner review register policy logprotect, data, encryption0
NIST-Q-043protect configuration hardening controls evidence owner review register policy logprotect, configuration, hardening0
NIST-Q-044detect monitoring logging controls evidence owner review register policy logdetect, monitoring, logging0
NIST-Q-045detect anomaly alerting controls evidence owner review register policy logdetect, anomaly, alerting0

Query Log

query_idquery_texttagshits
NIST-Q-001identify asset inventory controls evidence owner review register policy logidentify, asset, inventory0
NIST-Q-002identify context dependency controls evidence owner review register policy logidentify, context, dependency0
NIST-Q-003identify risk governance controls evidence owner review register policy logidentify, risk, governance0
NIST-Q-004protect identity access controls evidence owner review register policy logprotect, identity, access0
NIST-Q-005protect awareness training controls evidence owner review register policy logprotect, awareness, training0
NIST-Q-006protect data encryption controls evidence owner review register policy logprotect, data, encryption0
NIST-Q-007protect configuration hardening controls evidence owner review register policy logprotect, configuration, hardening0
NIST-Q-008detect monitoring logging controls evidence owner review register policy logdetect, monitoring, logging0
NIST-Q-009detect anomaly alerting controls evidence owner review register policy logdetect, anomaly, alerting0
NIST-Q-010respond incident planning controls evidence owner review register policy logrespond, incident, planning0
NIST-Q-011respond analysis mitigation controls evidence owner review register policy logrespond, analysis, mitigation0
NIST-Q-012recover continuity improvement controls evidence owner review register policy logrecover, continuity, improvement0
NIST-Q-013identify asset inventory controls evidence owner review register policy logidentify, asset, inventory0
NIST-Q-014identify context dependency controls evidence owner review register policy logidentify, context, dependency0
NIST-Q-015identify risk governance controls evidence owner review register policy logidentify, risk, governance0
NIST-Q-016protect identity access controls evidence owner review register policy logprotect, identity, access0
NIST-Q-017protect awareness training controls evidence owner review register policy logprotect, awareness, training0
NIST-Q-018protect data encryption controls evidence owner review register policy logprotect, data, encryption0
NIST-Q-019protect configuration hardening controls evidence owner review register policy logprotect, configuration, hardening0
NIST-Q-020detect monitoring logging controls evidence owner review register policy logdetect, monitoring, logging0
NIST-Q-021detect anomaly alerting controls evidence owner review register policy logdetect, anomaly, alerting0
NIST-Q-022respond incident planning controls evidence owner review register policy logrespond, incident, planning0
NIST-Q-023respond analysis mitigation controls evidence owner review register policy logrespond, analysis, mitigation0
NIST-Q-024recover continuity improvement controls evidence owner review register policy logrecover, continuity, improvement0
NIST-Q-025identify asset inventory controls evidence owner review register policy logidentify, asset, inventory0
NIST-Q-026identify context dependency controls evidence owner review register policy logidentify, context, dependency0
NIST-Q-027identify risk governance controls evidence owner review register policy logidentify, risk, governance0
NIST-Q-028protect identity access controls evidence owner review register policy logprotect, identity, access0
NIST-Q-029protect awareness training controls evidence owner review register policy logprotect, awareness, training0
NIST-Q-030protect data encryption controls evidence owner review register policy logprotect, data, encryption0
NIST-Q-031protect configuration hardening controls evidence owner review register policy logprotect, configuration, hardening0
NIST-Q-032detect monitoring logging controls evidence owner review register policy logdetect, monitoring, logging0
NIST-Q-033detect anomaly alerting controls evidence owner review register policy logdetect, anomaly, alerting0
NIST-Q-034respond incident planning controls evidence owner review register policy logrespond, incident, planning0
NIST-Q-035respond analysis mitigation controls evidence owner review register policy logrespond, analysis, mitigation0
NIST-Q-036recover continuity improvement controls evidence owner review register policy logrecover, continuity, improvement0
NIST-Q-037identify asset inventory controls evidence owner review register policy logidentify, asset, inventory0
NIST-Q-038identify context dependency controls evidence owner review register policy logidentify, context, dependency0
NIST-Q-039identify risk governance controls evidence owner review register policy logidentify, risk, governance0
NIST-Q-040protect identity access controls evidence owner review register policy logprotect, identity, access0
NIST-Q-041protect awareness training controls evidence owner review register policy logprotect, awareness, training0
NIST-Q-042protect data encryption controls evidence owner review register policy logprotect, data, encryption0
NIST-Q-043protect configuration hardening controls evidence owner review register policy logprotect, configuration, hardening0
NIST-Q-044detect monitoring logging controls evidence owner review register policy logdetect, monitoring, logging0
NIST-Q-045detect anomaly alerting controls evidence owner review register policy logdetect, anomaly, alerting0