Compliance coverage
The register and the governance policy library rolled up against the NIST Cybersecurity Framework (CSF) 2.0 NIST CSF 2.0 Functions and CIS (Center for Internet Security) Controls v8 CIS Controls v8. Framework references are parsed and aggregated, so coverage and gaps are visible at a glance instead of buried in a text field. Risks cover the technical Functions; policies cover the governance ones (Govern / Respond / Recover).
NIST CSF 2.0 Functions
Bar reflects how many distinct subcategories a Function is addressed against, by a risk or a policy. Worst-residual is the highest residual severity still open under that Function; policy-only Functions show “governed by policy”.
⚠ Coverage gaps
No risk in the register maps to %s. For the capstone this is expected — the register is preventive/detective — but a complete GRC program should carry at least a governance risk (policy/ownership) and an incident response & recovery risk. Add one via + New risk with a framework ref like NIST CSF RS.MA-01 or NIST CSF RC.RP-01 to close the gap. Each gap is also tracked as an item on the POA&M.
Subcategory → risk / policy map
| CSF 2.0 subcategory | Outcome | Addressed by |
|---|---|---|
| none | ||
CIS Controls v8 touched
| Control | Name | Addressed by |
|---|---|---|
| none | ||