PlumbTrackLive demoGRC Risk System

Compliance coverage

The register and the governance policy library rolled up against the NIST Cybersecurity Framework (CSF) 2.0 NIST CSF 2.0 Functions and CIS (Center for Internet Security) Controls v8 CIS Controls v8. Framework references are parsed and aggregated, so coverage and gaps are visible at a glance instead of buried in a text field. Risks cover the technical Functions; policies cover the governance ones (Govern / Respond / Recover).

0%
CSF coverage - 0 of 6 Functions
0
Subcategories - CSF 2.0 outcomes addressed
0
CIS controls - v8 controls touched
0
Policies in force - governance mapped to CSF
6
Function gaps - no risk or policy covers them

NIST CSF 2.0 Functions

Bar reflects how many distinct subcategories a Function is addressed against, by a risk or a policy. Worst-residual is the highest residual severity still open under that Function; policy-only Functions show “governed by policy”.

GV
Govern
Risk strategy, roles, policy - established, communicated, monitored.
No mapped risk or policygap
ID
Identify
Current cybersecurity risks to assets are understood.
No mapped risk or policygap
PR
Protect
Safeguards to manage risks are used.
No mapped risk or policygap
DE
Detect
Possible attacks and compromises are found and analyzed.
No mapped risk or policygap
RS
Respond
Actions on a detected incident are taken.
No mapped risk or policygap
RC
Recover
Assets and operations affected by an incident are restored.
No mapped risk or policygap

⚠ Coverage gaps

No risk in the register maps to %s. For the capstone this is expected — the register is preventive/detective — but a complete GRC program should carry at least a governance risk (policy/ownership) and an incident response & recovery risk. Add one via + New risk with a framework ref like NIST CSF RS.MA-01 or NIST CSF RC.RP-01 to close the gap. Each gap is also tracked as an item on the POA&M.

Subcategory → risk / policy map

CSF 2.0 subcategoryOutcomeAddressed by
none

CIS Controls v8 touched

ControlNameAddressed by
none