Security Program Workspace

Track security controls, owners, evidence, risks, and remediation. Navigate NIST CSF, ISO 27001, SOC 2, and CIS references in a private browser workspace.

Advertisement

Turn a baseline into accountable work

Record implementation status, owner, target date, and evidence references for twelve foundational capabilities spanning Govern, Identify, Protect, Detect, Respond, and Recover. Weighted coverage and prioritized gaps update as the program changes.

Navigate frameworks without overstating equivalence

References to NIST CSF 2.0, ISO/IEC 27001:2022, SOC 2, and CIS Controls v8 are navigation aids, not an official crosswalk or certification opinion. The local risk register scores inherent likelihood and impact; legal, audit, and treatment-effectiveness decisions require qualified review.

Frequently Asked Questions

Can this tool certify compliance?+

No. It is a planning and readiness aid. Certification, attestation, legal interpretation, and audit conclusions require the applicable criteria, scoped evidence, and qualified independent reviewers.

Are the framework references official equivalencies?+

No. They are directional navigation references that help locate adjacent requirements in NIST CSF 2.0, ISO/IEC 27001:2022, SOC 2, and CIS Controls v8. Always verify the current authoritative framework text.

How is coverage scored?+

Verified controls receive full weight, implemented controls 80%, partial controls 50%, planned controls 15%, and not-started controls zero. Not-applicable controls are removed from the denominator; applicability itself should be documented and reviewed.

Related tools

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.