THE MODEL
Six lenses for finding the real gap.
Decision rights, accountability, policy hierarchy, risk appetite, committees, exceptions, and executive reporting.
Asset and business context, threat scenarios, likelihood, impact, treatment, acceptance, dependencies, and residual risk.
Administrative, technical, and physical safeguards mapped to requirements and implemented at the correct scope.
Logs, configurations, tickets, approvals, tests, inventories, attestations, metrics, and proof that controls operate.
Applicable laws, contracts, policies, standards, regulatory duties, audit commitments, and customer obligations.
Detection, response, recovery, continuity, third-party failure, exercises, lessons learned, and measurable improvement.
REFERENCE STACK
Crosswalk once. Reuse everywhere.
Build a common control spine instead of treating every framework as a separate universe. A practical enterprise baseline can map control objectives across NIST CSF 2.0, NIST SP 800-53, NIST RMF, NIST AI RMF, CIS Controls, Zero Trust principles, privacy requirements, contractual obligations, and sector-specific requirements where applicable.
Describe the outcome before mapping framework identifiers.
One strong control and evidence package can satisfy multiple overlapping requirements.
Identify systems, data, identities, vendors, facilities, AI models, agents, and processes covered.
Record owner, source, freshness, retention, test frequency, and source of truth.
ASSESSMENT ENGINE
Score the gap, not the paperwork.
Maturity: 0 absent · 1 ad hoc · 2 documented · 3 implemented · 4 measured · 5 continuously improved.
Evidence: none · anecdotal · partial · repeatable · independently verifiable.
The interactive engine applies this model across 24 controls, calculates domain and overall maturity, measures evidence confidence, identifies sub-3 gaps, and creates a prioritized 30/60/90-day view.
BEGIN ASSESSMENT →The goal is not to become compliant on paper. Know what must be true, prove what is true, expose what is not, and govern the difference.
EXECUTIVE OUTPUT
Turn GRC into a navigation system.
Material scenarios, exposure, treatment status and accountable ownership.
Coverage, effectiveness, evidence confidence, exceptions and dependencies.
Obligations, deficiencies, commitments, deadlines and accepted exceptions.
What gets funded first, why it reduces risk, dependencies and the risk of delay.