Skip to content
NIST CSF

Use live security findings as NIST CSF assessment evidence.

A CSF assessment asks what your current profile actually is. Retrievy supplies the technical half of that answer from collected configuration, refreshed on every scan rather than gathered once a year.

How evidence flows

From finding to subcategory

Evidence attaches at subcategory level, which is where an assessment conversation happens.

  1. 1 Observed

    Collected condition

    An observed configuration state on a connected cloud account, directory, or device.

  2. 2 Associated

    Subcategory evidence

    The finding is associated with the subcategories it informs, inside the relevant function.

  3. 3 Presented

    Current profile

    The function view shows what the evidence supports today, so a target profile can be set against something real.

  4. 4 Refreshed

    Reassessment

    Each scan refreshes the evidence, so profile drift is visible between formal assessments rather than at the next one.

Where the evidence lands

Identify and Protect receive the most direct support: asset and identity inventory, access control, data protection settings, and platform configuration are exactly what read-only collection observes. Detect receives partial support, because Retrievy can evidence whether logging and audit settings are configured, though not whether anyone is watching the output.

Govern, Respond and Recover describe organizational capability. Retrievy can evidence configured backup or retention settings where they exist, but a recovery plan, an exercise, or a decision-making structure is not a configuration and is not treated as one.

Current profile, refreshed

The usual difficulty with a CSF profile is that it ages the moment it is written. Because each scan re-collects the same evidence, the technical portion of the profile reflects the estate as it is now, and a subcategory that regressed after a change is visible without waiting for the next assessment cycle.

That is a reporting improvement, not a determination. Mapping findings to NIST CSF does not certify compliance with a program, and the CSF itself is a voluntary framework describing outcomes rather than a standard anyone can be certified against by scanning.

Using it with an assessor

The practical value is that the technical evidence arrives already organized by function and subcategory, with severity, ownership and the verifying scan attached. The assessment conversation then starts from what is demonstrably true and spends its time on the organizational subcategories where judgement is actually required.

Boundaries

What the NIST CSF view does not claim

  • Mapping findings to NIST CSF does not certify compliance with a program.
  • Govern, Respond and Recover subcategories describing process or capability fall outside the mapping.
  • Evidence that logging is configured is not evidence that detection is operating.
  • The CSF is a voluntary outcome framework; no scan produces a CSF certification.
  • Coverage is limited to the sources you connected and the scopes you granted.
Questions

Frequently asked questions

Can Retrievy produce a NIST CSF profile for us?
It produces the technical evidence portion, organized by function and subcategory and refreshed on every scan. A complete profile includes organizational subcategories that require judgement and interview. Mapping findings to NIST CSF does not certify compliance with a program.
Does it cover the Govern function added in CSF 2.0?
Only where a subcategory has a configuration expression. Govern is largely about roles, policy and oversight, which are organizational rather than technical, so most of its subcategories fall outside the mapping rather than being assessed.
How does this differ from the CIS Controls view?
The findings are the same; the organization differs. CIS Controls group by defensive action, CSF groups by outcome function. Teams reporting against both get both views from one scan without collecting evidence twice.
How often is the evidence refreshed?
On every scan. That is the main difference from a point-in-time assessment: a subcategory that regressed after an infrastructure change shows up when the change is scanned, not at the next assessment cycle.

Bring current evidence to the assessment.

Connect a source read-only and see the technical half of your CSF profile assembled from collected configuration.