Use live security findings as NIST CSF assessment evidence.
A CSF assessment asks what your current profile actually is. Retrievy supplies the technical half of that answer from collected configuration, refreshed on every scan rather than gathered once a year.
From finding to subcategory
Evidence attaches at subcategory level, which is where an assessment conversation happens.
-
1
Observed
Collected condition
An observed configuration state on a connected cloud account, directory, or device.
-
2
Associated
Subcategory evidence
The finding is associated with the subcategories it informs, inside the relevant function.
-
3
Presented
Current profile
The function view shows what the evidence supports today, so a target profile can be set against something real.
-
4
Refreshed
Reassessment
Each scan refreshes the evidence, so profile drift is visible between formal assessments rather than at the next one.
Where the evidence lands
Identify and Protect receive the most direct support: asset and identity inventory, access control, data protection settings, and platform configuration are exactly what read-only collection observes. Detect receives partial support, because Retrievy can evidence whether logging and audit settings are configured, though not whether anyone is watching the output.
Govern, Respond and Recover describe organizational capability. Retrievy can evidence configured backup or retention settings where they exist, but a recovery plan, an exercise, or a decision-making structure is not a configuration and is not treated as one.
Current profile, refreshed
The usual difficulty with a CSF profile is that it ages the moment it is written. Because each scan re-collects the same evidence, the technical portion of the profile reflects the estate as it is now, and a subcategory that regressed after a change is visible without waiting for the next assessment cycle.
That is a reporting improvement, not a determination. Mapping findings to NIST CSF does not certify compliance with a program, and the CSF itself is a voluntary framework describing outcomes rather than a standard anyone can be certified against by scanning.
Using it with an assessor
The practical value is that the technical evidence arrives already organized by function and subcategory, with severity, ownership and the verifying scan attached. The assessment conversation then starts from what is demonstrably true and spends its time on the organizational subcategories where judgement is actually required.
What the NIST CSF view does not claim
- Mapping findings to NIST CSF does not certify compliance with a program.
- Govern, Respond and Recover subcategories describing process or capability fall outside the mapping.
- Evidence that logging is configured is not evidence that detection is operating.
- The CSF is a voluntary outcome framework; no scan produces a CSF certification.
- Coverage is limited to the sources you connected and the scopes you granted.
Frequently asked questions
- Can Retrievy produce a NIST CSF profile for us?
- It produces the technical evidence portion, organized by function and subcategory and refreshed on every scan. A complete profile includes organizational subcategories that require judgement and interview. Mapping findings to NIST CSF does not certify compliance with a program.
- Does it cover the Govern function added in CSF 2.0?
- Only where a subcategory has a configuration expression. Govern is largely about roles, policy and oversight, which are organizational rather than technical, so most of its subcategories fall outside the mapping rather than being assessed.
- How does this differ from the CIS Controls view?
- The findings are the same; the organization differs. CIS Controls group by defensive action, CSF groups by outcome function. Teams reporting against both get both views from one scan without collecting evidence twice.
- How often is the evidence refreshed?
- On every scan. That is the main difference from a point-in-time assessment: a subcategory that regressed after an infrastructure change shows up when the change is scanned, not at the next assessment cycle.
Related resources
Bring current evidence to the assessment.
Connect a source read-only and see the technical half of your CSF profile assembled from collected configuration.