NIST Cybersecurity Framework 2.0 — Core + Tiers + Profiles

NIST Cybersecurity Framework 2.0 — Core + Tiers + Profiles — 88% of in-scope requirements covered.

130 requirements · 130 in scope (105 enforced · 10 designed · 15 advisory). The 88% is weighted over the in-scope base.

Source: NIST CSF 2.0 Core (NIST CSWP 29, February 2024) — 6 functions, 22 categories, 106 subcategories — plus Implementation Tiers (§3.1) and Profiles (§4). Deep-mapping extended 2026-05-29 (Wave-Ralph-B) to cover Implementation Tiers across all three dimensions (Risk Governance, Risk Management Process, External Engagement) and Profile creation lifecycle. · License: NIST publications are US-Government works in the public domain.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
DE Detect111001093%
GV Govern312326082%
ID Identify211920095%
Implementation Tiers — Risk Governance4301081%
Implementation Tiers — Risk Management Process4301081%
Implementation Tiers — External Engagement4301081%
Profiles & Tiers (§4)121020092%
PR Protect221345074%
RC Recover88000100%
RS Respond1313000100%

Every requirement → the KYE™ artefact that enforces it

IDTitleStatusKYE™ enforcement
nist-csf.DE.CM-01Networks and network services are monitored to find potentially adverse eventsenforcedaudit_events: kye.evidence.decision_map.v1, kye.signal.decision.admitted.v1
engines: internal, internal
workers: kye-gateway, kye-edge-arbiter
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
nist-csf.DE.CM-02The physical environment is monitored to find potentially adverse eventsadvisoryconstitution_refs: constitution/00-INDEX.md
nist-csf.DE.CM-03Personnel activity and technology usage are monitored to find potentially adverse eventsenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.DE.CM-06External service provider activities and services are monitored to find potentially adverse eventsenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.DE.CM-09Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse eventsenforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.stable_drift.detected.v1
engines: internal
workers: kye-drift-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.DE.AE-02Potentially adverse events are analyzed to better understand associated activitiesenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.DE.AE-03Information is correlated from multiple sourcesenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.DE.AE-04The estimated impact and scope of adverse events are understoodenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.DE.AE-06Information on adverse events is provided to authorized staff and toolsenforcedaudit_events: kye.comms.dispatched.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nist-csf.DE.AE-07Cyber threat intelligence and other contextual information are integrated into the analysisenforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.stable_drift.detected.v1
engines: internal
workers: kye-drift-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.DE.AE-08Incidents are declared when adverse events meet the defined incident criteriaenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.GV.OC-01The organizational mission is understood and informs cybersecurity risk managementadvisoryaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.GV.OC-02Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and consideredadvisoryaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.GV.OC-03Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managedenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/00-INDEX.md
nist-csf.GV.OC-04Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicatedenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.OC-05Outcomes, capabilities, and services that the organization depends on are understood and communicateddesignedaudit_events: kye.spof.path_to_full.v1
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.RM-01Risk management objectives are established and agreed to by organizational stakeholdersenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.GV.RM-02Risk appetite and risk tolerance statements are established, communicated, and maintainedenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.GV.RM-03Cybersecurity risk management activities and outcomes are included in enterprise risk management processesenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.GV.RM-04Strategic direction that describes appropriate risk response options is established and communicatedenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.GV.RM-05Lines of communication across the organization are established for cybersecurity risksenforcedaudit_events: kye.comms.dispatched.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nist-csf.GV.RM-06A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicatedenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.GV.RM-07Strategic opportunities (i.e., positive risks) are characterized and included in organizational cybersecurity risk discussionsadvisoryaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.GV.RR-01Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improvingenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.GV.RR-02Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforcedenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.GV.RR-03Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policiesadvisoryaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.GV.RR-04Cybersecurity is included in human resources practicesadvisoryaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.GV.PO-01Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforcedenforcedaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.GV.PO-02Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational missionenforcedaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and directionenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/00-INDEX.md
nist-csf.GV.OV-02The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risksenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/00-INDEX.md
nist-csf.GV.OV-03Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments neededenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/00-INDEX.md
nist-csf.GV.SC-01A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholdersenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.SC-02Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externallyenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processesenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.SC-04Suppliers are known and prioritized by criticalityenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.SC-05Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third partiesenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.SC-06Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationshipsadvisoryaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.SC-07The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationshipenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.SC-08Relevant suppliers and other third parties are included in incident planning, response, and recovery activitiesenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.GV.SC-09Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycledesignedaudit_events: kye.spof.path_to_full.v1
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.GV.SC-10Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreementenforcedaudit_events: kye.revocation.event.v1, kye.signal.revocation.cascaded.v1
engines: internal
workers: kye-authority-revocation-orchestrator
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.ID.AM-01Inventories of hardware managed by the organization are maintainedenforcedaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.ID.AM-02Inventories of software, services, and systems managed by the organization are maintainedenforcedaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.ID.AM-03Representations of the organization's authorized network communication and internal and external network data flows are maintainedenforcedaudit_events: kye.evidence.decision_map.v1, kye.signal.decision.admitted.v1
engines: internal, internal
workers: kye-gateway, kye-edge-arbiter
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
nist-csf.ID.AM-04Inventories of services provided by suppliers are maintainedenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.ID.AM-05Assets are prioritized based on classification, criticality, resources, and impact on the missionenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.ID.AM-07Inventories of data and corresponding metadata for designated data types are maintainedenforcedaudit_events: kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
nist-csf.ID.AM-08Systems, hardware, software, services, and data are managed throughout their life cyclesenforcedaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.ID.RA-01Vulnerabilities in assets are identified, validated, and recordedenforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.stable_drift.detected.v1
engines: internal
workers: kye-drift-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.ID.RA-02Cyber threat intelligence is received from information sharing forums and sourcesenforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.stable_drift.detected.v1
engines: internal
workers: kye-drift-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.ID.RA-03Internal and external threats to the organization are identified and recordedenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.ID.RA-04Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recordedenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.ID.RA-05Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritizationenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.ID.RA-06Risk responses are chosen, prioritized, planned, tracked, and communicatedenforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.ID.RA-07Changes and exceptions are managed, assessed for risk impact, recorded, and trackedenforcedaudit_events: kye.governedui.approval.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/36-GOVERNEDUI.md
nist-csf.ID.RA-08Processes for receiving, analyzing, and responding to vulnerability disclosures are establishedenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.ID.RA-09The authenticity and integrity of hardware and software are assessed prior to acquisition and usedesignedaudit_events: kye.evidence.tool_call_pin.v1, kye.agent.mcp_allow_list.v1
constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md
nist-csf.ID.RA-10Critical suppliers are assessed prior to acquisitionenforcedaudit_events: kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.ID.IM-01Improvements are identified from evaluationsenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.ID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third partiesenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.ID.IM-03Improvements are identified from execution of operational processes, procedures, and activitiesdesignedaudit_events: kye.signal.drift.detected.v1
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md
nist-csf.ID.IM-04Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improvedenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.IT.RG-T1Implementation Tier 1 (Partial) — Risk Governance: cybersecurity risk-management practices are not formalised, and risk is managed in an ad hoc and sometimes reactive manner.advisoryaudit_events: kye.compliance.attestation.v1
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.IT.RG-T2Implementation Tier 2 (Risk-Informed) — Risk Governance: risk-management practices are approved by management but may not be established as organisation-wide policy.enforcedaudit_events: kye.governedui.approval.v1, kye.compliance.attestation.v1
governedui_modules: kye.governedui.module.action_approval.v1
constitution_refs: constitution/36-GOVERNEDUI.md
nist-csf.IT.RG-T3Implementation Tier 3 (Repeatable) — Risk Governance: risk-management practices are formally approved and expressed as policy; cybersecurity practices are regularly updated based on the application of risk-management processes to changes in business / mission requirements and a changing threat landscape.enforcedaudit_events: kye.compliance.attestation.v1, kye.reconciliation.verdict.v1
engines: internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md, constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.IT.RG-T4Implementation Tier 4 (Adaptive) — Risk Governance: the organisation adapts its cybersecurity practices based on previous and current cybersecurity activities, including lessons learnt and predictive indicators.enforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.stable_drift.detected.v1, kye.assurance.audit_replay_report.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/41-ERROR-HORIZONS.md
nist-csf.IT.RM-T1Implementation Tier 1 (Partial) — Risk Management Process: there is limited awareness of cybersecurity risk at the organisational level, and risk management is implemented case-by-case.advisoryaudit_events: kye.risk.score.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.IT.RM-T2Implementation Tier 2 (Risk-Informed) — Risk Management Process: risk-informed, management-approved processes and procedures are defined and implemented; staff has adequate resources.enforcedaudit_events: kye.risk_assessment.v1, kye.risk.score.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.IT.RM-T3Implementation Tier 3 (Repeatable) — Risk Management Process: the organisation's risk-management practices are formally approved and expressed as policy; methods to respond effectively to changes in risk are in place.enforcedaudit_events: kye.risk.score.v1, kye.reconciliation.verdict.v1, kye.signal.revocation.cascaded.v1
engines: internal, internal, internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md
nist-csf.IT.RM-T4Implementation Tier 4 (Adaptive) — Risk Management Process: the organisation uses real-time or near-real-time information to understand and consistently act upon cybersecurity risk associated with the products and services it provides and uses.enforcedaudit_events: kye.risk.score.v1, kye.signal.drift.detected.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/35-STREAMING-LOGS.md
nist-csf.IT.EE-T1Implementation Tier 1 (Partial) — External Engagement: the organisation does not understand its role in the larger ecosystem with respect to either its dependencies or dependants.advisoryaudit_events: kye.subprocessor.v1
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nist-csf.IT.EE-T2Implementation Tier 2 (Risk-Informed) — External Engagement: the organisation collaborates with and receives some information from external parties, generates some of its own, but may not share information externally.enforcedaudit_events: kye.subprocessor.v1, kye.federation.cross_org_delegation.v1
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/49-UNIVERSAL-ENGAGEMENT-RAIL.md
nist-csf.IT.EE-T3Implementation Tier 3 (Repeatable) — External Engagement: the organisation collaborates with and receives information from partners on a regular basis, and contributes its own information; the organisation is aware of risks associated with its products and services and its place in the larger ecosystem.enforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.subprocessor.v1, kye.comms.dispatched.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md, constitution/49-UNIVERSAL-ENGAGEMENT-RAIL.md
nist-csf.IT.EE-T4Implementation Tier 4 (Adaptive) — External Engagement: the organisation receives, generates and reviews prioritised information that informs continuous analysis of its risks as the threat and technology landscape evolves; the organisation shares information through formal and informal mechanisms.enforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.signal.drift.detected.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/38-COMMS-RAIL.md
nist-csf.PF.CurrentCurrent Profile — describes the cybersecurity outcomes that the organisation is currently achieving (or attempting to achieve) and the extent to which each outcome is being achieved.enforcedaudit_events: kye.compliance.attestation.v1, kye.reconciliation.verdict.v1
engines: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.PF.TargetTarget Profile — describes the desired cybersecurity outcomes the organisation has selected and prioritised for achieving its risk-management objectives.designedaudit_events: kye.compliance.attestation.v1
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md, constitution/53-COHESION-CASCADE.md
nist-csf.PF.CommunityCommunity Profile — a sectoral, technology- or threat-specific baseline of CSF outcomes for use as a starting point by similar organisations.enforcedaudit_events: kye.compliance.attestation.v1
sector_packs: kye:sector-pack:financial-services, kye:sector-pack:healthcare
constitution_refs: constitution/29-PROFILES-LITE.md, constitution/49-UNIVERSAL-ENGAGEMENT-RAIL.md
nist-csf.PF.OrgOrganisational Profile — describes a specific organisation's current and / or target cybersecurity posture in terms of Core outcomes.designedaudit_events: kye.compliance.attestation.v1
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.PF.ScopeScope the Organisational Profile — define the boundaries of the Organisational Profile (entire enterprise, subsidiary, system or service) so the cybersecurity outcomes are clearly bounded.enforcedaudit_events: kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.PF.GatherGather information needed to prepare the Organisational Profile — collect information about the organisation's risks, priorities, dependencies, resources, threats and previous incidents.enforcedaudit_events: kye.audit.event.v1, kye.signal.incident.opened.v1, kye.subprocessor.v1
engines: internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.PF.CreateCreate the Organisational Profile — for each selected Core element, document the current and / or target state along with the rationale, considerations and applicability.enforcedaudit_events: kye.compliance.attestation.v1
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.PF.AnalyseAnalyse gaps and create an action plan — compare the current and target Profiles, identify gaps, prioritise actions, and assign owners and timeframes.enforcedaudit_events: kye.signal.drift.detected.v1, kye.spof.path_to_full.v1
engines: internal
registries: internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.PF.ImplementImplement the action plan and update the Organisational Profile — execute identified actions, track progress, and update the Profile to reflect the new state.enforcedaudit_events: kye.reconciliation.verdict.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md, constitution/53-COHESION-CASCADE.md
nist-csf.PF.TiersImplementation Tiers — characterise the rigour of an organisation's cybersecurity risk-governance and risk-management practices along the Partial / Risk-Informed / Repeatable / Adaptive scale.enforcedaudit_events: kye.compliance.attestation.v1
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/40-IMPLEMENTATION-CANONICAL.md
nist-csf.PF.UpdateMaintain and continually improve the Organisational Profile — update the Profile on an ongoing basis to reflect the current and target cybersecurity posture, adjusting priorities and actions as needed.enforcedaudit_events: kye.compliance.attestation.v1, kye.signal.compliance_card.refreshed.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.PF.CybersecurityCybersecurity Supply Chain Risk Management profile — a specialised Community Profile for supply-chain risk that organisations can adopt or adapt.enforcedaudit_events: kye.subprocessor.v1, kye.compliance.attestation.v1, kye.federation.cross_org_delegation.v1
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/52-DELEGATED-AGENT-BINDING.md
nist-csf.PR.AA-01Identities and credentials for authorized users, services, and hardware are managed by the organizationenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.PR.AA-02Identities are proofed and bound to credentials based on the context of interactionsenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.PR.AA-03Users, services, and hardware are authenticatedenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.PR.AA-04Identity assertions are protected, conveyed, and verifiedenforcedaudit_events: kye.signing.multisig_envelope.v1
engines: internal, internal
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.PR.AA-05Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of dutiesenforcedaudit_events: kye.authority.grant.v1, kye.evidence.decision_map.v1, kye.purpose.permission.v1
engines: internal, internal
workers: kye-pdp
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.PR.AA-06Physical access to assets is managed, monitored, and enforced commensurate with riskadvisoryconstitution_refs: constitution/00-INDEX.md
nist-csf.PR.AT-01Personnel are provided with awareness and training so they possess the knowledge and skills to perform general tasks with cybersecurity risks in mindadvisoryaudit_events: kye.comms.dispatched.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nist-csf.PR.AT-02Individuals in specialized roles are provided with awareness and training so they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mindadvisoryaudit_events: kye.comms.dispatched.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nist-csf.PR.DS-01The confidentiality, integrity, and availability of data-at-rest are protectedenforcedaudit_events: kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
nist-csf.PR.DS-02The confidentiality, integrity, and availability of data-in-transit are protectedenforcedaudit_events: kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
nist-csf.PR.DS-10The confidentiality, integrity, and availability of data-in-use are protectedenforcedaudit_events: kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
nist-csf.PR.DS-11Backups of data are created, protected, maintained, and testedenforcedaudit_events: kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver, kye-d1-backup-worker
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.PR.PS-01Configuration management practices are established and applieddesignedaudit_events: kye.signal.drift.detected.v1
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md
nist-csf.PR.PS-02Software is maintained, replaced, and removed commensurate with riskenforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.stable_drift.detected.v1
engines: internal
workers: kye-drift-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.PR.PS-03Hardware is maintained, replaced, and removed commensurate with riskadvisoryconstitution_refs: constitution/00-INDEX.md
nist-csf.PR.PS-04Log records are generated and made available for continuous monitoringenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.PR.PS-05Installation and execution of unauthorized software are preventeddesignedaudit_events: kye.evidence.tool_call_pin.v1, kye.agent.mcp_allow_list.v1
constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md
nist-csf.PR.PS-06Secure software development practices are integrated and their performance is monitored throughout the software development life cycleenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.PR.IR-01Networks and environments are protected from unauthorized logical access and usageenforcedaudit_events: kye.evidence.decision_map.v1, kye.signal.decision.admitted.v1
engines: internal, internal
workers: kye-gateway, kye-edge-arbiter
constitution_refs: constitution/25-EDGE-GOVERNANCE.md
nist-csf.PR.IR-02The organization's technology assets are protected from environmental threatsadvisoryconstitution_refs: constitution/00-INDEX.md
nist-csf.PR.IR-03Mechanisms are implemented to achieve resilience requirements in normal and adverse situationsdesignedaudit_events: kye.spof.path_to_full.v1
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.PR.IR-04Adequate resource capacity to ensure availability is maintaineddesignedaudit_events: kye.spof.path_to_full.v1
constitution_refs: constitution/51-NO-SPOF.md
nist-csf.RC.RP-01The recovery portion of the incident response plan is executed once initiated from the incident response processenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.RC.RP-02Recovery actions are selected, scoped, prioritized, and performedenforcedaudit_events: kye.assurance.audit_replay_report.v1
engines: internal
workers: kye-audit-replay-orchestrator
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nist-csf.RC.RP-03The integrity of backups and other restoration assets is verified before using them for restorationenforcedaudit_events: kye.compliance.attestation.v1
engines: internal, internal
workers: kye-audit-archiver, kye-d1-backup-worker
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.RC.RP-04Critical mission functions and cybersecurity risk management are considered to establish post-incident operational normsenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/00-INDEX.md
nist-csf.RC.RP-05The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmedenforcedaudit_events: kye.assurance.audit_replay_report.v1
engines: internal
workers: kye-audit-replay-orchestrator
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nist-csf.RC.RP-06The end of incident recovery is declared based on criteria, and incident-related documentation is completedenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.RC.CO-03Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholdersenforcedaudit_events: kye.comms.dispatched.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nist-csf.RC.CO-04Public updates on incident recovery are shared using approved methods and messagingenforcedaudit_events: kye.comms.dispatched.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nist-csf.RS.MA-01The incident response plan is executed in coordination with relevant third parties once an incident is declaredenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.RS.MA-02Incident reports are triaged and validatedenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.RS.MA-03Incidents are categorized and prioritizedenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.RS.MA-04Incidents are escalated or elevated as neededenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.RS.MA-05The criteria for initiating incident recovery are appliedenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.RS.AN-03Analysis is performed to establish what has taken place during an incident and the root causeenforcedaudit_events: kye.assurance.audit_replay_report.v1
engines: internal
workers: kye-audit-replay-orchestrator
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nist-csf.RS.AN-06Actions performed during an investigation are recorded, and the records' integrity and provenance are preservedenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.RS.AN-07Incident data and metadata are collected, and their integrity and provenance are preservedenforced 1 unverified citationaudit_events: kye.audit.event.appended.v1 unverified citation, kye.evidence.pack.v1
engines: internal, internal
workers: kye-audit-archiver
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
nist-csf.RS.AN-08An incident's magnitude is estimated and validatedenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1
engines: internal
workers: kye-incident-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nist-csf.RS.CO-02Internal and external stakeholders are notified of incidentsenforcedaudit_events: kye.comms.dispatched.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nist-csf.RS.CO-03Information is shared with designated internal and external stakeholdersenforcedaudit_events: kye.comms.dispatched.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nist-csf.RS.MI-01Incidents are containedenforcedaudit_events: kye.revocation.event.v1, kye.signal.revocation.cascaded.v1
engines: internal
workers: kye-authority-revocation-orchestrator
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nist-csf.RS.MI-02Incidents are eradicatedenforcedaudit_events: kye.revocation.event.v1, kye.signal.revocation.cascaded.v1
engines: internal
workers: kye-authority-revocation-orchestrator
constitution_refs: constitution/12-PURPOSE-PERMISSION.md

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.