Work in progress, testing phase. This capability evaluation view is under active development: layout, capability set, and effect data are subject to change and have not completed the framework's full validation cycle. Do not cite in audit or procurement artifacts yet.
Defensive Framework // Evaluate and Procure
Stack Lab: CSF Function Ledger
Pick a threat, then build a capability stack. The ledger shows how the stack changes operating burden across the six CSF functions: steps absorbed, handoffs removed, detection stage shift, posture balance. Structural and ordinal claims only.
1 · THREATGTG-1002A4 · 32-step baseline
2 · STACK3 of 9CTEM / Exposure Mgmt, AI / MCP Gateway, AI SOC AssistantExample stack · edit to match yours
3 · VERDICT3 of 9 capabilities · gtg-1002
30 of 32 steps stay human with this stack.
Detection stays at At-execution. Nothing in this stack moves it earlier.
Govern, Protect and Recover: not touched by anything in this catalog for this threat.
Capability categories, not products. Verify against your vendor before acting on this view.