Cheewan LogoCHEEWAN.AI // DEFENSIVE FRAMEWORK v3.0 Framework home
TEAM VIEW // YOU ARE HERE

Response Swimlane

See who acts, in what order, for a selected threat. Threat first, with delegation fallback for lean teams.

Start here if you run the team that responds.

Current view
BOARD VIEW // REPORTING TO THE BOARD?

CSF Crosswalk

Map catalogued threats and controls to the CSF function you already report against. Function first.

Start here if the board or a regulator is your audience.

Open Crosswalk
EVALUATION VIEW // EVALUATING A CAPABILITY?

Stack Lab (Preview)

Evaluate what a capability stack changes across the six functions.

Start here if you are choosing or defending a security stack.

Open Stack Lab
Additive crosswalk reference

Role-aware AI Threat Defensive Swimlane

NIST CSF 2.0 aligned. Swimlane shows sequence (who acts in what order). RACI shows incident assignment. The standing accountability RACI lives in the framework document.
ConfirmedClass A4Nov 2025
The autonomy threshold. Defines tier-5 AI capability for the framework.
Attacker tier: 4 · Nation-state
AI capability: 5 · Autonomous
In the wild: yes
Trigger: Thousands of agent requests per second from one identity (M-A4-01)

Overview: role coverage by CSF function

Dots show where each role has steps for the selected threat class (A4). Click a column header, or a function above, to zoom into that function's numbered flow.
Cadence functions, labelled cycle below, run on a schedule whether or not anything is burning. Event functions, labelled live flow, activate when a live threat trips a detection signal. The lanes below show both, for the selected threat.
RoleGovernIdentifyProtectDetectRespondRecover
CISO / Head of Security2 steps...1 step.
CRO / Board Risk3 steps....1 step
SOC Manager...1 step.1 step
Tier 1 Analyst...1 step..
Tier 2 Analyst...1 step..
Incident Responder....1 step1 step
Threat Intel Lead.2 steps....
Detection Engineer...1 step.1 step
Cloud Security Engineer.1 step..1 step.
Application Owner......
IAM / Identity Owner.1 step2 steps1 step1 step.
Delegation fallback chains are recommended defaults, not standards-derived. Steps and controls trace to the v2.4 catalog and named public standards. Re-verify standard and CVE status before audit citation.
Steady-state ownership //Steady-state ownership (who owns each domain year-round) lives in the framework document, Section 2.4.