TEAM VIEW // YOU ARE HERE
Response Swimlane
See who acts, in what order, for a selected threat. Threat first, with delegation fallback for lean teams.
Start here if you run the team that responds.
Current viewBOARD VIEW // REPORTING TO THE BOARD?
CSF Crosswalk
Map catalogued threats and controls to the CSF function you already report against. Function first.
Start here if the board or a regulator is your audience.
Open Crosswalk →EVALUATION VIEW // EVALUATING A CAPABILITY?
Stack Lab (Preview)
Evaluate what a capability stack changes across the six functions.
Start here if you are choosing or defending a security stack.
Open Stack Lab →Additive crosswalk reference
Role-aware AI Threat Defensive Swimlane
NIST CSF 2.0 aligned. Swimlane shows sequence (who acts in what order). RACI shows incident assignment. The standing accountability RACI lives in the framework document.
The autonomy threshold. Defines tier-5 AI capability for the framework.
Attacker tier: 4 · Nation-state
AI capability: 5 · Autonomous
In the wild: yes
Trigger: Thousands of agent requests per second from one identity (M-A4-01)
Overview: role coverage by CSF function
Dots show where each role has steps for the selected threat class (A4). Click a column header, or a function above, to zoom into that function's numbered flow.
Cadence functions, labelled cycle below, run on a schedule whether or not anything is burning. Event functions, labelled live flow, activate when a live threat trips a detection signal. The lanes below show both, for the selected threat.
| Role | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| CISO / Head of Security | 2 steps | . | . | . | 1 step | . |
| CRO / Board Risk | 3 steps | . | . | . | . | 1 step |
| SOC Manager | . | . | . | 1 step | . | 1 step |
| Tier 1 Analyst | . | . | . | 1 step | . | . |
| Tier 2 Analyst | . | . | . | 1 step | . | . |
| Incident Responder | . | . | . | . | 1 step | 1 step |
| Threat Intel Lead | . | 2 steps | . | . | . | . |
| Detection Engineer | . | . | . | 1 step | . | 1 step |
| Cloud Security Engineer | . | 1 step | . | . | 1 step | . |
| Application Owner | . | . | . | . | . | . |
| IAM / Identity Owner | . | 1 step | 2 steps | 1 step | 1 step | . |
Steady-state ownership //Steady-state ownership (who owns each domain year-round) lives in the framework document, Section 2.4.
