Map cybersecurity guidance to operating evidence
Use public NIST and CISA guidance as a reference point, then trace the relevant Cybatar records, workflows, dependencies and limitations. These are first-party operational mappings—not certifications or official crosswalks.
Framework mappings with source status and claim boundaries
Each page starts from an authoritative publisher source and shows where documented Cybatar evidence may be relevant.
NIST CSF 2.0
Cybatar can help organisations organise operating records, evidence and workflows that are relevant across the six NIST CSF 2.0 Functions—Govern, Identify, Protect, Detect, Respond and Recover. This page is an illustrative Cybatar mapping, not an official NIST crosswalk, certification, endorsement or proof that any CSF outcome has been achieved.
Open mapping → Evidence mappingCISA CPGs
Cybatar can help organise evidence, ownership, monitoring, exposure, incident-response and assurance workflows around several operational themes addressed by the CISA Cross-Sector Cybersecurity Performance Goals. The CPGs are voluntary practices, and this Cybatar mapping is not an official CISA assessment, endorsement or attestation.
Open mapping → Evidence mappingNIST SP 800-61r3
NIST SP 800-61 Revision 3 treats incident response as part of cybersecurity risk management across all six NIST CSF 2.0 Functions. Cybatar can support the operational records that connect preparation, detection, response, evidence, recovery and learning, while the organisation remains responsible for its actual response programme and decisions.
Open mapping → Evidence mappingNIST SP 800-92
Cybatar can support parts of a log-management operating model through event-source registration, ingestion, parsing, normalization, deduplication, correlation, access to normalized events and incident escalation. Source generation, transport security, time synchronisation, retention, disposal and completeness still depend on the organisation’s systems and deployment configuration.
Open mapping →Evidence patterns
See what operational records can support incident response, logging/monitoring and vulnerability-management assurance.
Explore control evidenceHow mappings are made
Read the rules used to separate external guidance, Cybatar interpretation, product evidence and explicit non-claims.
Read methodologyVerify product claims
Use the Cybatar Evidence Registry when a framework mapping references product capability, integration scope or trust information.
Open Evidence Registry