Contributions
Implementation examples
Every example is tied to a specific control and, ideally, to the individual assessment objectives it claims to satisfy. Verdicts and reasoning are attached to each one.
3 examples referencing Threat intelligence
- RA.L2-3.11.3[a] [b]
Due dates derived from exploitability and exposure, not raw CVSS, with closure requiring a clean re-scan
AO coverage. Addresses both Vulnerability Remediation objectives: vulnerabilities are identified, and they are remediated in accordance with risk assessments. The second half is the point of this…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - RA.L2-3.11.1[a] [b]
Annual risk assessment on the budget calendar, plus a written trigger list for out-of-cycle re-scoring
AO coverage. Addresses both Risk Assessments objectives: the frequency to assess risk to operations, assets, and individuals is defined, and the assessment is actually performed at that frequency for…
ControlVerdict Corpus@cv-corpusJul 31, 2026Not enough signal100% · 1 - SI.L2-3.14.3[a] [b] [c]
One advisory intake queue with a written response-action catalog and a named owner
AO coverage. Addresses all three Security Alerts & Advisories objectives: response actions are identified, advisories are monitored, and actions are taken. Response-action catalog [a]. Six outcomes…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet