What framework coverage shows

Security frameworks ask for many of the same things in different words. Framework coverage, on your dashboard, shows how far the work in your action plan already reaches into frameworks beyond the one you assessed against.

Why does one piece of work count more than once?

Every control in your plan is made of tasks, and each task is linked to the requirements it helps satisfy, in every framework that asks for it.

Take a task from the Endpoint Protection control: Enforce full-disk encryption on all managed endpoints. Encrypting your laptops satisfies part of NIS2, and it is also what ISO/IEC 27001, GDPR, CIS Controls and the NIST Cybersecurity Framework ask for in their own terms.

One task and the requirements it cites across five frameworks

You do the task once. Coverage counts it against every framework it reaches.

Where do the numbers come from?

From the controls in your action plan. An assessment on its own does not fill the panel: until your first control is planned, it says there is no framework mapping yet.

When you take a control into the plan, the tasks your assessment answers say you already do are marked as done from the start. Your existing work counts from day one.

How do you read a row?

The framework coverage panel

Each framework gets one bar and one line of text:

  • Requirements: every requirement in that framework, whether or not your work touches it.
  • Addressed, the grey part: requirements that at least one control in your plan is linked to.
  • Met, the green part: requirements that at least one finished control is linked to.

A requirement counts once, however many of your controls reach it. The numbers move as you work: planning a control can raise addressed, and finishing one raises met.

What do the numbers not tell you?

Addressed is a starting point. A requirement counts as addressed as soon as one task in your plan speaks to it. The requirement may ask for more than that task does.

Met is not certification. It means a finished control in your plan covers the requirement. Whether an auditor agrees depends on the evidence behind the work, which coverage does not assess.

Percentages do not compare across frameworks. Frameworks are divided differently. Some consist of a small number of broad controls, others of hundreds of articles and sub-points. A short bar can simply mean that most of a framework is about something else: a regulation largely about how personal data is handled will show modest coverage from security work, and that is expected.

Only frameworks that set obligations appear. Catalogues used to name attack techniques or software weaknesses are linked to tasks elsewhere in the platform, but nobody is audited against them, so they are left off.

What is it useful for?

Choosing what comes next. If a customer or a partner asks about a second framework, coverage shows how much of it your current plan already reaches before you commit to anything.

Answering the question early. When someone asks whether your work helps with ISO or NIST, the panel gives a real figure instead of an estimate.

It does not replace an assessment against that framework. Coverage only sees requirements your controls are linked to. What a framework asks for that your plan never touches only shows up when you assess against it directly.


Related articles