{"repo":"MarianoFacundoArch/nist-csf-evidence-gap-analysis-tool","free":true,"listed":false,"github":"https://github.com/MarianoFacundoArch/nist-csf-evidence-gap-analysis-tool","clone":"git clone https://github.com/MarianoFacundoArch/nist-csf-evidence-gap-analysis-tool.git","description":"Free, open-source tool to build a NIST CSF 2.0 Current Profile and gap analysis from an organization's documents (AI-assisted, human-validated, runs offline).","language":"JavaScript","stars":85,"topics":["cli","compliance","csf","current-profile","cybersecurity","gap-analysis","nist","nist-csf","security"],"license":"MIT","category":"security-tools","readme_excerpt":"NIST CSF 2.0 — AI-Assisted Evidence & Gap Analysis Tool A free, open-source tool that helps any organization measure how well its existing security practices meet the United States' national cybersecurity standard — the NIST Cybersecurity Framework (CSF) 2.0 — and shows exactly where the gaps are. One of the deliverables: dashboard.html — a single self-contained file (no server, no network) with the whole assessment: coverage, review status, current-vs-target, and every outcome's verified evidence. Purpose and significance Cybersecurity is a recognized national priority in the United States: attacks on businesses, hospitals, schools, utilities, and local governments cause serious economic and public harm. To help organizations manage this risk, the U.S. government's National Institute of Standards and Technology (NIST) publishes the Cybersecurity Framework (CSF) 2.0 — a common, widely used national standard that defines 106 cybersecurity outcomes an organization should achieve. (An \"outcome\" is a concrete result the organization should be able to demonstrate — for example, keeping an up-to-date inventory of its hardware.) In practice, the evidence of how an organization actually protects itself is spread across dozens or hundreds of documents — security policies, procedures, audit reports, standards, and internal records, often scattered across different teams and systems. Reading through all of that by hand and matching each piece of evidence to the right outcome in the NIST","default_branch":null,"files":null,"tree":[],"storefront":"/r/MarianoFacundoArch","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/MarianoFacundoArch/nist-csf-evidence-gap-analysis-tool/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}