Skip to main content

Rating a Subcategory (CSF 2.0)

Learn how to rate a subcategory in the Cye Exposure Management Platform's NIST CSF 2.0 maturity assessment.

Overview

This article explains how to assign a maturity level to a subcategory in the Cye Exposure Management Platform when working with the NIST CSF 2.0 framework. This article covers system-calculated scores, manual maturity levels, and how linked findings, technologies, and processes contribute to the assessment.


How to Rate a Subcategory

  1. Navigate to the subcategory assessment pane

    • Go to Maturity Assessment

    • Select a Function > Category > Subcategory

  2. Check for existing data

    • A system-calculated score may be present based on linked findings, technologies, or processes

    • The score can be accepted or reassessed manually

  3. Set a manual maturity rating

    • Click Current level to enable the rating controls

    • Choose a value from 1 to 5, or select:

      • Unknown – if the subcategory cannot be confidently assessed

      • Not Relevant – if the subcategory is not applicable to the organization


Understanding Maturity Levels

Each level builds on the one before, layering improvements like formalized processes, clear responsibilities, measurement, and continuous monitoring:

Level

Description

1 – Initial

Ad hoc or non-existent implementation; no ownership or repeatability

2 – Developing

Some basic controls or processes in place; inconsistent application

3 – Defined

Documented and standardized processes; supporting technologies in place

4 – Managed

Effectiveness is actively measured and policy compliance is tracked

5 – Optimized

Mature, continuously improved, and adaptable to change


Linked Findings, Technologies, and Processes

  • Findings

    • Automatically factored into the maturity score if linked

    • Click a finding to view or edit it on the Findings page

    • Use the Unmapped Framework filter on the Findings page to locate findings not yet linked to subcategories

  • Technologies & Processes

    • Linked assets are visible under their respective sections

    • Click to view or manage them on the Assets page


Wrap-up / Next Steps

Rating a subcategory is a foundational step in building a maturity profile. Combine manual ratings with linked data where possible, and use filters to identify what's missing — assessments will be more complete and actionable.

Did this answer your question?