Skip to main content

Associate a NIST Subcategory with a Finding

Learn how to associate NIST subcategories with findings to enable maturity scoring in the Cye Exposure Management Platform.

Overview

To contribute to maturity scoring in the Cye Exposure Management Platform, a finding must be linked to a specific NIST subcategory. This article explains how to associate a finding with one or more subcategories from the NIST Cybersecurity Framework (CSF), ensuring the finding impacts the maturity assessment.


How to Associate a Subcategory When Creating a Finding

  1. Use the Create Finding Wizard

    • In the NIST CSF section, the following must be completed for the primary framework (either CSF 1.1 or 2.0):

      • Function

      • Category

      • Subcategory

  2. Select Fields in Any Order

    • Start by selecting the subcategory to auto-fill the related category and function

    • If the subcategory is not defined, the finding will not impact maturity scoring

  3. Add Additional Subcategories (Optional)

    • Click the + button to associate multiple function/category/subcategory entries

    • A finding can impact multiple subcategories


Editing NIST Associations After Creation

  1. Open the Findings page

  2. In the right-hand pane, go to the Standards tab:

  3. Locate the NIST section

  4. Edit the function, category, or subcategory as needed

    • Mappings can be added or removed, but at least one subcategory must remain

    • Edits to the non-primary framework are optional and do not affect platform-wide scoring:

Note: Editing the NIST section requires appropriate permissions.


Wrap-up / Next Steps

Linking findings to the right NIST subcategories ensures they are accurately reflected in the maturity score. Be sure to complete the required fields during creation — and revisit the Standards tab if mappings need to be adjusted later.

Did this answer your question?