-
Removing the lower level nested Requirement Statements from an assessment
When you have a level 3 Requirement statement, can the level 1 and level 2 requirement statement for that same control be removed from the assessment? This would remove redundancy, by not having to ask the business for evidence at each level because it would be inclusive in the level 3. This would also lower the number of overall baselines while still covering the control.
9 votesGreat suggestion. This is actually on the slate to be addressed in v10 of the CSF.
-
Enumerate policy statements and required areas for illustrative procedures
Specifically enumerate all required policy statements and items for each requirement at the policy and procedure level as a checklist. Hiding specific requirements inside the repetitive narrative of the illustrative procedures makes it extremely difficult to parse-out what is required in policy and procedure documentation. While you're at it, remove the repetitive language all together since it's obvious for each control that "ad hoc or well understood blah blah" is already partially acceptable by your rubric and focus on giving more examples of acceptable language or implementations or links to relevant information.
6 votesGreat suggestions, this will be included in v10. Thanks.
-
[BL] Name and Security should include CSF Version expiration
There should be a date for a CSF version's expiration shown when on the Name and Security page.
4 votes -
APEC CBPRS and PRPS regulatory factors/reports
Allow for targeting assessments against APEC programs
1 vote -
[BL] Authoritative Source shown when hovering on an Assessment Statement
When users are completing a CSF Assessment the Authoritative Source section should be shown when hovering over an Assessment Statement.
There should be an info logo for the user to hover over
2 votes -
[BL] CSF Version Differences
Ability to run a report that mirrors the CSF Summary Changes
1 vote -
[BL] Search Functionality for the Library
Give users the ability to search a CSF library for strings.
1 vote -
[BL] Expand all Sub-Components in Library
Ability to expand out the elements of the library en masse. For example press a button to show all of the children under the Control Categories section for easier searching.
0 votes -
[BL] Root-level view for Control Reference within CSF Library
root-level view for control reference that opens up into the 156 control references and then opens up into the requirement statements listed under each control reference..
*Looking something like this: *
+ Control References
--- 00.a Information Security Management Program
--+ 01.a Access Control Policy
------- An access control policy shall be established documented and reviewed based on business and security requirements for access.
------- There shall be a formal documented and implemented user registration and de-registration procedure for granting and revoking access.If I understand correctly the problem with going through the category view is that control references may…
0 votes
- Don't see your idea?