Skip to content

How items are categorised

Every knowledge base item can be filed against a standard taxonomy, so a knowledge base of a few thousand items stays navigable and questions about the same control sit together.

The taxonomy has two levels: areas at the top, each containing a set of categories.

It is derived from the NIST Cybersecurity Framework 2.0, whose six functions — Govern, Identify, Protect, Detect, Respond, and Recover — form the first six areas, along with their categories and codes.

Two further areas cover ground that security questionnaires ask about but the framework does not: Application, for questions about the software you provide, and AI, for questions about how you use AI responsibly.

On import. Auto categorize items is switched on by default when you import from CSV, so imported items are filed as they arrive.

When you create an item by hand. ResponseHub suggests an area and category from the question as you write it. You can accept the suggestion or pick your own.

You can change the area and category on any item at any time.

Area Covers Categories
Govern (GV) Cybersecurity risk management strategy, expectations, and policy GV.OC Organizational Context
GV.RM Risk Management Strategy
GV.RR Roles, Responsibilities, and Authorities
GV.PO Policy
GV.OV Oversight
GV.SC Cybersecurity Supply Chain Risk Management
Identify (ID) Current cybersecurity risks are understood ID.AM Asset Management
ID.RA Risk Assessment
ID.IM Improvement
Protect (PR) Safeguards to manage cybersecurity risks PR.AA Identity Management, Authentication, and Access Control
PR.AT Awareness and Training
PR.DS Data Security
PR.PS Platform Security
PR.IR Technology Infrastructure Resilience
Detect (DE) Cybersecurity attacks and compromises are found and analyzed DE.CM Continuous Monitoring
DE.AE Adverse Event Analysis
Respond (RS) Actions regarding detected cybersecurity incidents are taken RS.MA Incident Management
RS.AN Incident Analysis
RS.CO Incident Response Reporting and Communication
RS.MI Incident Mitigation
Recover (RC) Assets and operations affected by cybersecurity incidents are restored RC.RP Incident Recovery Plan Execution
RC.CO Incident Recovery Communication
Application (APP) Information relating to the applications provided by the organisation
AI (AI) How the organisation uses AI responsibly

Area names, category names, and their descriptions are taken from NIST CSF 2.0 and use American spelling, as the framework does.