Cyber Resilience

Control trends

How is defensive coverage evolving?

NIST 800-53 controls and the CWEs / ATT&CK techniques they address. Configuration-management rule coverage (CIS Benchmarks, AWS Config conformance, STIGs) will plug into reserved chart slots when that data is ingested.

Last updated: 2026-08-11 00:54 UTC

Control family share of mitigations

→ Each week, the share of CVEs whose strongest mitigating control falls in each grouping. Use the Framework selector under the chart to switch between NIST 800-53 families, ISO 27002 themes, and NIST CSF 2.0 functions. Every mapping runs CVE → its official CWE → control through the direct CWE↔framework cross-walks — no per-CVE model call.

Reserved — Configuration rule coverage by control family

Coming when CIS Benchmarks / AWS Config conformance / Azure Policy / STIG ingestion lands. See the controls catalogue for the 49 cloud-native rules we have today.

Reserved — Implementation drift

Coming when configuration-drift observations are ingested. Will chart deviation between a customer's running configuration and their declared baseline, by control family.

Active anomalies — Control lensAI

→ Auto-detected each daily run. Shifts in control-family mitigation share over time. Resolves when the metric stops triggering.

No active anomalies in this lens.