NIST CSF 2.0 Evidence Report
NIST Cybersecurity Framework 2.0 core function evidence across Govern, Identify, and Protect — GV.PO-02, ID.RA-01, PR.AA-05, and PR.PS-04.
Overview
The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, is the most widely adopted cybersecurity framework in the United States and is increasingly referenced internationally. Unlike sector-specific frameworks (FedRAMP, HIPAA, PCI-DSS), CSF 2.0 applies across all industries and organization sizes.
CSF 2.0 introduced a new sixth core function — Govern (GV) — alongside the original Identify, Protect, Detect, Respond, and Recover functions. Koalr generates evidence for four subcategory controls across the Govern, Identify, and Protect functions that are directly addressable by engineering change management data.
Controls covered
GV.PO-02 — Change Management Policy
Control language: Policies, processes, and procedures for managing the organization's cybersecurity risks are established, communicated, and enforced.
Koalr evidence: Every merged change is subject to a defined review and approval process. The report shows approval coverage across the period — evidencing that the change management policy is actively enforced, not just documented.
ID.RA-01 — Asset Vulnerability Identification
Control language: Vulnerabilities in assets are identified, validated, and recorded.
Koalr evidence: Automated deploy risk scoring runs on every pull request before merge, identifying DDL migrations, blast radius, CVE-adjacent paths, and complexity. Each signal is scored and recorded as a risk finding — providing a continuous, documented vulnerability identification process.
PR.AA-05 — Access Control Enforcement
Control language: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed.
Koalr evidence: CODEOWNERS rules define which individuals are authorized to approve changes to protected code paths. The enforcement is automatic and logged on every pull request. Violations — unauthorized merges to protected paths — are surfaced as access control exceptions.
PR.PS-04 — Audit Log Maintenance
Control language: Logs of events are generated and retained.
Koalr evidence: Koalr maintains a complete audit log of every code change, reviewer, approver, risk score, and signal breakdown. The evidence log is exportable as PDF and CSV for assessor review and is generated point-in-time for any date range.
Report output
- Dark navy cover page prepared for "NIST CSF Assessor / Internal Security Team"
- Executive summary with six KPI tiles
- Per-control detail blocks with EVIDENCED / PARTIAL / NOT_COVERED status badges and evidence counts
- Change log table with approval, CODEOWNERS, and risk columns
- Page number footer with CONFIDENTIAL marking
- Machine-readable CSV export
Generating a report
- Navigate to Compliance → NIST CSF 2.0
- Select your reporting period (typically annual, or aligned with your CSF profile review cadence)
- Click Download evidence package (PDF) or Export CSV
Using CSF evidence in a broader program
NIST CSF 2.0 is typically used as a risk management framework alongside more prescriptive regulatory requirements. Common use cases for Koalr's CSF report:
- Board and executive reporting: CSF provides a common language for communicating cybersecurity posture to non-technical stakeholders
- Cyber insurance applications: Many insurers now request CSF self-assessments; Koalr's evidence supports the GV, ID, and PR function ratings
- Vendor risk reviews: Enterprise customers may request CSF evidence as part of third-party risk assessments
- SOC 2 alignment: CSF 2.0 controls map closely to SOC 2 TSC — teams using both frameworks can produce evidence from a single Koalr report set
CSF profile mapping
NIST CSF 2.0 introduces organizational profiles (Current Profile and Target Profile) for gap analysis. Koalr's evidence supports the following profile elements:
| Function | Category | Subcategory | Koalr signal |
|---|---|---|---|
| GV | Policy (PO) | GV.PO-02 | Approval coverage rate |
| ID | Risk Assessment (RA) | ID.RA-01 | Risk scoring coverage |
| PR | Identity Mgmt & Access Control (AA) | PR.AA-05 | CODEOWNERS compliance rate |
| PR | Platform Security (PS) | PR.PS-04 | Audit log completeness |
Assessor review notes
- The PDF cover page names "NIST CSF Assessor / Internal Security Team" in the Prepared For field
- Koalr's evidence addresses a subset of CSF 2.0 subcategories — the ones directly addressable by engineering change management data
- For a complete CSF Current Profile assessment, pair Koalr's evidence with your broader security program documentation (asset inventory, incident response plan, vulnerability management, etc.)
Integration requirements
- GitHub (required) — provides all change management and access control data
Disclaimer
This report is designed to support NIST CSF 2.0 evidence collection for the covered subcategories. It does not constitute a formal CSF assessment or certification. Engage a qualified cybersecurity assessor for a complete CSF profile evaluation.
HIPAA Evidence Report
HIPAA Security Rule Technical Safeguards evidence under 45 CFR § 164.312 — audit controls, access authorization, integrity controls, and transmission security.
Code Review & Review Queue
Monitor review health, reviewer workload, and queue bottlenecks — keep reviews from becoming your delivery bottleneck.