Framework Workbench · Agentic Controls Mapping

Framework Mapper

Automated discovery of regulatory updates across NIST, CIS, ISO, NIS2 and EU regulation — parsed, structured into canonical controls, mapped to the internal control framework with traceable lineage, and kept current by a continuous-monitoring agent.

Frameworks Tracked
0
2 Q2
Requirements
0
49 WoW
Controls Mapped
0
30 WoW
Coverage
0%
1 WoW
Open Gaps
0
2 WoW
Pending Review
0

Latest Intake · EU AI Act (2024/1689)

Intake Run · eur-lex.europa.eucomplete
  1. New release detected09:12:04
    Discovery
    Regulation (EU) 2024/1689 · eur-lex feed · corrigendum OJ L series
  2. Document parsed09:12:31
    Parsing
    PDF · 144 pp → 412 segments · article citations preserved
  3. Requirements normalized09:13:02
    Structuring
    68 canonical requirements · stable IDs AIACT-001…068
  4. Persisted to Framework DB09:13:20
    Structuring
    postgres: 68 rows · embeddings indexed → pgvector
  5. Crosswalked to ICF09:14:05
    Mapping
    41 of 68 mapped · 12 lineage overlaps (GDPR · ISO 27001)
  6. Fit to org context09:14:48
    Applicability
    deployer profile · EU region · 23 obligations in scope
  7. Gaps published09:15:12
    Gaps
    7 new gaps (3 high) · routed to Recommendation agent
fully automated · no human touch3m 08s
Relevant For You · Applicability23 / 68
DeployerEU RegionHigh-Risk UseNot a Provider
  • Art. 4
    AI literacy for staff operating AI systems
    no matching control
    gap
  • Art. 26(2)
    Assign human oversight for high-risk AI use
    no matching control
    gap
  • Art. 26(6)
    Retain automatically generated logs ≥ 6 months
    ICF-LM-05
    partial
  • Art. 26(7)
    Inform workers before deploying high-risk AI
    ICF-HR-03
    partial
  • Art. 50
    Transparency for chatbots & synthetic content
    ICF-DP-09
    covered
  • Art. 72
    Post-market monitoring cooperation (deployer)
    ICF-IR-08
    covered
45 provider-only obligations excluded from scope
New Gaps · From This Release7
  • HIGH
    AI literacy programme for operators of AI systems
    origin Art. 4
    3–5 wks
  • HIGH
    Human-oversight roles for high-risk AI deployments
    origin Art. 26(2)
    2–4 wks
  • HIGH
    Fundamental-rights impact assessment procedure
    origin Art. 27
    4–6 wks
  • MED
    6-month retention for high-risk AI system logs
    origin Art. 26(6)
    1–2 wks
  • MED
    Worker notification prior to high-risk AI use
    origin Art. 26(7)
    1 wk
+ 2 low-severity gaps5 control drafts ready ↓

Agent Pipeline

Discovery
12 sources watched
Parsing
NIS2 · 214 segments
Structuring
canonical IDs assigned
Mapping
crosswalk → ICF
Validation
34 in review
Applicability
Gaps & Findings
Recommendation
Reporting
Monitoring

Agent Swarms

Agent Swarm · Framework Intake
Framework Discoverydone
Source & version detection
  • ·Monitor subscriptions
  • ·Register sources
  • ·Detect new releases
12 sources · 2 new releases
Document Parsingdone
Raw document extraction
  • ·Parse PDF / DOCX / XLSX / HTML
  • ·Segment contents
  • ·Preserve citations
214 segments · citations kept
Control Structuringdone
Canonical control creation
  • ·Extract domains
  • ·Normalize requirements
  • ·Assign stable IDs
1,847 requirements structured
Harmonization & QA
Control Mappingactive
Cross-framework alignment
  • ·Map to internal taxonomy
  • ·Identify overlaps
  • ·Trace lineage
1,412 mapped · 88 overlaps
Validationactive
Quality & governance checks
  • ·Flag duplicates
  • ·Score confidence
  • ·Route exceptions
34 routed to human review
Assessment Swarm
Applicabilityactive
Fit to org context
  • ·Match sector / region
  • ·Evaluate triggers
  • ·Prioritize controls
GxP scope · 3 regions
Gaps & Findingsqueued
Internal comparison
  • ·Compare expected vs current
  • ·Classify gaps
  • ·Assign severity
43 open gaps
Recommendationqueued
Internal improvement action
  • ·Draft missing controls
  • ·Suggest control language
  • ·Estimate effort
9 drafts pending
Delivery & Lifecycle
Reporting & Chatqueued
Analyst consumption
  • ·Answer with citations
  • ·Generate reports
  • ·Support ad-hoc search
128 Q&A sessions
Continuous Monitoringactive
Lifecycle management
  • ·Watch source changes
  • ·Trigger reassessments
  • ·Maintain history
next sweep in 04:12

Framework Registry

FrameworkVersionRequirementsMappedGapsLast SyncStatus
NIST CSFnist.gov
2.0106
100%
302 Jul 2026synced
NIST SP 800-53nist.gov
Rev 51,189
84%
1828 Jun 2026synced
ISO/IEC 27001iso.org
202293
100%
224 Jun 2026synced
CIS Controlscisecurity.org
v8.1153
92%
630 Jun 2026review
NIS2 Directiveeur-lex.europa.eu
EU 2022/2555214
46%
1114 Jul 2026mapping
EU DORAeur-lex.europa.eu
2022/255464
71%
311 Jul 2026mapping
EU AI Acteur-lex.europa.eu
2024/168968
60%
714 Jul 2026new release

Harmonization & Gaps

Requirements · Mapping Status
76%
Coverage
  • Mapped141276%
  • Review17810%
  • Unmapped25714%
Open Gaps · By DomainGAPS
  • Incident Reporting & Notification
    11NIS2 · DORA
  • Supply Chain / Third-Party
    9800-53 · CSF
  • Resilience Testing
    7DORA
  • Access Control & PAM
    6CIS · ISO
  • Logging & Monitoring
    5800-53
  • Data Protection (GxP)
    5ISO · GxP
Agent Activity10
  1. 14:02:11[DISCOVERY]eur-lex feed: NIS2 implementing act rev detected (v2024-07)
  2. 14:02:19[PARSING]parse_pdf(nis2_implementing_act.pdf) → 214 segments, citations preserved
  3. 14:02:40[STRUCTURING]normalized 41 requirements → assigned IDs NIS2-IR-001…041
  4. 14:03:02[MAPPING]crosswalk NIS2-IR-004 → ICF-IR-12 (lineage: 800-53 IR-6)
  5. 14:03:05[MAPPING]overlap detected: NIS2-IR-004 ≈ DORA Art.19 — merged lineage
  6. 14:03:18[VALIDATION]confidence 0.63 < 0.75 threshold → routed to human review
  7. 14:03:29[APPLICABILITY]NIS2 Art.23 applies: essential entity, EU region, GxP unaffected
  8. 14:03:44[GAPS]expected control ICF-IR-24 (24h notification) not found — severity H
  9. 14:04:01[RECOMMEND]drafted control language for ICF-IR-24 · est. effort M (2–4 wks)
  10. 14:04:10[MONITORING]reassessment scheduled for CIS v8.1 delta (3 changed safeguards)

Requirement → Control Traceability

Requirement IDExternal ObligationInternal ControlConfidenceStatus
NIS2-IR-004
Notify CSIRT of significant incidents within 24 hoursNIS2
ICF-IR-12
0.91
validated
DORA-19.1
Classify ICT-related incidents by materiality thresholdsDORA
ICF-IR-08
0.87
validated
CSF-GV.SC-06
Due diligence prior to supplier relationshipNIST CSF
ICF-TP-03
0.63
in review
NIS2-IR-009
Final incident report within one month of notificationNIS2
gap
800-53-AC-6(7)
Review privileges of privileged users periodically800-53
ICF-AC-17
0.94
validated
CIS-8.11
Conduct audit log reviews on a weekly basis or moreCIS v8.1
ICF-LM-05
0.71
in review
DORA-24.2
Threat-led penetration testing every 3 yearsDORA
gap

Drafted Controls

Missing Controls · Drafted by Recommendation Agent5
  • HIGH
    24-hour early-warning notification procedure to national CSIRT
    ICF-IR-24 · origin NIS2 Art.23
    est. 2–4 wks
  • HIGH
    Threat-led penetration testing programme (TLPT) on critical functions
    ICF-RT-07 · origin DORA Art.26
    est. 6–8 wks
  • MED
    Register of ICT third-party contractual arrangements
    ICF-TP-11 · origin DORA Art.28
    est. 3–5 wks
  • MED
    Weekly privileged-session log review with documented sign-off
    ICF-LM-09 · origin CIS 8.11
    est. 1–2 wks
  • LOW
    GxP audit-trail retention policy alignment (21 CFR Part 11)
    ICF-DP-15 · origin GxP baseline
    est. 1 wk
High-Level Architecture
Framework Sources
NIST · EU · NIS2 · CIS · Tavily
Orchestrator
FastAPI · MCP · task routing
Agent Swarms
intake · QA · assessment
Framework DB
Postgres · pgvector RAG
GRC Platform
ServiceNow sync
Model Garden
self-host + frontier API