Map every tabletop exercise to NIST CSF 2.0's six Functions — from GOVERN through RECOVER. Generate automated compliance evidence, track coverage gaps, and demonstrate continuous readiness to auditors and leadership.
⚠️ This toolkit is an educational resource for exercise program design. Skyhigh Cybersecurity does not provide formal NIST CSF assessment, audit, or attestation services. Organizations subject to CSF-referenced regulations should engage qualified assessors for official compliance determinations.
| CSF 2.0 Function | Key Categories for Exercises | Skyhigh Coverage | Evidence Generated |
|---|---|---|---|
| GV GOVERN | GV.RM — Risk Management Strategy GV.SC — Supply Chain Risk GV.RR — Roles & Responsibilities GV.PO — Policy |
Supporting | Exercise demonstrates role clarity (GV.RR); supply chain scenarios address GV.SC; policy gaps surface in AAR |
| ID IDENTIFY | ID.RA — Risk Assessment ID.IM — Improvement (lessons learned) ID.AM — Asset Management |
Direct | AAR gap analysis maps directly to ID.IM improvements; risk-based scenario selection validates ID.RA methodology |
| PR PROTECT | PR.AT — Awareness & Training PR.AA — Access Control PR.PS — Platform Security PR.IR — Infrastructure Resilience |
Direct | Every completed exercise is a dated training event (PR.AT); access control and hardening gaps surface in scenarios |
| DE DETECT | DE.CM — Continuous Monitoring DE.AE — Adverse Event Analysis |
Direct | MTTD metrics from exercises; detection step analysis; MITRE ATT&CK coverage gaps; sensor coverage validation |
| RS RESPOND | RS.MA — Incident Management RS.AN — Incident Analysis RS.MI — Incident Mitigation RS.CO — Communication |
Core | Primary exercise output — response execution evidence, stakeholder communication log, MTTR metrics, AI-written AAR |
| RC RECOVER | RC.RP — Recovery Plan Execution RC.IM — Recovery Plan Improvements RC.CO — Recovery Communication |
Direct | BC/DR scenario evidence; recovery timeline validation; post-exercise improvement tracking; stakeholder communication exercise |
Skyhigh exercise evidence maps to multiple frameworks simultaneously. One exercise program — complete regulatory coverage.
Your first exercise takes less than an hour to launch. Free plan available — no credit card required.