The board asks whether the controls work. This Catalogue turns that question into evidence: 7+1 Key Risk Indicators, 76 KPIs and 256 Control Proofs, each one naming the system that holds the record.
7+1Key Risk Indicators
76KPIs
256Control Proofs
153/153CIS Controls v8.1 safeguards
21/21OWASP GenAI data security risks
Built on CIS Controls Assessment Specification v8.1 · NIST SP 800-55 measure types · FedRAMP 2026 Key Security Indicators · CISA ScubaGear and open-source evidence tools. Mapped by PRISM Assure; not reviewed or endorsed by those bodies.
Step 1 · Your tools
Tick the platforms you already run
Most of the evidence a board needs is already sitting in your security and IT platforms. See how much.
0 / 51
Tick your platforms to see how many Control Proofs they already hold.
Step 2 · Where you start
Crawl, walk, run
Nobody starts with every safeguard measured and every proof automated. Choose a tier and the scope changes. The evidence standard does not.
The hard part is continuous evidence
Board approval of the risk appetite is the first hurdle. The harder one is technical: producing evidence on schedule without people assembling it by hand. No new product is needed. Each automated proof needs six things, all from tools you already run.
Read access. A read-only service account or app registration on the source tool, with a named owner and credential rotation. Check the licence tier and log retention first.
A scheduler. Power Automate, Azure Logic Apps, Tines, or a scheduled script.
An evidence repository. Not a product: a SharePoint library with retention labels, or immutable cloud storage such as Amazon S3 Object Lock. The producer can add evidence but cannot change it.
A calculation. A saved query in Microsoft Sentinel or Splunk. With no SIEM, a script or Power BI.
Failure alerts. A pull that fails, runs late or returns nothing must alert its owner. A silent failure looks exactly like a Green.
An owner for upkeep. APIs, licences and field names change. Each integration is re-tested after every vendor change.
Automate where proofs are frequent, high-volume or error-prone. A proof produced by hand, on schedule and to specification, is still a Control Proof.
14KPIs in scope
51Control Proofs
21 / 153CIS safeguards measured
4 / 21OWASP GenAI risks, direct
CIS Controls v8.1 · 18 controls · 153 safeguards
Measured at this tierImplementation Group 1, not yet measuredIG2 or IG3, not yet measured
Step 3 · Follow the chain
From risk appetite to a record an auditor can test
Risk Appetite Statement→KRI→KPI→Control Proofs
Get the full Catalogue
The complete workbook: all 76 KPIs with thresholds and owners, all 256 Control Proofs with Crawl, Walk and Run collection steps, Second Line challenge and Third Line audit tests, a tier-aware board scorecard and full CIS and OWASP coverage maps. Complimentary, from the author of PRISM Assure: Governing Cyber Risk in the AI Era.