FrameworkMapper

About Your Organization

Takes about 2 minutes. Personalizes priority scores in your gap optimization and assessments.

Dedicated IT employees (FTE)

Dedicated security roles (FTE)

Used to auto-select your resource profile (minimal / moderate / well-resourced)

Cloud Environments

Select every cloud model your organization uses. These signals affect how controls related to cloud configuration, identity, and data protection are weighted in your priority scores.

Workforce

How your staff works affects your exposure to phishing, credential theft, and endpoint risks. Remote and hybrid environments require stronger identity and device controls.

Operational Technology

OT and industrial IoT systems are often unpatched, always-on, and safety-critical — they require a different set of security controls than standard IT environments.

Sensitive Data Types

Check every data type your organization stores, processes, or transmits. Each type activates specific regulatory controls and raises the stakes for certain security failures.

Exposure

External-facing systems and third-party connections are among the most common attack entry points. These signals significantly increase the weight on perimeter and supply-chain controls.

How many external vendors, suppliers, or service providers have access to your systems, network, or data?

Identity & Email (optional)

Knowing your email and identity platforms helps tailor recommendations for phishing defense, MFA, and access management controls.