NIST SP 800-137
Reporting and Risk Scoring

NIST SP 800-137 4: Security Status Reporting and Risk Score Aggregation

Provide security status reporting per Section 3.6 to System Owners + ISSO + AO + CISO + senior leadership. Apply risk score aggregation including: vulnerability scoring (CVSS v4.0 + EPSS + KEV catalog) + asset criticality scoring + threat intelligence overlay + business impact analysis. Use ATT&CK MITRE coverage scoring + NIST Cybersecurity Framework profile scoring + RMF system risk score per NIST SP 800-39 + Continuous Diagnostics and Mitigation (CDM) Federal Dashboard. Apply Federal Information Security Modernization Act (FISMA) reporting + OMB CyberStat reviews + annual FISMA report.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.