The functions, categories, tiers, and profile vocabulary you actually need mid-engagement — plus Anchor's own trust-but-verify audit loop, condensed.
| Code | Category | Subcats |
|---|---|---|
| Govern — GV | ||
| GV.OC | Organizational Context | 5 |
| GV.RM | Risk Management Strategy | 7 |
| GV.RR | Roles, Responsibilities, and Authorities | 4 |
| GV.PO | Policy | 2 |
| GV.OV | Oversight | 3 |
| GV.SC | Cybersecurity Supply Chain Risk Management | 10 |
| Identify — ID | ||
| ID.AM | Asset Management | 7 |
| ID.RA | Risk Assessment | 10 |
| ID.IM | Improvement | 4 |
| Protect — PR | ||
| PR.AA | Identity Management, Authentication, and Access Control | 6 |
| PR.AT | Awareness and Training | 2 |
| PR.DS | Data Security | 4 |
| PR.PS | Platform Security | 6 |
| PR.IR | Technology Infrastructure Resilience | 4 |
| Detect — DE | ||
| DE.CM | Continuous Monitoring | 5 |
| DE.AE | Adverse Event Analysis | 6 |
| Respond — RS | ||
| RS.MA | Incident Management | 5 |
| RS.AN | Incident Analysis | 4 |
| RS.CO | Incident Response Reporting and Communication | 2 |
| RS.MI | Incident Mitigation | 2 |
| Recover — RC | ||
| RC.RP | Incident Recovery Plan Execution | 6 |
| RC.CO | Incident Recovery Communication | 2 |
What the organization actually does today, Subcategory by Subcategory — evidence-backed, not aspirational.
What should be true given mission, risk appetite, and obligations. Prioritized Low/Med/High — SP 1301 calls prioritization "the defining feature of a Profile."