Improvement
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
Tools for improvement
Hosted MCP servers your agents can use for these controls.
Starter prompts
Paste into Claude Code, Microsoft Copilot, or Codex connected to Tracecat MCP, and build it out together.
Turn case retros into tracked improvements
Build me a case-triggered workflow in Tracecat that runs when a significant case closes. Have an agent read the case timeline and comments, extract what slowed the response down and what information was missing, and open a Linear improvement issue for each concrete fix. Post a weekly digest of open improvements and their age to the team channel. First help me understand how this maps to ID.IM-03 and why improvements from daily operations beat annual lessons-learned documents. Ask me which case types deserve a retro. Talk me through keeping the improvement backlog from becoming a graveyard.
Keep the incident response plan current
Build me a quarterly workflow in Tracecat that checks our incident response plan against reality. Have an agent read the plan in Notion, compare its steps and contacts against how our last quarter of incidents actually ran in Incident.io, and draft proposed updates: steps nobody follows, contacts who left, and paths real incidents took that the plan never mentions. First help me understand how this maps to ID.IM-04 and what makes response plans drift from practice. Ask me where the plan lives and who owns it. Talk me through whether the agent should propose edits directly or assemble evidence for a human review session.
Mine test and exercise results for fixes
Build me an automation in Tracecat that turns security test results into tracked work. Import findings from pentest reports, purple team exercises, and tabletop notes, dedupe them against known gaps, and open a Jira ticket per new finding with the exercise context attached. Track closure and flag findings that resurface across exercises. First help me understand how this maps to ID.IM-02 and why repeat findings are the signal worth escalating. Ask me what format our test results arrive in. Talk me through involving suppliers when an exercise exposes a gap on their side.
Controls
- ID.IM-01AC-1AT-1AU-1CA-1CA-2CA-5CA-7CA-8CM-1CP-1CP-2IA-1IR-1IR-4IR-8MA-1MP-1PE-1PL-1PL-2PM-1PS-1PT-1RA-1RA-3RA-5RA-7SA-1SA-8SA-11SA-17(6)SC-1SI-1SI-2SI-4SR-1SR-5
Improvements are identified from evaluations
- ID.IM-02AC-1AT-1AU-1CA-1CA-2CA-5CA-7CA-8CM-1CP-1CP-2CP-4IA-1IR-1IR-3IR-4IR-8MA-1MP-1PE-1PL-1PL-2PM-1PM-4PM-31PS-1PT-1RA-1RA-3RA-5RA-7SA-1SA-8SA-11SC-1SI-1SI-2SI-4SR-1SR-5
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- ID.IM-03AC-1AT-1AU-1CA-1CA-2CA-5CA-7CA-8CM-1CP-1CP-2IA-1IR-1IR-4IR-8MA-1MP-1PE-1PL-1PL-2PM-1PM-4PM-31PS-1PT-1RA-1RA-3RA-5RA-7SA-1SA-4SA-8SA-11SC-1SI-1SI-2SI-4SR-1SR-5
Improvements are identified from execution of operational processes, procedures, and activities
- ID.IM-04CP-2IR-8PL-2SR-2
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
Control text and SP 800-53 Rev 5 references from the official NIST CSF 2.0 and OLIR releases.
Automate improvement with agents
Paste an example into your coding assistant and an agent builds the automation around your tools.