| A current inventory of assets | A dated external asset inventory covering domains, subdomains, reachable services and exposed panels, with the attribution evidence that ties each entry to your organisation and not to a similar name. | Attack Surface Management |
| CSCRF asset inventory covers the whole estate, including internal systems. Outside-in discovery covers the internet-facing part of it and nothing else. The internal register stays yours to maintain. |
| Monitoring that runs continuously, not at a single point in time | A change record, not a report: what appeared, what changed, when it was first observed, and when it stopped being observed. The record itself is the evidence. | Attack Surface Management |
| This is a record of external exposure. It is not a SOC, and it does not discharge whatever SOC or M-SOC obligation attaches to your tier. Which one attaches, and on what terms, is a classification question this page does not answer. Security Brigade publishes the tier cards that do. |
| Closure of findings inside a defined remediation timeline | Per-finding timestamps for first observed, acknowledged, owner assigned and closed, measured against the remediation window your own policy sets, so adherence can be queried instead of reconstructed. | The platform |
| The window is yours, not ours. CSCRF does not publish one universal remediation SLA, so the trail records adherence to whatever timeline your policy and IT Committee have defined. |
| Risks knowingly carried instead of remediated | An accepted-risk record holding the finding, the approver, the rationale and the review date. It stays alongside the open queue instead of being deleted out of it, so an accepted risk resurfaces when its review date arrives. | The platform |
| Acceptance is a decision your IT Committee or its delegate makes. The platform records the decision and keeps the finding visible; it does not make the decision, approve it, or judge whether it was reasonable. |
| Third-party and supply-chain exposure | Vendor-side external findings scored with the identical categories, the same maths and the same bands used on your own estate, so an internal target and a vendor threshold are directly comparable. | Third-Party Risk Management |
| The August 2025 clarifications place supply-chain risk assessment in consultation with the IT Committee. Outside-in vendor findings are an input to that assessment. They are not the assessment, and they do not see anything inside a vendor perimeter. |
| Exposure that has been tested, not only observed (which CSCRF does not ask for) | Where it is safe and authorised, a validation record naming what was tested, the scope it was bounded to, the time it ran and the audit identifier for the run. | Continuous Automated Red-Teaming |
| SEBI made BAS and Continuous Automated Red-Teaming recommendatory on 28 August 2025. See the section below before treating it as an obligation. Validation is also never universal: what was not tested says so. |
| Awareness of directives issued against you | A dated log of advisories and directives from the authorities in scope for you, each routed to the part of the platform that holds your evidence for it, so the open question is whether a directive applies to you, not whether it exists. | Regulatory Intelligence |
| Programme context, never legal advice. Tracking covers 31 authorities, which matters because SEBI amends this framework often, but a feed cannot tell you whether an amendment binds you. |
| An audit trail of who did what | An action log per finding: who changed its state, what they changed it to, and when. Nothing is deleted from the queue, so a closed or accepted finding is still there to be produced. | The platform |
| This is the platform’s own log and covers activity inside ShadowMap. It is one source among the several a CSCRF review will ask for, not the whole audit trail. |