logo

NJP

GRC: Cyber Risk Institute (CRI) Profile Accelerator

GRC: Cyber Risk Institute (CRI) Profile Accelerator

by Service-now.com

Drive better cyber compliance management for financial service organizations

0 installs 0 reviews v22.3.1 Scoped Application Free-ish (consumes 1 tables) 1 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 10 -10
180 days of no change
2025-10-28 9 +1
63 days of no change
2025-08-25 8 +1
62 days of no change
2025-06-23 7 +1
2025-06-22 6 +1
25 days of no change
2025-05-27 5 +1
11 days of no change
2025-05-15 4 +1
6 days of no change
2025-05-08 3 +1
56 days of no change
2025-03-12 2 +1
22 days of no change
2025-02-17 1 +1

About

The Cyber Risk Institute (CRI) consists of framework profile and assessments that enable organizations to strengthen cyber compliance management. This framework includes comprehensive diagnostic statements (control objectives) aligned with NIST CSF 2.0 and is mapped to financial services regulatory references, such as FS citations from Federal Financial Institutions Examination Council Cybersecurity Assessment Tool (FFIEC CAT).

With the Cyber Risk Institute (CRI) Accelerator offering, customers can:

- Import a CRI profile that includes relevant authority documents, citations, and control objectives based on NIST CSF.
- Streamline risk management with automated tiering and selection of CRI assessments, conducted using the smart assessment engine.
- Automate control creation based on the tier and generate a compliance score from the CRI assessment responses, which then roll up to the entity level.

Key Features

The Cyber Risk Institute (CRI) Accelerator enables financial service institutions to implement appropriate controls tailored to their type and size. It drives standardization to improve efficiency, enhance compliance, and reduce risk. 

The accelerator includes:

- A CRI profile that aligns with NIST CSF v2.0, containing detailed diagnostic statements (control objectives) and mapping to financial services regulatory references (FS citations).
- Out-of-the-box content for NIST CSF v2.0, FFIEC CAT, and the CRI Profile.
- Applicability across four tiers for institutions of different sizes.
- Automatic identification of CRI assessments based on tiering assessment results.
- Tiering and CRI assessments conducted using the smart assessment engine.
- Automatic creation of controls based on tiering results.
- Detailed guidance and instructions for each CRI assessment question, including recommended evidence and required justification.
- Automatic calculation of a compliance score based on CRI assessment responses, with scores rolled up to the entity level. 

 

Version History (5)
v22.3.1 2026-06-16 16:35:30
New Enabled versioning support for CRI tiering and assessments. Enhancements to query range ACLs: Consistent access control — All tables include ...
v22.0.1 2026-03-12 15:51:52
Changed Updated the control objective content records with record nature field as Current version and state as published  Updated the control...
v21.1.0 2025-12-11 12:49:31
Fixed Added a read-only attribute to the read-only field 'CRI Tier' in Control objective table to enhance security.
v21.0.1 2025-07-31 15:54:58
Changed Smart assessment updates for CRI and Tiering assessments to support the introduction of a new reference field called "purpose."
v19.1.0 2024-11-07 15:55:45
Changed Security fixes Labels
ID: 5dda0cc1dde08a103e0dbb374782b371 · Published: Jun 2026 · Updated: Sep 09, 2026