IN PROGRESS
Technical summary
Native NEXUS plugin for tracking controls from NIST CSF 2.0, ISO/IEC 27001:2022 and PNSI. The catalog stores status, owners, evidence and notes, while the gap report links pending controls to active plugins and MITRE ATT&CK mitigations; lookups also reach the Intelligence Hub and the /compliance command.
Executed scope
backend.phpbackend (496 lines): static MVP catalog with 51 controls (22 NIST CSF 2.0, 15 ISO 27001 Annex A, 14 PNSI Decree 12.572/2025), each withevidence_plugins(slugs of NEXUS plugins that help cover the control) andevidence_mitre(M####IDs assigned viacompliance_mitre_links()— catalogs are not merged, only cross technical evidence is suggested).compliance_install(): createscompliance_control_state(control_idPK varchar(32),framework,statusdefaultplanned,owner,evidence,notes,updated_at,updated_by) withidx_compliance_fw_status(framework,status) index.- 5 API actions via
PluginManager::registerApiAction—compliance_list(frameworknist/iso/pnsi,statusandqfilters + stats),compliance_save(validates the control against the catalog and the status, limitsowner≤ 100,evidence≤ 2000,notes≤ 4000, INSERT/UPDATE),compliance_gaps,compliance_lookupandcompliance_stats. - Auditing: every
compliance_savelogs an event in the corenx-audit.php(audit_log_event('compliance_control_update', ...)with control_id/status/owner). - Intelligence Hub enricher:
compliance_detect_ids()(regex for NISTGV/ID/PR/DE/RS/RC.XX, ISOA.x.yand PNSIPNSI.*IDs) +compliance_intel_enrich()emittingcompliance_controlsignals with severity 2 when the control isplanned/partial(cached). - Alpine.js UI (
tab.php352 lines): "Compliance Hub" tab in the panel with 5 stat cards (Total, Implemented, Partial, Planned, Gaps), two sub-tabs (Catalog / Gap report), framework/status filters and search, active (green) and inactive (strikethrough) plugin chips,M####chips with a direct link to the MITRE ATT&CK tab, and an edit modal (status, owner, evidence, notes). - Fast Response slash:
/compliance <ID>→compliance_lookup(fastr.json). - No external API key: uses the NEXUS API key (Bearer + CSRF) on the panel REST actions.
Stack and tooling
- PHP 8 (no framework)
- MySQL 8 (
compliance_control_statetable) - Alpine.js + Tailwind CSS
- NEXUS plugin system (
PluginManager) + auditing core (nx-audit.php) - Control ID detection regex (NIST / ISO / PNSI)
Operational tags
- Compliance
- Security
- GRC
- NIST CSF 2.0
- ISO 27001
- PNSI
Operational outcome
- Consolidated NEXUS compliance tracking into a single plugin: MVP catalog with NIST CSF 2.0, ISO 27001 (Annex A subset) and PNSI (Decree 12.572/2025, which replaces Decree 9.637/2018, revoked).
- Objective gap report:
planned/partialcontrols crossed with the active NEXUS plugins (acting as technical evidence) and MITREM####mitigations to check in the MITRE ATT&CK tab. - Traceable evidence: every update records date/author and fires an audit event in the core (
audit_log_event). - Intelligence Hub and Fast Responses integration: control IDs mentioned in tasks/comments generate automatic signals, and
/compliance <ID>looks up the control on demand. - Cross-link with the
nexus-mitre-attack-complianceplugin without merging catalogs: manual GRC vs automated checks stay separate.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Native NEXUS plugin (is_core) for a MVP compliance registry with NIST CSF 2.0, ISO/IEC 27001:2022 (Annex A subset) and PNSI (Decree 12.572/2025): a control catalog with status, owner, evidence, gap report crossed with active NEXUS plugins and MITRE ATT&CK cross-links.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.