Cover image for project: Nexus Compliance Hub IN PROGRESS

Technical summary

Native NEXUS plugin for tracking controls from NIST CSF 2.0, ISO/IEC 27001:2022 and PNSI. The catalog stores status, owners, evidence and notes, while the gap report links pending controls to active plugins and MITRE ATT&CK mitigations; lookups also reach the Intelligence Hub and the /compliance command.

Executed scope

  • backend.php backend (496 lines): static MVP catalog with 51 controls (22 NIST CSF 2.0, 15 ISO 27001 Annex A, 14 PNSI Decree 12.572/2025), each with evidence_plugins (slugs of NEXUS plugins that help cover the control) and evidence_mitre (M#### IDs assigned via compliance_mitre_links() — catalogs are not merged, only cross technical evidence is suggested).
  • compliance_install(): creates compliance_control_state (control_id PK varchar(32), framework, status default planned, owner, evidence, notes, updated_at, updated_by) with idx_compliance_fw_status (framework, status) index.
  • 5 API actions via PluginManager::registerApiAction — compliance_list (framework nist/iso/pnsi, status and q filters + stats), compliance_save (validates the control against the catalog and the status, limits owner ≤ 100, evidence ≤ 2000, notes ≤ 4000, INSERT/UPDATE), compliance_gaps, compliance_lookup and compliance_stats.
  • Auditing: every compliance_save logs an event in the core nx-audit.php (audit_log_event('compliance_control_update', ...) with control_id/status/owner).
  • Intelligence Hub enricher: compliance_detect_ids() (regex for NIST GV/ID/PR/DE/RS/RC.XX, ISO A.x.y and PNSI PNSI.* IDs) + compliance_intel_enrich() emitting compliance_control signals with severity 2 when the control is planned/partial (cached).
  • Alpine.js UI (tab.php 352 lines): "Compliance Hub" tab in the panel with 5 stat cards (Total, Implemented, Partial, Planned, Gaps), two sub-tabs (Catalog / Gap report), framework/status filters and search, active (green) and inactive (strikethrough) plugin chips, M#### chips with a direct link to the MITRE ATT&CK tab, and an edit modal (status, owner, evidence, notes).
  • Fast Response slash: /compliance <ID> → compliance_lookup (fastr.json).
  • No external API key: uses the NEXUS API key (Bearer + CSRF) on the panel REST actions.

Stack and tooling

  • PHP 8 (no framework)
  • MySQL 8 (compliance_control_state table)
  • Alpine.js + Tailwind CSS
  • NEXUS plugin system (PluginManager) + auditing core (nx-audit.php)
  • Control ID detection regex (NIST / ISO / PNSI)

Operational tags

  • Compliance
  • Security
  • GRC
  • NIST CSF 2.0
  • ISO 27001
  • PNSI

Operational outcome

  • Consolidated NEXUS compliance tracking into a single plugin: MVP catalog with NIST CSF 2.0, ISO 27001 (Annex A subset) and PNSI (Decree 12.572/2025, which replaces Decree 9.637/2018, revoked).
  • Objective gap report: planned/partial controls crossed with the active NEXUS plugins (acting as technical evidence) and MITRE M#### mitigations to check in the MITRE ATT&CK tab.
  • Traceable evidence: every update records date/author and fires an audit event in the core (audit_log_event).
  • Intelligence Hub and Fast Responses integration: control IDs mentioned in tasks/comments generate automatic signals, and /compliance <ID> looks up the control on demand.
  • Cross-link with the nexus-mitre-attack-compliance plugin without merging catalogs: manual GRC vs automated checks stay separate.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Native NEXUS plugin (is_core) for a MVP compliance registry with NIST CSF 2.0, ISO/IEC 27001:2022 (Annex A subset) and PNSI (Decree 12.572/2025): a control catalog with status, owner, evidence, gap report crossed with active NEXUS plugins and MITRE ATT&CK cross-links.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.