Problem and impact

Research problem, aim, stakeholders, evidence base, and intended outcomes.

Problem statement

Cybersecurity and GRC teams must distinguish artifacts that demonstrate control operation from material that's incomplete, irrelevant, stale, or contradictory. Treating a policy document as proof can create false assurance because relevance isn't the same thing as evidence of operation.

NIST SP 800-53A Rev. 5 grounds the assessment problem in verifying implementation and outcomes. NIST Small Business Cybersecurity guidance also recognizes real cybersecurity resource and budget constraints among smaller organizations. ControlSift studies whether low-cost evidence-triage methods can help without replacing human judgment.

Research aim

Evaluate a five-class evidence-quality task using a low-cost classical baseline and small-language-model methods, while publishing failures and research boundaries rather than forcing an AI-success narrative.

Primary metric
Macro F1 on test and challenge splits
Classical experiments
Dataset v1.1.0: majority and TF-IDF + logistic regression
Gemma experiments
Dataset v1.0.0: zero-shot, few-shot, and QLoRA
Comparison boundary
Within-version comparisons are controlled; cross-version scores are descriptive only

Stakeholders

Intended outcomes

The project delivers an open research artifact, a transparent experiment record, failure analysis, assurance documentation, and a measured answer to what the small-model experiments did and didn't show. For the MMC rubric the project uses option 4, Reduced Inequalities; the official United Nations designation is SDG 10.

Out of scope