standard
NIST CSF 2.0
NIST Cybersecurity Framework 2.0
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- nist-csf-2
- authority
- framework
Details
- authority
- framework
- version
- 2.0
- publicationDate
- 2024-02-26
- amendmentState
- none
- effectiveDate
- Not provided
- source_url
- Not provided
- reviewed_at
- Not provided
- note
- Not provided
- propositions
Source
No record-specific source URL is provided.
Connections
- PR.IR-03 — Technology Infrastructure Resilience: Mechanisms are implemented to achieve resilience requirements in normal and adverse situations belongs_to NIST CSF 2.0
- RC.RP-06 — Incident Recovery Plan Execution: The end of incident recovery is declared based on criteria, and incident-related documentation is completed belongs_to NIST CSF 2.0
- GV.SC-01 — Cybersecurity Supply Chain Risk Management: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders belongs_to NIST CSF 2.0
- DE.AE-06 — Adverse Event Analysis: Information on adverse events is provided to authorized staff and tools belongs_to NIST CSF 2.0
- RS.MI-01 — Incident Mitigation: Incidents are contained belongs_to NIST CSF 2.0
- GV.RM-02 — Risk Management Strategy: Risk appetite and risk tolerance statements are established, communicated, and maintained belongs_to NIST CSF 2.0
- PR.PS-03 — Platform Security: Hardware is maintained, replaced, and removed commensurate with risk belongs_to NIST CSF 2.0
- ID.AM-07 — Asset Management: Inventories of data and corresponding metadata for designated data types are maintained belongs_to NIST CSF 2.0
- PR.AA-02 — Identity Management, Authentication, and Access Control: Identities are proofed and bound to credentials based on the context of interactions belongs_to NIST CSF 2.0
- RC.RP-04 — Incident Recovery Plan Execution: Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms belongs_to NIST CSF 2.0
- ID.RA-08 — Risk Assessment: Processes for receiving, analyzing, and responding to vulnerability disclosures are established belongs_to NIST CSF 2.0
- RC.CO-03 — Incident Recovery Communication: Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders belongs_to NIST CSF 2.0
- GV.PO-01 — Policy: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced belongs_to NIST CSF 2.0
- GV.RM-07 — Risk Management Strategy: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions belongs_to NIST CSF 2.0
- ID.AM-08 — Asset Management: Systems, hardware, software, services, and data are managed throughout their life cycles belongs_to NIST CSF 2.0
- GV.RR-02 — Roles, Responsibilities, and Authorities: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced belongs_to NIST CSF 2.0
- RS.MA-03 — Incident Management: Incidents are categorized and prioritized belongs_to NIST CSF 2.0
- RS.MA-04 — Incident Management: Incidents are escalated or elevated as needed belongs_to NIST CSF 2.0
- GV.SC-06 — Cybersecurity Supply Chain Risk Management: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships belongs_to NIST CSF 2.0
- GV.RR-01 — Roles, Responsibilities, and Authorities: Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving belongs_to NIST CSF 2.0
- GV.SC-10 — Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement belongs_to NIST CSF 2.0
- ID.IM-03 — Improvement: Improvements are identified from execution of operational processes, procedures, and activities belongs_to NIST CSF 2.0
- RS.AN-08 — Incident Analysis: An incident's magnitude is estimated and validated belongs_to NIST CSF 2.0
- RS.AN-06 — Incident Analysis: Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved belongs_to NIST CSF 2.0
- PR.AA-06 — Identity Management, Authentication, and Access Control: Physical access to assets is managed, monitored, and enforced commensurate with risk belongs_to NIST CSF 2.0
- PR.DS-11 — Data Security: Backups of data are created, protected, maintained, and tested belongs_to NIST CSF 2.0
- DE.AE-03 — Adverse Event Analysis: Information is correlated from multiple sources belongs_to NIST CSF 2.0
- PR.IR-04 — Technology Infrastructure Resilience: Adequate resource capacity to ensure availability is maintained belongs_to NIST CSF 2.0
- GV.RM-05 — Risk Management Strategy: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties belongs_to NIST CSF 2.0
- DE.AE-08 — Adverse Event Analysis: Incidents are declared when adverse events meet the defined incident criteria belongs_to NIST CSF 2.0
- PR.AA-05 — Identity Management, Authentication, and Access Control: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties belongs_to NIST CSF 2.0
- PR.IR-02 — Technology Infrastructure Resilience: The organization's technology assets are protected from environmental threats belongs_to NIST CSF 2.0
- ID.RA-04 — Risk Assessment: Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded belongs_to NIST CSF 2.0
- GV.SC-03 — Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes belongs_to NIST CSF 2.0
- PR.PS-02 — Platform Security: Software is maintained, replaced, and removed commensurate with risk belongs_to NIST CSF 2.0
- GV.RM-04 — Risk Management Strategy: Strategic direction that describes appropriate risk response options is established and communicated belongs_to NIST CSF 2.0
- GV.OV-01 — Oversight: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction belongs_to NIST CSF 2.0
- GV.SC-04 — Cybersecurity Supply Chain Risk Management: Suppliers are known and prioritized by criticality belongs_to NIST CSF 2.0
- PR.PS-06 — Platform Security: Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle belongs_to NIST CSF 2.0
- DE.AE-07 — Adverse Event Analysis: Cyber threat intelligence and other contextual information are integrated into the analysis belongs_to NIST CSF 2.0
- GV.OC-01 — Organizational Context: The organizational mission is understood and informs cybersecurity risk management belongs_to NIST CSF 2.0
- PR.PS-01 — Platform Security: Configuration management practices are established and applied belongs_to NIST CSF 2.0
- RC.RP-02 — Incident Recovery Plan Execution: Recovery actions are selected, scoped, prioritized, and performed belongs_to NIST CSF 2.0
- ID.RA-06 — Risk Assessment: Risk responses are chosen, prioritized, planned, tracked, and communicated belongs_to NIST CSF 2.0
- RS.AN-07 — Incident Analysis: Incident data and metadata are collected, and their integrity and provenance are preserved belongs_to NIST CSF 2.0
- GV.OV-02 — Oversight: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks belongs_to NIST CSF 2.0
- RS.AN-03 — Incident Analysis: Analysis is performed to establish what has taken place during an incident and the root cause of the incident belongs_to NIST CSF 2.0
- PR.AT-02 — Awareness and Training: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind belongs_to NIST CSF 2.0
- GV.RM-01 — Risk Management Strategy: Risk management objectives are established and agreed to by organizational stakeholders belongs_to NIST CSF 2.0
- RC.RP-01 — Incident Recovery Plan Execution: The recovery portion of the incident response plan is executed once initiated from the incident response process belongs_to NIST CSF 2.0
- ID.IM-01 — Improvement: Improvements are identified from evaluations belongs_to NIST CSF 2.0
- ID.AM-03 — Asset Management: Representations of the organization's authorized network communication and internal and external network data flows are maintained belongs_to NIST CSF 2.0
- GV.RM-06 — Risk Management Strategy: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated belongs_to NIST CSF 2.0
- RC.CO-04 — Incident Recovery Communication: Public updates on incident recovery are shared using approved methods and messaging belongs_to NIST CSF 2.0
- GV.SC-07 — Cybersecurity Supply Chain Risk Management: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship belongs_to NIST CSF 2.0
- PR.AA-01 — Identity Management, Authentication, and Access Control: Identities and credentials for authorized users, services, and hardware are managed by the organization belongs_to NIST CSF 2.0
- DE.AE-02 — Adverse Event Analysis: Potentially adverse events are analyzed to better understand associated activities belongs_to NIST CSF 2.0
- DE.CM-09 — Continuous Monitoring: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events belongs_to NIST CSF 2.0
- GV.SC-05 — Cybersecurity Supply Chain Risk Management: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties belongs_to NIST CSF 2.0
- PR.DS-02 — Data Security: The confidentiality, integrity, and availability of data-in-transit are protected belongs_to NIST CSF 2.0
- RC.RP-03 — Incident Recovery Plan Execution: The integrity of backups and other restoration assets is verified before using them for restoration belongs_to NIST CSF 2.0
- GV.SC-09 — Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle belongs_to NIST CSF 2.0
- PR.DS-10 — Data Security: The confidentiality, integrity, and availability of data-in-use are protected belongs_to NIST CSF 2.0
- GV.OC-03 — Organizational Context: Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed belongs_to NIST CSF 2.0
- GV.OC-04 — Organizational Context: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated belongs_to NIST CSF 2.0
- ID.RA-09 — Risk Assessment: The authenticity and integrity of hardware and software are assessed prior to acquisition and use belongs_to NIST CSF 2.0
- DE.AE-04 — Adverse Event Analysis: The estimated impact and scope of adverse events are understood belongs_to NIST CSF 2.0
- RS.MA-01 — Incident Management: The incident response plan is executed in coordination with relevant third parties once an incident is declared belongs_to NIST CSF 2.0
- GV.SC-02 — Cybersecurity Supply Chain Risk Management: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally belongs_to NIST CSF 2.0
- GV.RR-04 — Roles, Responsibilities, and Authorities: Cybersecurity is included in human resources practices belongs_to NIST CSF 2.0
- PR.PS-04 — Platform Security: Log records are generated and made available for continuous monitoring belongs_to NIST CSF 2.0
- ID.AM-01 — Asset Management: Inventories of hardware managed by the organization are maintained belongs_to NIST CSF 2.0
- RS.MA-05 — Incident Management: The criteria for initiating incident recovery are applied belongs_to NIST CSF 2.0
- RS.CO-03 — Incident Response Reporting and Communication: Information is shared with designated internal and external stakeholders belongs_to NIST CSF 2.0
- GV.PO-02 — Policy: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission belongs_to NIST CSF 2.0
- GV.RR-03 — Roles, Responsibilities, and Authorities: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies belongs_to NIST CSF 2.0
- DE.CM-02 — Continuous Monitoring: The physical environment is monitored to find potentially adverse events belongs_to NIST CSF 2.0
- PR.AA-04 — Identity Management, Authentication, and Access Control: Identity assertions are protected, conveyed, and verified belongs_to NIST CSF 2.0
- PR.DS-01 — Data Security: The confidentiality, integrity, and availability of data-at-rest are protected belongs_to NIST CSF 2.0
- ID.AM-02 — Asset Management: Inventories of software, services, and systems managed by the organization are maintained belongs_to NIST CSF 2.0
- ID.RA-03 — Risk Assessment: Internal and external threats to the organization are identified and recorded belongs_to NIST CSF 2.0
- ID.RA-02 — Risk Assessment: Cyber threat intelligence is received from information sharing forums and sources belongs_to NIST CSF 2.0
- PR.IR-01 — Technology Infrastructure Resilience: Networks and environments are protected from unauthorized logical access and usage belongs_to NIST CSF 2.0
- DE.CM-06 — Continuous Monitoring: External service provider activities and services are monitored to find potentially adverse events belongs_to NIST CSF 2.0
- PR.AT-01 — Awareness and Training: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind belongs_to NIST CSF 2.0
- RS.MI-02 — Incident Mitigation: Incidents are eradicated belongs_to NIST CSF 2.0
- RC.RP-05 — Incident Recovery Plan Execution: The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed belongs_to NIST CSF 2.0
- ID.AM-05 — Asset Management: Assets are prioritized based on classification, criticality, resources, and impact on the mission belongs_to NIST CSF 2.0
- ID.AM-04 — Asset Management: Inventories of services provided by suppliers are maintained belongs_to NIST CSF 2.0
- ID.IM-04 — Improvement: Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved belongs_to NIST CSF 2.0
- ID.RA-01 — Risk Assessment: Vulnerabilities in assets are identified, validated, and recorded belongs_to NIST CSF 2.0
- GV.OV-03 — Oversight: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed belongs_to NIST CSF 2.0
- RS.CO-02 — Incident Response Reporting and Communication: Internal and external stakeholders are notified of incidents belongs_to NIST CSF 2.0
- GV.OC-02 — Organizational Context: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered belongs_to NIST CSF 2.0
- PR.AA-03 — Identity Management, Authentication, and Access Control: Users, services, and hardware are authenticated belongs_to NIST CSF 2.0
- GV.SC-08 — Cybersecurity Supply Chain Risk Management: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities belongs_to NIST CSF 2.0
- DE.CM-01 — Continuous Monitoring: Networks and network services are monitored to find potentially adverse events belongs_to NIST CSF 2.0
- DE.CM-03 — Continuous Monitoring: Personnel activity and technology usage are monitored to find potentially adverse events belongs_to NIST CSF 2.0
- ID.IM-02 — Improvement: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties belongs_to NIST CSF 2.0
- ID.RA-05 — Risk Assessment: Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization belongs_to NIST CSF 2.0
- RS.MA-02 — Incident Management: Incident reports are triaged and validated belongs_to NIST CSF 2.0
- PR.PS-05 — Platform Security: Installation and execution of unauthorized software are prevented belongs_to NIST CSF 2.0
- GV.RM-03 — Risk Management Strategy: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes belongs_to NIST CSF 2.0
- ID.RA-07 — Risk Assessment: Changes and exceptions are managed, assessed for risk impact, recorded, and tracked belongs_to NIST CSF 2.0
- GV.OC-05 — Organizational Context: Outcomes, capabilities, and services that the organization depends on are understood and communicated belongs_to NIST CSF 2.0
- ID.RA-10 — Risk Assessment: Critical suppliers are assessed prior to acquisition belongs_to NIST CSF 2.0