Framework

NIST CSF 2.0

NIST Cybersecurity Framework 2.0

106 requirements · 70 connected unified controls

Open NIST CSF 2.0 in the map
Version
2.0
Published
2024-02-26
Amendments
none

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

Govern

RequirementUnified control and mapping
GV.OC-01Organizational Context: The organizational mission is understood and informs cybersecurity risk management
GV.OC-02Organizational Context: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
GV.OC-03Organizational Context: Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
GV.OC-04Organizational Context: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
GV.OC-05Organizational Context: Outcomes, capabilities, and services that the organization depends on are understood and communicated
GV.RM-01Risk Management Strategy: Risk management objectives are established and agreed to by organizational stakeholders
GV.RM-02Risk Management Strategy: Risk appetite and risk tolerance statements are established, communicated, and maintained
GV.RM-03Risk Management Strategy: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
GV.RM-04Risk Management Strategy: Strategic direction that describes appropriate risk response options is established and communicated
UC-RISK-09 — Select, plan, and implement risk treatmentsPartial

Remaining requirement: establishing and communicating the strategic risk-response direction itself; this UC only applies that direction during treatment selection

GV.RM-05Risk Management Strategy: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
GV.RM-06Risk Management Strategy: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
GV.RM-07Risk Management Strategy: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
GV.RR-01Roles, Responsibilities, and Authorities: Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
GV.RR-02Roles, Responsibilities, and Authorities: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
GV.RR-03Roles, Responsibilities, and Authorities: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
GV.RR-04Roles, Responsibilities, and Authorities: Cybersecurity is included in human resources practices
GV.PO-01Policy: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
GV.PO-02Policy: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
GV.OV-01Oversight: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
GV.OV-02Oversight: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
GV.OV-03Oversight: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
GV.SC-01Cybersecurity Supply Chain Risk Management: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
GV.SC-02Cybersecurity Supply Chain Risk Management: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
GV.SC-03Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
GV.SC-04Cybersecurity Supply Chain Risk Management: Suppliers are known and prioritized by criticality
GV.SC-05Cybersecurity Supply Chain Risk Management: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
GV.SC-06Cybersecurity Supply Chain Risk Management: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
GV.SC-07Cybersecurity Supply Chain Risk Management: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
GV.SC-08Cybersecurity Supply Chain Risk Management: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
GV.SC-09Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
UC-TPRM-04 — Monitor vendor performance, services, and riskPartial

Remaining requirement: integration of practices across the technology life cycle satisfied by program control

GV.SC-10Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

Identify

RequirementUnified control and mapping
ID.AM-01Asset Management: Inventories of hardware managed by the organization are maintained
ID.AM-02Asset Management: Inventories of software, services, and systems managed by the organization are maintained
ID.AM-03Asset Management: Representations of the organization's authorized network communication and internal and external network data flows are maintained
ID.AM-04Asset Management: Inventories of services provided by suppliers are maintained
ID.AM-05Asset Management: Assets are prioritized based on classification, criticality, resources, and impact on the mission
ID.AM-07Asset Management: Inventories of data and corresponding metadata for designated data types are maintained
ID.AM-08Asset Management: Systems, hardware, software, services, and data are managed throughout their life cycles
ID.RA-01Risk Assessment: Vulnerabilities in assets are identified, validated, and recorded
ID.RA-02Risk Assessment: Cyber threat intelligence is received from information sharing forums and sources
ID.RA-03Risk Assessment: Internal and external threats to the organization are identified and recorded
ID.RA-04Risk Assessment: Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
ID.RA-05Risk Assessment: Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
ID.RA-06Risk Assessment: Risk responses are chosen, prioritized, planned, tracked, and communicated
ID.RA-07Risk Assessment: Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
ID.RA-08Risk Assessment: Processes for receiving, analyzing, and responding to vulnerability disclosures are established
ID.RA-09Risk Assessment: The authenticity and integrity of hardware and software are assessed prior to acquisition and use
ID.RA-10Risk Assessment: Critical suppliers are assessed prior to acquisition
ID.IM-01Improvement: Improvements are identified from evaluations
ID.IM-02Improvement: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
UC-AUDIT-17 — Follow up on findings and escalate risk acceptancePartial

Remaining requirement: ID.IM-02's security-test-and-exercise-driven improvement is an operations outcome only partially covered by audit follow-up; its operational home is the improvement objective (UC-ASSET-11)

ID.IM-03Improvement: Improvements are identified from execution of operational processes, procedures, and activities
ID.IM-04Improvement: Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

Protect

RequirementUnified control and mapping
PR.AA-01Identity Management, Authentication, and Access Control: Identities and credentials for authorized users, services, and hardware are managed by the organization
UC-ACCESS-06 — Manage unique identities and identifiers end to endPartial

Remaining requirement: credential issuance and protection satisfied by the authenticator management control

PR.AA-02Identity Management, Authentication, and Access Control: Identities are proofed and bound to credentials based on the context of interactions
PR.AA-03Identity Management, Authentication, and Access Control: Users, services, and hardware are authenticated
UC-ACCESS-09 — Authenticate all users with multi-factor authenticationPartial

Remaining requirement: service and hardware authentication satisfied by the device/service authentication control

PR.AA-04Identity Management, Authentication, and Access Control: Identity assertions are protected, conveyed, and verified
PR.AA-05Identity Management, Authentication, and Access Control: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of dutiesPartial

Remaining requirement: periodic review of granted access rights, addressed by the access-review control

PR.AA-06Identity Management, Authentication, and Access Control: Physical access to assets is managed, monitored, and enforced commensurate with risk
PR.AT-01Awareness and Training: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
PR.AT-02Awareness and Training: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
PR.DS-01Data Security: The confidentiality, integrity, and availability of data-at-rest are protected
UC-CRYPTO-01 — Encrypt data at rest and in transitPartial

Remaining requirement: availability of data-at-rest (backup/redundancy), addressed by the backup control

PR.DS-02Data Security: The confidentiality, integrity, and availability of data-in-transit are protected
UC-CRYPTO-01 — Encrypt data at rest and in transitPartial

Remaining requirement: availability of data-in-transit (resilient/redundant communication paths) and confidentiality of transmission over internal network paths not addressed

PR.DS-10Data Security: The confidentiality, integrity, and availability of data-in-use are protected
PR.DS-11Data Security: Backups of data are created, protected, maintained, and tested
PR.PS-01Platform Security: Configuration management practices are established and applied
PR.PS-02Platform Security: Software is maintained, replaced, and removed commensurate with risk
PR.PS-03Platform Security: Hardware is maintained, replaced, and removed commensurate with risk
PR.PS-04Platform Security: Log records are generated and made available for continuous monitoring
PR.PS-05Platform Security: Installation and execution of unauthorized software are prevented
PR.PS-06Platform Security: Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
PR.IR-01Technology Infrastructure Resilience: Networks and environments are protected from unauthorized logical access and usage
PR.IR-02Technology Infrastructure Resilience: The organization's technology assets are protected from environmental threats
PR.IR-03Technology Infrastructure Resilience: Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
UC-BCDR-04 — Provide redundant and alternate processing, storage, and telecomPartial

Remaining requirement: in-situ / normal-operations resilience mechanisms (load balancing, failover, hot-swap, graceful degradation) beyond alternate-site/redundant capacity

PR.IR-04Technology Infrastructure Resilience: Adequate resource capacity to ensure availability is maintained

Detect

RequirementUnified control and mapping
DE.CM-01Continuous Monitoring: Networks and network services are monitored to find potentially adverse events
DE.CM-02Continuous Monitoring: The physical environment is monitored to find potentially adverse events
DE.CM-03Continuous Monitoring: Personnel activity and technology usage are monitored to find potentially adverse events
DE.CM-06Continuous Monitoring: External service provider activities and services are monitored to find potentially adverse events
DE.CM-09Continuous Monitoring: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
DE.AE-02Adverse Event Analysis: Potentially adverse events are analyzed to better understand associated activities
DE.AE-03Adverse Event Analysis: Information is correlated from multiple sources
DE.AE-04Adverse Event Analysis: The estimated impact and scope of adverse events are understood
DE.AE-06Adverse Event Analysis: Information on adverse events is provided to authorized staff and tools
DE.AE-07Adverse Event Analysis: Cyber threat intelligence and other contextual information are integrated into the analysis
DE.AE-08Adverse Event Analysis: Incidents are declared when adverse events meet the defined incident criteria

Respond

RequirementUnified control and mapping
RS.MA-01Incident Management: The incident response plan is executed in coordination with relevant third parties once an incident is declared
RS.MA-02Incident Management: Incident reports are triaged and validated
RS.MA-03Incident Management: Incidents are categorized and prioritized
RS.MA-04Incident Management: Incidents are escalated or elevated as needed
RS.MA-05Incident Management: The criteria for initiating incident recovery are applied
RS.AN-03Incident Analysis: Analysis is performed to establish what has taken place during an incident and the root cause of the incident
RS.AN-06Incident Analysis: Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
RS.AN-07Incident Analysis: Incident data and metadata are collected, and their integrity and provenance are preserved
RS.AN-08Incident Analysis: An incident's magnitude is estimated and validated
RS.CO-02Incident Response Reporting and Communication: Internal and external stakeholders are notified of incidents
RS.CO-03Incident Response Reporting and Communication: Information is shared with designated internal and external stakeholders
RS.MI-01Incident Mitigation: Incidents are contained
RS.MI-02Incident Mitigation: Incidents are eradicated

Recover

RequirementUnified control and mapping
RC.RP-01Incident Recovery Plan Execution: The recovery portion of the incident response plan is executed once initiated from the incident response process
RC.RP-02Incident Recovery Plan Execution: Recovery actions are selected, scoped, prioritized, and performed
RC.RP-03Incident Recovery Plan Execution: The integrity of backups and other restoration assets is verified before using them for restoration
RC.RP-04Incident Recovery Plan Execution: Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
RC.RP-05Incident Recovery Plan Execution: The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
RC.RP-06Incident Recovery Plan Execution: The end of incident recovery is declared based on criteria, and incident-related documentation is completed
RC.CO-03Incident Recovery Communication: Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
RC.CO-04Incident Recovery Communication: Public updates on incident recovery are shared using approved methods and messaging