← Framework library
NIST Cybersecurity Framework 2.0
Selected subcategories across the six CSF 2.0 Functions: Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS) and Recover (RC). Govern is new in 2.0 and is the function most organisations are weakest on.
NIST (US Department of Commerce) · 2.0, February 2024 · United States (voluntary, used internationally)
· Official source
CSF is a voluntary framework organised around outcomes, not a prescriptive control list, and is intended to be tailored to an organisation's risk profile. Subcategory text is paraphrased.
GV.OC-01
Organisational mission is understood and informs risk management
low
The organisational mission is understood and informs cybersecurity risk management.
GOVERN — Organizational Context
policy-governancerisk-assessment
GV.RM-01
Risk management objectives are established and agreed
high
Risk management objectives are established and agreed to by organisational stakeholders.
GOVERN — Risk Management Strategy
risk-assessmentpolicy-governance
GV.RM-05
Communication of cybersecurity risk
medium
Lines of communication across the organisation are established for cybersecurity risks, including risks from suppliers and other third parties.
GOVERN — Risk Management Strategy
policy-governanceboard-oversight
GV.RR-02
Roles, responsibilities and authorities are established
medium
Roles, responsibilities and authorities related to cybersecurity risk management are established, communicated, understood and enforced.
GOVERN — Roles, Responsibilities and Authorities
roles-responsibilities
GV.PO-01
Cybersecurity policy is established and communicated
high
Policy for managing cybersecurity risks is established based on organisational context, cybersecurity strategy and priorities, and is communicated and enforced.
GOVERN — Policy
policy-governance
GV.SC-03
Supply chain risk management is integrated
high
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment and improvement processes.
GOVERN — Supply Chain Risk Management
vendor-managementthird-party
GV.SC-08
Suppliers are included in incident planning and response
medium
Relevant suppliers and other third parties are included in incident planning, response and recovery activities.
GOVERN — Supply Chain Risk Management
vendor-managementincident-response
ID.AM-01
Inventories of hardware are maintained
high
Inventories of hardware managed by the organisation are maintained.
IDENTIFY — Asset Management
asset-managementinventory
ID.AM-02
Inventories of software, services and systems are maintained
high
Inventories of software, services and systems managed by the organisation are maintained.
IDENTIFY — Asset Management
asset-managementinventorycloud
ID.AM-05
Assets are prioritised by criticality
medium
Assets are prioritised based on classification, criticality, resources and impact on the mission.
IDENTIFY — Asset Management
asset-managementdata-classification
ID.RA-01
Vulnerabilities are identified, validated and recorded
critical
Vulnerabilities in assets are identified, validated and recorded.
IDENTIFY — Risk Assessment
vulnerability-management
ID.RA-05
Risks are prioritised to inform response
high
Threats, vulnerabilities, likelihoods and impacts are used to understand inherent risk and inform risk response prioritisation.
IDENTIFY — Risk Assessment
risk-assessment
ID.IM-01
Improvements are identified from evaluations
medium
Improvements are identified from evaluations, including self-assessments, audits and reviews.
IDENTIFY — Improvement
audit
PR.AA-01
Identities and credentials are managed
critical
Identities and credentials for authorised users, services and hardware are managed by the organisation.
PROTECT — Identity, Authentication and Access Control
access-controlauthentication
PR.AA-03
Users, services and hardware are authenticated
critical
Users, services and hardware are authenticated, with the strength of authentication commensurate with risk.
PROTECT — Identity, Authentication and Access Control
authenticationmfa
PR.AA-05
Access permissions follow least privilege and separation of duties
critical
Access permissions, entitlements and authorisations are defined in a policy, managed, enforced and reviewed, and incorporate the principles of least privilege and separation of duties.
PROTECT — Identity, Authentication and Access Control
access-controlprivileged-accesssegregation
PR.AT-01
Personnel are provided awareness and training
high
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.
PROTECT — Awareness and Training
trainingawareness
PR.DS-01
Confidentiality, integrity and availability of data at rest
critical
The confidentiality, integrity and availability of data at rest are protected.
PROTECT — Data Security
encryption-at-restkey-management
PR.DS-02
Confidentiality, integrity and availability of data in transit
critical
The confidentiality, integrity and availability of data in transit are protected.
PROTECT — Data Security
encryption-in-transitnetwork-security
PR.DS-11
Backups of data are created, protected and tested
critical
Backups of data are created, protected, maintained and tested.
PROTECT — Data Security
backuprecoverydr-testing
PR.PS-02
Software is maintained, replaced and removed commensurate with risk
high
Software is maintained, replaced and removed commensurate with risk, including timely application of patches.
PROTECT — Platform Security
patchingvulnerability-management
PR.PS-04
Log records are generated and made available for monitoring
high
Log records are generated and made available for continuous monitoring.
PROTECT — Platform Security
logging
PR.PS-06
Secure software development practices are integrated
high
Secure software development practices are integrated and their performance is monitored throughout the software development life cycle.
PROTECT — Platform Security
sdlcsecure-development
PR.IR-01
Networks and environments are protected from unauthorised logical access
high
Networks and environments are protected from unauthorised logical access and usage.
PROTECT — Technology Infrastructure Resilience
network-securitysegregation
DE.CM-01
Networks and network services are monitored
high
Networks and network services are monitored to find potentially adverse events.
DETECT — Continuous Monitoring
monitoringnetwork-security
DE.CM-09
Computing hardware, software and services are monitored
high
Computing hardware and software, runtime environments and their data are monitored to find potentially adverse events.
DETECT — Continuous Monitoring
monitoringsiemendpoint
DE.AE-02
Potentially adverse events are analysed
high
Potentially adverse events are analysed to better understand associated activities.
DETECT — Adverse Event Analysis
monitoringincident-response
DE.AE-06
Information on adverse events is provided to authorised staff
medium
Information on adverse events is provided to authorised staff and tools.
DETECT — Adverse Event Analysis
monitoringincident-response
RS.MA-01
The incident response plan is executed
critical
The incident response plan is executed in coordination with relevant third parties once an incident is declared.
RESPOND — Incident Management
incident-response
RS.MA-02
Incident reports are triaged and validated
high
Incident reports are triaged and validated.
RESPOND — Incident Management
incident-response
RS.AN-03
Root cause is determined
medium
Analysis is performed to establish what has taken place during an incident and the root cause of the incident.
RESPOND — Incident Analysis
incident-response
RS.CO-02
Internal and external stakeholders are notified
high
Internal and external stakeholders are notified of incidents in accordance with the organisation's reporting criteria.
RESPOND — Incident Response Reporting
breach-notificationincident-response
RC.RP-01
The recovery portion of the incident response plan is executed
high
The recovery portion of the incident response plan is executed once initiated from the incident response process.
RECOVER — Incident Recovery Plan Execution
recoverybusiness-continuity
RC.RP-05
Integrity of restored assets is verified
medium
The integrity of backups and other restoration assets is verified before using them for restoration.
RECOVER — Incident Recovery Plan Execution
recoveryintegrity
RC.CO-03
Recovery activities are communicated
low
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders.
RECOVER — Incident Recovery Communication
incident-response