← Framework library

NIST Cybersecurity Framework 2.0

Selected subcategories across the six CSF 2.0 Functions: Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS) and Recover (RC). Govern is new in 2.0 and is the function most organisations are weakest on.

NIST (US Department of Commerce) · 2.0, February 2024 · United States (voluntary, used internationally) · Official source

CSF is a voluntary framework organised around outcomes, not a prescriptive control list, and is intended to be tailored to an organisation's risk profile. Subcategory text is paraphrased.
35 of 35 controls
GV.OC-01 Organisational mission is understood and informs risk management low

The organisational mission is understood and informs cybersecurity risk management.

GOVERN — Organizational Context policy-governancerisk-assessment
GV.RM-01 Risk management objectives are established and agreed high

Risk management objectives are established and agreed to by organisational stakeholders.

GOVERN — Risk Management Strategy risk-assessmentpolicy-governance
GV.RM-05 Communication of cybersecurity risk medium

Lines of communication across the organisation are established for cybersecurity risks, including risks from suppliers and other third parties.

GOVERN — Risk Management Strategy policy-governanceboard-oversight
GV.RR-02 Roles, responsibilities and authorities are established medium

Roles, responsibilities and authorities related to cybersecurity risk management are established, communicated, understood and enforced.

GOVERN — Roles, Responsibilities and Authorities roles-responsibilities
GV.PO-01 Cybersecurity policy is established and communicated high

Policy for managing cybersecurity risks is established based on organisational context, cybersecurity strategy and priorities, and is communicated and enforced.

GOVERN — Policy policy-governance
GV.SC-03 Supply chain risk management is integrated high

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment and improvement processes.

GOVERN — Supply Chain Risk Management vendor-managementthird-party
GV.SC-08 Suppliers are included in incident planning and response medium

Relevant suppliers and other third parties are included in incident planning, response and recovery activities.

GOVERN — Supply Chain Risk Management vendor-managementincident-response
ID.AM-01 Inventories of hardware are maintained high

Inventories of hardware managed by the organisation are maintained.

IDENTIFY — Asset Management asset-managementinventory
ID.AM-02 Inventories of software, services and systems are maintained high

Inventories of software, services and systems managed by the organisation are maintained.

IDENTIFY — Asset Management asset-managementinventorycloud
ID.AM-05 Assets are prioritised by criticality medium

Assets are prioritised based on classification, criticality, resources and impact on the mission.

IDENTIFY — Asset Management asset-managementdata-classification
ID.RA-01 Vulnerabilities are identified, validated and recorded critical

Vulnerabilities in assets are identified, validated and recorded.

IDENTIFY — Risk Assessment vulnerability-management
ID.RA-05 Risks are prioritised to inform response high

Threats, vulnerabilities, likelihoods and impacts are used to understand inherent risk and inform risk response prioritisation.

IDENTIFY — Risk Assessment risk-assessment
ID.IM-01 Improvements are identified from evaluations medium

Improvements are identified from evaluations, including self-assessments, audits and reviews.

IDENTIFY — Improvement audit
PR.AA-01 Identities and credentials are managed critical

Identities and credentials for authorised users, services and hardware are managed by the organisation.

PROTECT — Identity, Authentication and Access Control access-controlauthentication
PR.AA-03 Users, services and hardware are authenticated critical

Users, services and hardware are authenticated, with the strength of authentication commensurate with risk.

PROTECT — Identity, Authentication and Access Control authenticationmfa
PR.AA-05 Access permissions follow least privilege and separation of duties critical

Access permissions, entitlements and authorisations are defined in a policy, managed, enforced and reviewed, and incorporate the principles of least privilege and separation of duties.

PROTECT — Identity, Authentication and Access Control access-controlprivileged-accesssegregation
PR.AT-01 Personnel are provided awareness and training high

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.

PROTECT — Awareness and Training trainingawareness
PR.DS-01 Confidentiality, integrity and availability of data at rest critical

The confidentiality, integrity and availability of data at rest are protected.

PROTECT — Data Security encryption-at-restkey-management
PR.DS-02 Confidentiality, integrity and availability of data in transit critical

The confidentiality, integrity and availability of data in transit are protected.

PROTECT — Data Security encryption-in-transitnetwork-security
PR.DS-11 Backups of data are created, protected and tested critical

Backups of data are created, protected, maintained and tested.

PROTECT — Data Security backuprecoverydr-testing
PR.PS-02 Software is maintained, replaced and removed commensurate with risk high

Software is maintained, replaced and removed commensurate with risk, including timely application of patches.

PROTECT — Platform Security patchingvulnerability-management
PR.PS-04 Log records are generated and made available for monitoring high

Log records are generated and made available for continuous monitoring.

PROTECT — Platform Security logging
PR.PS-06 Secure software development practices are integrated high

Secure software development practices are integrated and their performance is monitored throughout the software development life cycle.

PROTECT — Platform Security sdlcsecure-development
PR.IR-01 Networks and environments are protected from unauthorised logical access high

Networks and environments are protected from unauthorised logical access and usage.

PROTECT — Technology Infrastructure Resilience network-securitysegregation
DE.CM-01 Networks and network services are monitored high

Networks and network services are monitored to find potentially adverse events.

DETECT — Continuous Monitoring monitoringnetwork-security
DE.CM-09 Computing hardware, software and services are monitored high

Computing hardware and software, runtime environments and their data are monitored to find potentially adverse events.

DETECT — Continuous Monitoring monitoringsiemendpoint
DE.AE-02 Potentially adverse events are analysed high

Potentially adverse events are analysed to better understand associated activities.

DETECT — Adverse Event Analysis monitoringincident-response
DE.AE-06 Information on adverse events is provided to authorised staff medium

Information on adverse events is provided to authorised staff and tools.

DETECT — Adverse Event Analysis monitoringincident-response
RS.MA-01 The incident response plan is executed critical

The incident response plan is executed in coordination with relevant third parties once an incident is declared.

RESPOND — Incident Management incident-response
RS.MA-02 Incident reports are triaged and validated high

Incident reports are triaged and validated.

RESPOND — Incident Management incident-response
RS.AN-03 Root cause is determined medium

Analysis is performed to establish what has taken place during an incident and the root cause of the incident.

RESPOND — Incident Analysis incident-response
RS.CO-02 Internal and external stakeholders are notified high

Internal and external stakeholders are notified of incidents in accordance with the organisation's reporting criteria.

RESPOND — Incident Response Reporting breach-notificationincident-response
RC.RP-01 The recovery portion of the incident response plan is executed high

The recovery portion of the incident response plan is executed once initiated from the incident response process.

RECOVER — Incident Recovery Plan Execution recoverybusiness-continuity
RC.RP-05 Integrity of restored assets is verified medium

The integrity of backups and other restoration assets is verified before using them for restoration.

RECOVER — Incident Recovery Plan Execution recoveryintegrity
RC.CO-03 Recovery activities are communicated low

Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders.

RECOVER — Incident Recovery Communication incident-response