catalog: uuid: 720a010b-253c-4a94-bb65-cb58400966f5 metadata: title: Electronic Version of NIST Cybersecurity Framework 2.0 published: "2026-05-13T12:30:00-00:00" last-modified: "2026-05-11T16:01:09.00000-00:00" version: 1.2.0 oscal-version: v1.2.2 revisions: - title: NIST Cybersecurity Framework 2.0 last-modified: "2025-05-14T12:08:20.050176-05:00" version: 1.0.0 oscal-version: v1.1.3 links: - href: 720a010b-253c-4a94-bb65-cb58400966f5 rel: version-history remarks: OSCAL v1.2.2 representation of the NIST Cybersecurity Framework 2.0 with bug fixes for withdrawn categories and subcategories. props: - name: framework-identifier ns: https://csrc.nist.gov/ns/cprt value: CSF - name: framework-version-identifier ns: https://csrc.nist.gov/ns/cprt value: CSF_2_0_0 - name: generated-by ns: https://csrc.nist.gov/ns/cprt value: Cybersecurity And Privacy Open Reference Datasets In OSCAL (CAPORDINO) - name: publication-status ns: https://csrc.nist.gov/ns/cprt value: Final - name: keywords value: Critical infrastructure, cybersecurity, information security, information system, OSCAL, Open Security Controls Assessment Language, security functions, security requirements, system, system security links: - href: '#3ab41d8a-66e3-4732-ae28-07405dad5127' rel: alternate - href: '#a7f54afa-16cf-4200-a043-85aa554b93e4' rel: alternate - href: '#0451580b-8ef9-4f52-9182-bc887d6cf369' rel: canonical roles: - id: publisher title: Document converter to OSCAL - id: contact title: Contact - id: author title: Document content author parties: - uuid: 8238c306-4ee0-4321-a4fb-503adda3d8c1 type: organization name: National Institute of Standards and Technology short-name: NIST email-addresses: - capordino@nist.gov addresses: - addr-lines: - National Institute of Standards and Technology - 'Attn: Computer Security Division' - Information Technology Laboratory - 100 Bureau Drive (Mail Stop 2000) city: Gaithersburg state: MD postal-code: 20899-2000 - uuid: 49e0888a-e68c-43f1-a26d-7c88fb076e0e type: organization name: National Institute of Standards and Technology short-name: NIST email-addresses: - cyberframework@nist.gov addresses: - addr-lines: - National Institute of Standards and Technology - 'Attn: Applied Cybersecurity Division' - Information Technology Laboratory - 100 Bureau Drive (Mail Stop 2000) city: Gaithersburg state: MD postal-code: 20899-2000 responsible-parties: - role-id: publisher party-uuids: - 8238c306-4ee0-4321-a4fb-503adda3d8c1 - role-id: contact party-uuids: - 8238c306-4ee0-4321-a4fb-503adda3d8c1 - role-id: author party-uuids: - 49e0888a-e68c-43f1-a26d-7c88fb076e0e groups: - id: GV class: function title: GOVERN props: - name: sort-id value: "00001" - name: label value: GOVERN (GV) parts: - id: GV_overview name: overview prose: The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored controls: - id: GV.OC class: category title: Organizational Context props: - name: sort-id value: "00001.00001" - name: label value: Organizational Context (GV.OC) parts: - id: GV.OC_statement name: statement prose: The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood controls: - id: GV.OC-01 class: subcategory title: GV.OC-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00001.00001 - name: label value: GV.OC-01 parts: - id: GV.OC-01_statement name: statement prose: The organizational mission is understood and informs cybersecurity risk management - id: GV.OC-01.001 name: example ns: https://csrc.nist.gov/ns/csf prose: Share the organization's mission (e.g., through vision and mission statements, marketing, and service strategies) to provide a basis for identifying risks that may impede that mission - id: GV.OC-02 class: subcategory title: GV.OC-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00001.00002 - name: label value: GV.OC-02 parts: - id: GV.OC-02_statement name: statement prose: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered - id: GV.OC-02.002 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify relevant internal stakeholders and their cybersecurity-related expectations (e.g., performance and risk expectations of officers, directors, and advisors; cultural expectations of employees) - id: GV.OC-02.003 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify relevant external stakeholders and their cybersecurity-related expectations (e.g., privacy expectations of customers, business expectations of partnerships, compliance expectations of regulators, ethics expectations of society) - id: GV.OC-03 class: subcategory title: GV.OC-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00001.00003 - name: label value: GV.OC-03 parts: - id: GV.OC-03_statement name: statement prose: Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed - id: GV.OC-03.004 name: example ns: https://csrc.nist.gov/ns/csf prose: Determine a process to track and manage legal and regulatory requirements regarding protection of individuals' information (e.g., Health Insurance Portability and Accountability Act, California Consumer Privacy Act, General Data Protection Regulation) - id: GV.OC-03.005 name: example ns: https://csrc.nist.gov/ns/csf prose: Determine a process to track and manage contractual requirements for cybersecurity management of supplier, customer, and partner information - id: GV.OC-03.006 name: example ns: https://csrc.nist.gov/ns/csf prose: Align the organization's cybersecurity strategy with legal, regulatory, and contractual requirements - id: GV.OC-04 class: subcategory title: GV.OC-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00001.00004 - name: label value: GV.OC-04 parts: - id: GV.OC-04_statement name: statement prose: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated - id: GV.OC-04.007 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish criteria for determining the criticality of capabilities and services as viewed by internal and external stakeholders - id: GV.OC-04.008 name: example ns: https://csrc.nist.gov/ns/csf prose: Determine (e.g., from a business impact analysis) assets and business operations that are vital to achieving mission objectives and the potential impact of a loss (or partial loss) of such operations - id: GV.OC-04.009 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish and communicate resilience objectives (e.g., recovery time objectives) for delivering critical capabilities and services in various operating states (e.g., under attack, during recovery, normal operation) - id: GV.OC-05 class: subcategory title: GV.OC-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00001.00005 - name: label value: GV.OC-05 parts: - id: GV.OC-05_statement name: statement prose: Outcomes, capabilities, and services that the organization depends on are understood and communicated - id: GV.OC-05.010 name: example ns: https://csrc.nist.gov/ns/csf prose: Create an inventory of the organization's dependencies on external resources (e.g., facilities, cloud-based hosting providers) and their relationships to organizational assets and business functions - id: GV.OC-05.011 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify and document external dependencies that are potential points of failure for the organization's critical capabilities and services, and share that information with appropriate personnel - id: GV.OV class: category title: Oversight props: - name: sort-id value: "00001.00005" - name: label value: Oversight (GV.OV) parts: - id: GV.OV_statement name: statement prose: Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy controls: - id: GV.OV-01 class: subcategory title: GV.OV-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00005.00001 - name: label value: GV.OV-01 parts: - id: GV.OV-01_statement name: statement prose: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction - id: GV.OV-01.058 name: example ns: https://csrc.nist.gov/ns/csf prose: Measure how well the risk management strategy and risk results have helped leaders make decisions and achieve organizational objectives - id: GV.OV-01.059 name: example ns: https://csrc.nist.gov/ns/csf prose: Examine whether cybersecurity risk strategies that impede operations or innovation should be adjusted - id: GV.OV-02 class: subcategory title: GV.OV-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00005.00002 - name: label value: GV.OV-02 parts: - id: GV.OV-02_statement name: statement prose: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks - id: GV.OV-02.060 name: example ns: https://csrc.nist.gov/ns/csf prose: Review audit findings to confirm whether the existing cybersecurity strategy has ensured compliance with internal and external requirements - id: GV.OV-02.061 name: example ns: https://csrc.nist.gov/ns/csf prose: Review the performance oversight of those in cybersecurity-related roles to determine whether policy changes are necessary - id: GV.OV-02.062 name: example ns: https://csrc.nist.gov/ns/csf prose: Review strategy in light of cybersecurity incidents - id: GV.OV-03 class: subcategory title: GV.OV-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00005.00003 - name: label value: GV.OV-03 parts: - id: GV.OV-03_statement name: statement prose: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed - id: GV.OV-03.063 name: example ns: https://csrc.nist.gov/ns/csf prose: Review key performance indicators (KPIs) to ensure that organization-wide policies and procedures achieve objectives - id: GV.OV-03.064 name: example ns: https://csrc.nist.gov/ns/csf prose: Review key risk indicators (KRIs) to identify risks the organization faces, including likelihood and potential impact - id: GV.OV-03.065 name: example ns: https://csrc.nist.gov/ns/csf prose: Collect and communicate metrics on cybersecurity risk management with senior leadership - id: GV.PO class: category title: Policy props: - name: sort-id value: "00001.00004" - name: label value: Policy (GV.PO) parts: - id: GV.PO_statement name: statement prose: Organizational cybersecurity policy is established, communicated, and enforced controls: - id: GV.PO-01 class: subcategory title: GV.PO-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00004.00001 - name: label value: GV.PO-01 parts: - id: GV.PO-01_statement name: statement prose: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced - id: GV.PO-01.049 name: example ns: https://csrc.nist.gov/ns/csf prose: Create, disseminate, and maintain an understandable, usable risk management policy with statements of management intent, expectations, and direction - id: GV.PO-01.050 name: example ns: https://csrc.nist.gov/ns/csf prose: Periodically review policy and supporting processes and procedures to ensure that they align with risk management strategy objectives and priorities, as well as the high-level direction of the cybersecurity policy - id: GV.PO-01.051 name: example ns: https://csrc.nist.gov/ns/csf prose: Require approval from senior management on policy - id: GV.PO-01.052 name: example ns: https://csrc.nist.gov/ns/csf prose: Communicate cybersecurity risk management policy and supporting processes and procedures across the organization - id: GV.PO-01.053 name: example ns: https://csrc.nist.gov/ns/csf prose: Require personnel to acknowledge receipt of policy when first hired, annually, and whenever policy is updated - id: GV.PO-02 class: subcategory title: GV.PO-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00004.00002 - name: label value: GV.PO-02 parts: - id: GV.PO-02_statement name: statement prose: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission - id: GV.PO-02.054 name: example ns: https://csrc.nist.gov/ns/csf prose: Update policy based on periodic reviews of cybersecurity risk management results to ensure that policy and supporting processes and procedures adequately maintain risk at an acceptable level - id: GV.PO-02.055 name: example ns: https://csrc.nist.gov/ns/csf prose: Provide a timeline for reviewing changes to the organization's risk environment (e.g., changes in risk or in the organization's mission objectives), and communicate recommended policy updates - id: GV.PO-02.056 name: example ns: https://csrc.nist.gov/ns/csf prose: Update policy to reflect changes in legal and regulatory requirements - id: GV.PO-02.057 name: example ns: https://csrc.nist.gov/ns/csf prose: Update policy to reflect changes in technology (e.g., adoption of artificial intelligence) and changes to the business (e.g., acquisition of a new business, new contract requirements) - id: GV.RM class: category title: Risk Management Strategy props: - name: sort-id value: "00001.00002" - name: label value: Risk Management Strategy (GV.RM) parts: - id: GV.RM_statement name: statement prose: The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions controls: - id: GV.RM-01 class: subcategory title: GV.RM-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00002.00001 - name: label value: GV.RM-01 parts: - id: GV.RM-01_statement name: statement prose: Risk management objectives are established and agreed to by organizational stakeholders - id: GV.RM-01.012 name: example ns: https://csrc.nist.gov/ns/csf prose: Update near-term and long-term cybersecurity risk management objectives as part of annual strategic planning and when major changes occur - id: GV.RM-01.013 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish measurable objectives for cybersecurity risk management (e.g., manage the quality of user training, ensure adequate risk protection for industrial control systems) - id: GV.RM-01.014 name: example ns: https://csrc.nist.gov/ns/csf prose: Senior leaders agree about cybersecurity objectives and use them for measuring and managing risk and performance - id: GV.RM-02 class: subcategory title: GV.RM-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00002.00002 - name: label value: GV.RM-02 parts: - id: GV.RM-02_statement name: statement prose: Risk appetite and risk tolerance statements are established, communicated, and maintained - id: GV.RM-02.015 name: example ns: https://csrc.nist.gov/ns/csf prose: Determine and communicate risk appetite statements that convey expectations about the appropriate level of risk for the organization - id: GV.RM-02.016 name: example ns: https://csrc.nist.gov/ns/csf prose: Translate risk appetite statements into specific, measurable, and broadly understandable risk tolerance statements - id: GV.RM-02.017 name: example ns: https://csrc.nist.gov/ns/csf prose: Refine organizational objectives and risk appetite periodically based on known risk exposure and residual risk - id: GV.RM-03 class: subcategory title: GV.RM-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00002.00003 - name: label value: GV.RM-03 parts: - id: GV.RM-03_statement name: statement prose: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes - id: GV.RM-03.018 name: example ns: https://csrc.nist.gov/ns/csf prose: Aggregate and manage cybersecurity risks alongside other enterprise risks (e.g., compliance, financial, operational, regulatory, reputational, safety) - id: GV.RM-03.019 name: example ns: https://csrc.nist.gov/ns/csf prose: Include cybersecurity risk managers in enterprise risk management planning - id: GV.RM-03.020 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish criteria for escalating cybersecurity risks within enterprise risk management - id: GV.RM-04 class: subcategory title: GV.RM-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00002.00004 - name: label value: GV.RM-04 parts: - id: GV.RM-04_statement name: statement prose: Strategic direction that describes appropriate risk response options is established and communicated - id: GV.RM-04.021 name: example ns: https://csrc.nist.gov/ns/csf prose: Specify criteria for accepting and avoiding cybersecurity risk for various classifications of data - id: GV.RM-04.022 name: example ns: https://csrc.nist.gov/ns/csf prose: Determine whether to purchase cybersecurity insurance - id: GV.RM-04.023 name: example ns: https://csrc.nist.gov/ns/csf prose: Document conditions under which shared responsibility models are acceptable (e.g., outsourcing certain cybersecurity functions, having a third party perform financial transactions on behalf of the organization, using public cloud-based services) - id: GV.RM-05 class: subcategory title: GV.RM-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00002.00005 - name: label value: GV.RM-05 parts: - id: GV.RM-05_statement name: statement prose: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties - id: GV.RM-05.024 name: example ns: https://csrc.nist.gov/ns/csf prose: Determine how to update senior executives, directors, and management on the organization's cybersecurity posture at agreed-upon intervals - id: GV.RM-05.025 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify how all departments across the organization - such as management, operations, internal auditors, legal, acquisition, physical security, and HR - will communicate with each other about cybersecurity risks - id: GV.RM-06 class: subcategory title: GV.RM-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00002.00006 - name: label value: GV.RM-06 parts: - id: GV.RM-06_statement name: statement prose: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated - id: GV.RM-06.026 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish criteria for using a quantitative approach to cybersecurity risk analysis, and specify probability and exposure formulas - id: GV.RM-06.027 name: example ns: https://csrc.nist.gov/ns/csf prose: Create and use templates (e.g., a risk register) to document cybersecurity risk information (e.g., risk description, exposure, treatment, and ownership) - id: GV.RM-06.028 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish criteria for risk prioritization at the appropriate levels within the enterprise - id: GV.RM-06.029 name: example ns: https://csrc.nist.gov/ns/csf prose: Use a consistent list of risk categories to support integrating, aggregating, and comparing cybersecurity risks - id: GV.RM-07 class: subcategory title: GV.RM-07 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00002.00007 - name: label value: GV.RM-07 parts: - id: GV.RM-07_statement name: statement prose: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions - id: GV.RM-07.030 name: example ns: https://csrc.nist.gov/ns/csf prose: Define and communicate guidance and methods for identifying opportunities and including them in risk discussions (e.g., strengths, weaknesses, opportunities, and threats (SWOT) analysis) - id: GV.RM-07.031 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify stretch goals and document them - id: GV.RM-07.032 name: example ns: https://csrc.nist.gov/ns/csf prose: Calculate, document, and prioritize positive risks alongside negative risks - id: GV.RR class: category title: Roles, Responsibilities, and Authorities props: - name: sort-id value: "00001.00003" - name: label value: Roles, Responsibilities, and Authorities (GV.RR) parts: - id: GV.RR_statement name: statement prose: Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated controls: - id: GV.RR-01 class: subcategory title: GV.RR-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00003.00001 - name: label value: GV.RR-01 parts: - id: GV.RR-01_statement name: statement prose: Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving - id: GV.RR-01.033 name: example ns: https://csrc.nist.gov/ns/csf prose: Leaders (e.g., directors) agree on their roles and responsibilities in developing, implementing, and assessing the organization's cybersecurity strategy - id: GV.RR-01.034 name: example ns: https://csrc.nist.gov/ns/csf prose: Share leaders' expectations regarding a secure and ethical culture, especially when current events present the opportunity to highlight positive or negative examples of cybersecurity risk management - id: GV.RR-01.035 name: example ns: https://csrc.nist.gov/ns/csf prose: Leaders direct the CISO to maintain a comprehensive cybersecurity risk strategy and review and update it at least annually and after major events - id: GV.RR-01.036 name: example ns: https://csrc.nist.gov/ns/csf prose: Conduct reviews to ensure adequate authority and coordination among those responsible for managing cybersecurity risk - id: GV.RR-02 class: subcategory title: GV.RR-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00003.00002 - name: label value: GV.RR-02 parts: - id: GV.RR-02_statement name: statement prose: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced - id: GV.RR-02.037 name: example ns: https://csrc.nist.gov/ns/csf prose: Document risk management roles and responsibilities in policy - id: GV.RR-02.038 name: example ns: https://csrc.nist.gov/ns/csf prose: Document who is responsible and accountable for cybersecurity risk management activities and how those teams and individuals are to be consulted and informed - id: GV.RR-02.039 name: example ns: https://csrc.nist.gov/ns/csf prose: Include cybersecurity responsibilities and performance requirements in personnel descriptions - id: GV.RR-02.040 name: example ns: https://csrc.nist.gov/ns/csf prose: Document performance goals for personnel with cybersecurity risk management responsibilities, and periodically measure performance to identify areas for improvement - id: GV.RR-02.041 name: example ns: https://csrc.nist.gov/ns/csf prose: Clearly articulate cybersecurity responsibilities within operations, risk functions, and internal audit functions - id: GV.RR-03 class: subcategory title: GV.RR-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00003.00003 - name: label value: GV.RR-03 parts: - id: GV.RR-03_statement name: statement prose: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies - id: GV.RR-03.042 name: example ns: https://csrc.nist.gov/ns/csf prose: Conduct periodic management reviews to ensure that those given cybersecurity risk management responsibilities have the necessary authority - id: GV.RR-03.043 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify resource allocation and investment in line with risk tolerance and response - id: GV.RR-03.044 name: example ns: https://csrc.nist.gov/ns/csf prose: Provide adequate and sufficient people, process, and technical resources to support the cybersecurity strategy - id: GV.RR-04 class: subcategory title: GV.RR-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00001.00003.00004 - name: label value: GV.RR-04 parts: - id: GV.RR-04_statement name: statement prose: Cybersecurity is included in human resources practices - id: GV.RR-04.045 name: example ns: https://csrc.nist.gov/ns/csf prose: Integrate cybersecurity risk management considerations into human resources processes (e.g., personnel screening, onboarding, change notification, offboarding) - id: GV.RR-04.046 name: example ns: https://csrc.nist.gov/ns/csf prose: Consider cybersecurity knowledge to be a positive factor in hiring, training, and retention decisions - id: GV.RR-04.047 name: example ns: https://csrc.nist.gov/ns/csf prose: Conduct background checks prior to onboarding new personnel for sensitive roles, and periodically repeat background checks for personnel with such roles - id: GV.RR-04.048 name: example ns: https://csrc.nist.gov/ns/csf prose: Define and enforce obligations for personnel to be aware of, adhere to, and uphold security policies as they relate to their roles - id: GV.SC class: category title: Cybersecurity Supply Chain Risk Management props: - name: sort-id value: "00001.00006" - name: label value: Cybersecurity Supply Chain Risk Management (GV.SC) parts: - id: GV.SC_statement name: statement prose: Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders controls: - id: GV.SC-01 class: subcategory title: GV.SC-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00001 - name: label value: GV.SC-01 parts: - id: GV.SC-01_statement name: statement prose: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders - id: GV.SC-01.066 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish a strategy that expresses the objectives of the cybersecurity supply chain risk management program - id: GV.SC-01.067 name: example ns: https://csrc.nist.gov/ns/csf prose: Develop the cybersecurity supply chain risk management program, including a plan (with milestones), policies, and procedures that guide implementation and improvement of the program, and share the policies and procedures with the organizational stakeholders - id: GV.SC-01.068 name: example ns: https://csrc.nist.gov/ns/csf prose: Develop and implement program processes based on the strategy, objectives, policies, and procedures that are agreed upon and performed by the organizational stakeholders - id: GV.SC-01.069 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish a cross-organizational mechanism that ensures alignment between functions that contribute to cybersecurity supply chain risk management, such as cybersecurity, IT, operations, legal, human resources, and engineering - id: GV.SC-02 class: subcategory title: GV.SC-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00002 - name: label value: GV.SC-02 parts: - id: GV.SC-02_statement name: statement prose: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally - id: GV.SC-02.070 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify one or more specific roles or positions that will be responsible and accountable for planning, resourcing, and executing cybersecurity supply chain risk management activities - id: GV.SC-02.071 name: example ns: https://csrc.nist.gov/ns/csf prose: Document cybersecurity supply chain risk management roles and responsibilities in policy - id: GV.SC-02.072 name: example ns: https://csrc.nist.gov/ns/csf prose: Create responsibility matrixes to document who will be responsible and accountable for cybersecurity supply chain risk management activities and how those teams and individuals will be consulted and informed - id: GV.SC-02.073 name: example ns: https://csrc.nist.gov/ns/csf prose: Include cybersecurity supply chain risk management responsibilities and performance requirements in personnel descriptions to ensure clarity and improve accountability - id: GV.SC-02.074 name: example ns: https://csrc.nist.gov/ns/csf prose: Document performance goals for personnel with cybersecurity risk management-specific responsibilities, and periodically measure them to demonstrate and improve performance - id: GV.SC-02.075 name: example ns: https://csrc.nist.gov/ns/csf prose: Develop roles and responsibilities for suppliers, customers, and business partners to address shared responsibilities for applicable cybersecurity risks, and integrate them into organizational policies and applicable third-party agreements - id: GV.SC-02.076 name: example ns: https://csrc.nist.gov/ns/csf prose: Internally communicate cybersecurity supply chain risk management roles and responsibilities for third parties - id: GV.SC-02.077 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish rules and protocols for information sharing and reporting processes between the organization and its suppliers - id: GV.SC-03 class: subcategory title: GV.SC-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00003 - name: label value: GV.SC-03 parts: - id: GV.SC-03_statement name: statement prose: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes - id: GV.SC-03.078 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify areas of alignment and overlap with cybersecurity and enterprise risk management - id: GV.SC-03.079 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish integrated control sets for cybersecurity risk management and cybersecurity supply chain risk management - id: GV.SC-03.080 name: example ns: https://csrc.nist.gov/ns/csf prose: Integrate cybersecurity supply chain risk management into improvement processes - id: GV.SC-03.081 name: example ns: https://csrc.nist.gov/ns/csf prose: Escalate material cybersecurity risks in supply chains to senior management, and address them at the enterprise risk management level - id: GV.SC-04 class: subcategory title: GV.SC-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00004 - name: label value: GV.SC-04 parts: - id: GV.SC-04_statement name: statement prose: Suppliers are known and prioritized by criticality - id: GV.SC-04.082 name: example ns: https://csrc.nist.gov/ns/csf prose: Develop criteria for supplier criticality based on, for example, the sensitivity of data processed or possessed by suppliers, the degree of access to the organization's systems, and the importance of the products or services to the organization's mission - id: GV.SC-04.083 name: example ns: https://csrc.nist.gov/ns/csf prose: Keep a record of all suppliers, and prioritize suppliers based on the criticality criteria - id: GV.SC-05 class: subcategory title: GV.SC-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00005 - name: label value: GV.SC-05 parts: - id: GV.SC-05_statement name: statement prose: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties - id: GV.SC-05.084 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish security requirements for suppliers, products, and services commensurate with their criticality level and potential impact if compromised - id: GV.SC-05.085 name: example ns: https://csrc.nist.gov/ns/csf prose: Include all cybersecurity and supply chain requirements that third parties must follow and how compliance with the requirements may be verified in default contractual language - id: GV.SC-05.086 name: example ns: https://csrc.nist.gov/ns/csf prose: Define the rules and protocols for information sharing between the organization and its suppliers and sub-tier suppliers in agreements - id: GV.SC-05.087 name: example ns: https://csrc.nist.gov/ns/csf prose: Manage risk by including security requirements in agreements based on their criticality and potential impact if compromised - id: GV.SC-05.088 name: example ns: https://csrc.nist.gov/ns/csf prose: Define security requirements in service-level agreements (SLAs) for monitoring suppliers for acceptable security performance throughout the supplier relationship lifecycle - id: GV.SC-05.089 name: example ns: https://csrc.nist.gov/ns/csf prose: Contractually require suppliers to disclose cybersecurity features, functions, and vulnerabilities of their products and services for the life of the product or the term of service - id: GV.SC-05.090 name: example ns: https://csrc.nist.gov/ns/csf prose: Contractually require suppliers to provide and maintain a current component inventory (e.g., software or hardware bill of materials) for critical products - id: GV.SC-05.091 name: example ns: https://csrc.nist.gov/ns/csf prose: Contractually require suppliers to vet their employees and guard against insider threats - id: GV.SC-05.092 name: example ns: https://csrc.nist.gov/ns/csf prose: Contractually require suppliers to provide evidence of performing acceptable security practices through, for example, self-attestation, conformance to known standards, certifications, or inspections - id: GV.SC-05.093 name: example ns: https://csrc.nist.gov/ns/csf prose: Specify in contracts and other agreements the rights and responsibilities of the organization, its suppliers, and their supply chains, with respect to potential cybersecurity risks - id: GV.SC-06 class: subcategory title: GV.SC-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00006 - name: label value: GV.SC-06 parts: - id: GV.SC-06_statement name: statement prose: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships - id: GV.SC-06.094 name: example ns: https://csrc.nist.gov/ns/csf prose: Perform thorough due diligence on prospective suppliers that is consistent with procurement planning and commensurate with the level of risk, criticality, and complexity of each supplier relationship - id: GV.SC-06.095 name: example ns: https://csrc.nist.gov/ns/csf prose: Assess the suitability of the technology and cybersecurity capabilities and the risk management practices of prospective suppliers - id: GV.SC-06.096 name: example ns: https://csrc.nist.gov/ns/csf prose: Conduct supplier risk assessments against business and applicable cybersecurity requirements - id: GV.SC-06.097 name: example ns: https://csrc.nist.gov/ns/csf prose: Assess the authenticity, integrity, and security of critical products prior to acquisition and use - id: GV.SC-07 class: subcategory title: GV.SC-07 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00007 - name: label value: GV.SC-07 parts: - id: GV.SC-07_statement name: statement prose: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship - id: GV.SC-07.098 name: example ns: https://csrc.nist.gov/ns/csf prose: Adjust assessment formats and frequencies based on the third party's reputation and the criticality of the products or services they provide - id: GV.SC-07.099 name: example ns: https://csrc.nist.gov/ns/csf prose: Evaluate third parties' evidence of compliance with contractual cybersecurity requirements, such as self-attestations, warranties, certifications, and other artifacts - id: GV.SC-07.100 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor critical suppliers to ensure that they are fulfilling their security obligations throughout the supplier relationship lifecycle using a variety of methods and techniques, such as inspections, audits, tests, or other forms of evaluation - id: GV.SC-07.101 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor critical suppliers, services, and products for changes to their risk profiles, and reevaluate supplier criticality and risk impact accordingly - id: GV.SC-07.102 name: example ns: https://csrc.nist.gov/ns/csf prose: Plan for unexpected supplier and supply chain-related interruptions to ensure business continuity - id: GV.SC-08 class: subcategory title: GV.SC-08 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00008 - name: label value: GV.SC-08 parts: - id: GV.SC-08_statement name: statement prose: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities - id: GV.SC-08.103 name: example ns: https://csrc.nist.gov/ns/csf prose: Define and use rules and protocols for reporting incident response and recovery activities and the status between the organization and its suppliers - id: GV.SC-08.104 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify and document the roles and responsibilities of the organization and its suppliers for incident response - id: GV.SC-08.105 name: example ns: https://csrc.nist.gov/ns/csf prose: Include critical suppliers in incident response exercises and simulations - id: GV.SC-08.106 name: example ns: https://csrc.nist.gov/ns/csf prose: Define and coordinate crisis communication methods and protocols between the organization and its critical suppliers - id: GV.SC-08.107 name: example ns: https://csrc.nist.gov/ns/csf prose: Conduct collaborative lessons learned sessions with critical suppliers - id: GV.SC-09 class: subcategory title: GV.SC-09 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00009 - name: label value: GV.SC-09 parts: - id: GV.SC-09_statement name: statement prose: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle - id: GV.SC-09.108 name: example ns: https://csrc.nist.gov/ns/csf prose: Policies and procedures require provenance records for all acquired technology products and services - id: GV.SC-09.109 name: example ns: https://csrc.nist.gov/ns/csf prose: Periodically provide risk reporting to leaders about how acquired components are proven to be untampered and authentic - id: GV.SC-09.110 name: example ns: https://csrc.nist.gov/ns/csf prose: Communicate regularly among cybersecurity risk managers and operations personnel about the need to acquire software patches, updates, and upgrades only from authenticated and trustworthy software providers - id: GV.SC-09.111 name: example ns: https://csrc.nist.gov/ns/csf prose: Review policies to ensure that they require approved supplier personnel to perform maintenance on supplier products - id: GV.SC-09.112 name: example ns: https://csrc.nist.gov/ns/csf prose: Policies and procedure require checking upgrades to critical hardware for unauthorized changes - id: GV.SC-10 class: subcategory title: GV.SC-10 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00001.00006.00010 - name: label value: GV.SC-10 parts: - id: GV.SC-10_statement name: statement prose: Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement - id: GV.SC-10.113 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish processes for terminating critical relationships under both normal and adverse circumstances - id: GV.SC-10.114 name: example ns: https://csrc.nist.gov/ns/csf prose: Define and implement plans for component end-of-life maintenance support and obsolescence - id: GV.SC-10.115 name: example ns: https://csrc.nist.gov/ns/csf prose: Verify that supplier access to organization resources is deactivated promptly when it is no longer needed - id: GV.SC-10.116 name: example ns: https://csrc.nist.gov/ns/csf prose: Verify that assets containing the organization's data are returned or properly disposed of in a timely, controlled, and safe manner - id: GV.SC-10.117 name: example ns: https://csrc.nist.gov/ns/csf prose: Develop and execute a plan for terminating or transitioning supplier relationships that takes supply chain security risk and resiliency into account - id: GV.SC-10.118 name: example ns: https://csrc.nist.gov/ns/csf prose: Mitigate risks to data and systems created by supplier termination - id: GV.SC-10.119 name: example ns: https://csrc.nist.gov/ns/csf prose: Manage data leakage risks associated with supplier termination - id: ID class: function title: IDENTIFY props: - name: sort-id value: "00002" - name: label value: IDENTIFY (ID) parts: - id: ID_overview name: overview prose: The organization's current cybersecurity risks are understood controls: - id: ID.AM class: category title: Asset Management props: - name: sort-id value: "00002.00001" - name: label value: Asset Management (ID.AM) parts: - id: ID.AM_statement name: statement prose: Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization's risk strategy controls: - id: ID.AM-01 class: subcategory title: ID.AM-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00001.00001 - name: label value: ID.AM-01 parts: - id: ID.AM-01_statement name: statement prose: Inventories of hardware managed by the organization are maintained - id: ID.AM-01.120 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain inventories for all types of hardware, including IT, IoT, OT, and mobile devices - id: ID.AM-01.121 name: example ns: https://csrc.nist.gov/ns/csf prose: Constantly monitor networks to detect new hardware and automatically update inventories - id: ID.AM-02 class: subcategory title: ID.AM-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00001.00002 - name: label value: ID.AM-02 parts: - id: ID.AM-02_statement name: statement prose: Inventories of software, services, and systems managed by the organization are maintained - id: ID.AM-02.122 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain inventories for all types of software and services, including commercial-off-the-shelf, open-source, custom applications, API services, and cloud-based applications and services - id: ID.AM-02.123 name: example ns: https://csrc.nist.gov/ns/csf prose: Constantly monitor all platforms, including containers and virtual machines, for software and service inventory changes - id: ID.AM-02.124 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain an inventory of the organization's systems - id: ID.AM-03 class: subcategory title: ID.AM-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00002.00001.00003 - name: label value: ID.AM-03 parts: - id: ID.AM-03_statement name: statement prose: Representations of the organization's authorized network communication and internal and external network data flows are maintained - id: ID.AM-03.125 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain baselines of communication and data flows within the organization's wired and wireless networks - id: ID.AM-03.126 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain baselines of communication and data flows between the organization and third parties - id: ID.AM-03.127 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain baselines of communication and data flows for the organization's infrastructure-as-a-service (IaaS) usage - id: ID.AM-03.128 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain documentation of expected network ports, protocols, and services that are typically used among authorized systems - id: ID.AM-04 class: subcategory title: ID.AM-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00002.00001.00004 - name: label value: ID.AM-04 parts: - id: ID.AM-04_statement name: statement prose: Inventories of services provided by suppliers are maintained - id: ID.AM-04.129 name: example ns: https://csrc.nist.gov/ns/csf prose: Inventory all external services used by the organization, including third-party infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-service (SaaS) offerings; APIs; and other externally hosted application services - id: ID.AM-04.130 name: example ns: https://csrc.nist.gov/ns/csf prose: Update the inventory when a new external service is going to be utilized to ensure adequate cybersecurity risk management monitoring of the organization's use of that service - id: ID.AM-05 class: subcategory title: ID.AM-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00001.00005 - name: label value: ID.AM-05 parts: - id: ID.AM-05_statement name: statement prose: Assets are prioritized based on classification, criticality, resources, and impact on the mission - id: ID.AM-05.131 name: example ns: https://csrc.nist.gov/ns/csf prose: Define criteria for prioritizing each class of assets - id: ID.AM-05.132 name: example ns: https://csrc.nist.gov/ns/csf prose: Apply the prioritization criteria to assets - id: ID.AM-05.133 name: example ns: https://csrc.nist.gov/ns/csf prose: Track the asset priorities and update them periodically or when significant changes to the organization occur - id: ID.AM-06 class: subcategory title: ID.AM-06 props: - name: sort-id value: 00002.00001.00006 - name: label value: ID.AM-06 - name: status value: withdrawn links: - href: GV.RR-02 rel: incorporated_into - href: GV.SC-02 rel: incorporated_into parts: - id: ID.AM-06_statement name: statement prose: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established - id: ID.AM-07 class: subcategory title: ID.AM-07 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00001.00007 - name: label value: ID.AM-07 parts: - id: ID.AM-07_statement name: statement prose: Inventories of data and corresponding metadata for designated data types are maintained - id: ID.AM-07.134 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain a list of the designated data types of interest (e.g., personally identifiable information, protected health information, financial account numbers, organization intellectual property, operational technology data) - id: ID.AM-07.135 name: example ns: https://csrc.nist.gov/ns/csf prose: Continuously discover and analyze ad hoc data to identify new instances of designated data types - id: ID.AM-07.136 name: example ns: https://csrc.nist.gov/ns/csf prose: Assign data classifications to designated data types through tags or labels - id: ID.AM-07.137 name: example ns: https://csrc.nist.gov/ns/csf prose: Track the provenance, data owner, and geolocation of each instance of designated data types - id: ID.AM-08 class: subcategory title: ID.AM-08 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00002.00001.00008 - name: label value: ID.AM-08 parts: - id: ID.AM-08_statement name: statement prose: Systems, hardware, software, services, and data are managed throughout their life cycles - id: ID.AM-08.138 name: example ns: https://csrc.nist.gov/ns/csf prose: Integrate cybersecurity considerations throughout the life cycles of systems, hardware, software, and services - id: ID.AM-08.139 name: example ns: https://csrc.nist.gov/ns/csf prose: Integrate cybersecurity considerations into product life cycles - id: ID.AM-08.140 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify unofficial uses of technology to meet mission objectives (i.e., shadow IT) - id: ID.AM-08.141 name: example ns: https://csrc.nist.gov/ns/csf prose: Periodically identify redundant systems, hardware, software, and services that unnecessarily increase the organization's attack surface - id: ID.AM-08.142 name: example ns: https://csrc.nist.gov/ns/csf prose: Properly configure and secure systems, hardware, software, and services prior to their deployment in production - id: ID.AM-08.143 name: example ns: https://csrc.nist.gov/ns/csf prose: Update inventories when systems, hardware, software, and services are moved or transferred within the organization - id: ID.AM-08.144 name: example ns: https://csrc.nist.gov/ns/csf prose: Securely destroy stored data based on the organization's data retention policy using the prescribed destruction method, and keep and manage a record of the destructions - id: ID.AM-08.145 name: example ns: https://csrc.nist.gov/ns/csf prose: Securely sanitize data storage when hardware is being retired, decommissioned, reassigned, or sent for repairs or replacement - id: ID.AM-08.146 name: example ns: https://csrc.nist.gov/ns/csf prose: Offer methods for destroying paper, storage media, and other physical forms of data storage - id: ID.BE class: category title: Business Environment props: - name: sort-id value: "00002.00002" - name: label value: Business Environment (ID.BE) - name: status value: withdrawn links: - href: GV.OC rel: incorporated_into parts: - id: ID.BE_statement name: statement controls: - id: ID.BE-01 class: subcategory title: ID.BE-01 props: - name: sort-id value: 00002.00002.00001 - name: label value: ID.BE-01 - name: status value: withdrawn links: - href: GV.OC-05 rel: incorporated_into parts: - id: ID.BE-01_statement name: statement prose: The organization’s role in the supply chain is identified and communicated - id: ID.BE-02 class: subcategory title: ID.BE-02 props: - name: sort-id value: 00002.00002.00002 - name: label value: ID.BE-02 - name: status value: withdrawn links: - href: GV.OC-01 rel: incorporated_into parts: - id: ID.BE-02_statement name: statement prose: The organization’s place in critical infrastructure and its industry sector is identified and communicated - id: ID.BE-03 class: subcategory title: ID.BE-03 props: - name: sort-id value: 00002.00002.00003 - name: label value: ID.BE-03 - name: status value: withdrawn links: - href: GV.OC-01 rel: incorporated_into parts: - id: ID.BE-03_statement name: statement prose: Priorities for organizational mission, objectives, and activities are established and communicated - id: ID.BE-04 class: subcategory title: ID.BE-04 props: - name: sort-id value: 00002.00002.00004 - name: label value: ID.BE-04 - name: status value: withdrawn links: - href: GV.OC-04 rel: incorporated_into - href: GV.OC-05 rel: incorporated_into parts: - id: ID.BE-04_statement name: statement prose: Dependencies and critical functions for delivery of critical services are established - id: ID.BE-05 class: subcategory title: ID.BE-05 props: - name: sort-id value: 00002.00002.00005 - name: label value: ID.BE-05 - name: status value: withdrawn links: - href: GV.OC-04 rel: incorporated_into parts: - id: ID.BE-05_statement name: statement prose: Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations) - id: ID.GV class: category title: Governance props: - name: sort-id value: "00002.00003" - name: label value: Governance (ID.GV) - name: status value: withdrawn links: - href: GV rel: incorporated_into parts: - id: ID.GV_statement name: statement controls: - id: ID.GV-01 class: subcategory title: ID.GV-01 props: - name: sort-id value: 00002.00003.00001 - name: label value: ID.GV-01 - name: status value: withdrawn links: - href: GV.PO rel: incorporated_into - href: GV.PO-01 rel: incorporated_into - href: GV.PO-02 rel: incorporated_into parts: - id: ID.GV-01_statement name: statement prose: Organizational cybersecurity policy is established and communicated - id: ID.GV-02 class: subcategory title: ID.GV-02 props: - name: sort-id value: 00002.00003.00002 - name: label value: ID.GV-02 - name: status value: withdrawn links: - href: GV.RR rel: incorporated_into - href: GV.OC-02 rel: incorporated_into - href: GV.RR-02 rel: incorporated_into parts: - id: ID.GV-02_statement name: statement prose: Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners - id: ID.GV-03 class: subcategory title: ID.GV-03 props: - name: sort-id value: 00002.00003.00003 - name: label value: ID.GV-03 - name: status value: withdrawn links: - href: GV.OC-03 rel: moved_to parts: - id: ID.GV-03_statement name: statement prose: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed - id: ID.GV-04 class: subcategory title: ID.GV-04 props: - name: sort-id value: 00002.00003.00004 - name: label value: ID.GV-04 - name: status value: withdrawn links: - href: GV.RM-04 rel: moved_to parts: - id: ID.GV-04_statement name: statement prose: Governance and risk management processes address cybersecurity risks - id: ID.IM class: category title: Improvement props: - name: sort-id value: "00002.00007" - name: label value: Improvement (ID.IM) parts: - id: ID.IM_statement name: statement prose: Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions controls: - id: ID.IM-01 class: subcategory title: ID.IM-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00007.00001 - name: label value: ID.IM-01 parts: - id: ID.IM-01_statement name: statement prose: Improvements are identified from evaluations - id: ID.IM-01.177 name: example ns: https://csrc.nist.gov/ns/csf prose: Perform self-assessments of critical services that take current threats and TTPs into consideration - id: ID.IM-01.178 name: example ns: https://csrc.nist.gov/ns/csf prose: Invest in third-party assessments or independent audits of the effectiveness of the organization's cybersecurity program to identify areas that need improvement - id: ID.IM-01.179 name: example ns: https://csrc.nist.gov/ns/csf prose: Constantly evaluate compliance with selected cybersecurity requirements through automated means - id: ID.IM-02 class: subcategory title: ID.IM-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00002.00007.00002 - name: label value: ID.IM-02 parts: - id: ID.IM-02_statement name: statement prose: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties - id: ID.IM-02.180 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify improvements for future incident response activities based on findings from incident response assessments (e.g., tabletop exercises and simulations, tests, internal reviews, independent audits) - id: ID.IM-02.181 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify improvements for future business continuity, disaster recovery, and incident response activities based on exercises performed in coordination with critical service providers and product suppliers - id: ID.IM-02.182 name: example ns: https://csrc.nist.gov/ns/csf prose: Involve internal stakeholders (e.g., senior executives, legal department, HR) in security tests and exercises as appropriate - id: ID.IM-02.183 name: example ns: https://csrc.nist.gov/ns/csf prose: Perform penetration testing to identify opportunities to improve the security posture of selected high-risk systems as approved by leadership - id: ID.IM-02.184 name: example ns: https://csrc.nist.gov/ns/csf prose: Exercise contingency plans for responding to and recovering from the discovery that products or services did not originate with the contracted supplier or partner or were altered before receipt - id: ID.IM-02.185 name: example ns: https://csrc.nist.gov/ns/csf prose: Collect and analyze performance metrics using security tools and services to inform improvements to the cybersecurity program - id: ID.IM-03 class: subcategory title: ID.IM-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00007.00003 - name: label value: ID.IM-03 parts: - id: ID.IM-03_statement name: statement prose: Improvements are identified from execution of operational processes, procedures, and activities - id: ID.IM-03.186 name: example ns: https://csrc.nist.gov/ns/csf prose: Conduct collaborative lessons learned sessions with suppliers - id: ID.IM-03.187 name: example ns: https://csrc.nist.gov/ns/csf prose: Annually review cybersecurity policies, processes, and procedures to take lessons learned into account - id: ID.IM-03.188 name: example ns: https://csrc.nist.gov/ns/csf prose: Use metrics to assess operational cybersecurity performance over time - id: ID.IM-04 class: subcategory title: ID.IM-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00007.00003 - name: label value: ID.IM-04 parts: - id: ID.IM-04_statement name: statement prose: Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved - id: ID.IM-04.189 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish contingency plans (e.g., incident response, business continuity, disaster recovery) for responding to and recovering from adverse events that can interfere with operations, expose confidential information, or otherwise endanger the organization's mission and viability - id: ID.IM-04.190 name: example ns: https://csrc.nist.gov/ns/csf prose: Include contact and communication information, processes for handling common scenarios, and criteria for prioritization, escalation, and elevation in all contingency plans - id: ID.IM-04.191 name: example ns: https://csrc.nist.gov/ns/csf prose: Create a vulnerability management plan to identify and assess all types of vulnerabilities and to prioritize, test, and implement risk responses - id: ID.IM-04.192 name: example ns: https://csrc.nist.gov/ns/csf prose: Communicate cybersecurity plans (including updates) to those responsible for carrying them out and to affected parties - id: ID.IM-04.193 name: example ns: https://csrc.nist.gov/ns/csf prose: Review and update all cybersecurity plans annually or when a need for significant improvements is identified - id: ID.RA class: category title: Risk Assessment props: - name: sort-id value: "00002.00004" - name: label value: Risk Assessment (ID.RA) parts: - id: ID.RA_statement name: statement prose: The cybersecurity risk to the organization, assets, and individuals is understood by the organization controls: - id: ID.RA-01 class: subcategory title: ID.RA-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00004.00001 - name: label value: ID.RA-01 parts: - id: ID.RA-01_statement name: statement prose: Vulnerabilities in assets are identified, validated, and recorded - id: ID.RA-01.147 name: example ns: https://csrc.nist.gov/ns/csf prose: Use vulnerability management technologies to identify unpatched and misconfigured software - id: ID.RA-01.148 name: example ns: https://csrc.nist.gov/ns/csf prose: Assess network and system architectures for design and implementation weaknesses that affect cybersecurity - id: ID.RA-01.149 name: example ns: https://csrc.nist.gov/ns/csf prose: Review, analyze, or test organization-developed software to identify design, coding, and default configuration vulnerabilities - id: ID.RA-01.150 name: example ns: https://csrc.nist.gov/ns/csf prose: Assess facilities that house critical computing assets for physical vulnerabilities and resilience issues - id: ID.RA-01.151 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor sources of cyber threat intelligence for information on new vulnerabilities in products and services - id: ID.RA-01.152 name: example ns: https://csrc.nist.gov/ns/csf prose: Review processes and procedures for weaknesses that could be exploited to affect cybersecurity - id: ID.RA-02 class: subcategory title: ID.RA-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00004.00002 - name: label value: ID.RA-02 parts: - id: ID.RA-02_statement name: statement prose: Cyber threat intelligence is received from information sharing forums and sources - id: ID.RA-02.153 name: example ns: https://csrc.nist.gov/ns/csf prose: Configure cybersecurity tools and technologies with detection or response capabilities to securely ingest cyber threat intelligence feeds - id: ID.RA-02.154 name: example ns: https://csrc.nist.gov/ns/csf prose: Receive and review advisories from reputable third parties on current threat actors and their tactics, techniques, and procedures (TTPs) - id: ID.RA-02.155 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor sources of cyber threat intelligence for information on the types of vulnerabilities that emerging technologies may have - id: ID.RA-03 class: subcategory title: ID.RA-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00002.00004.00003 - name: label value: ID.RA-03 parts: - id: ID.RA-03_statement name: statement prose: Internal and external threats to the organization are identified and recorded - id: ID.RA-03.156 name: example ns: https://csrc.nist.gov/ns/csf prose: Use cyber threat intelligence to maintain awareness of the types of threat actors likely to target the organization and the TTPs they are likely to use - id: ID.RA-03.157 name: example ns: https://csrc.nist.gov/ns/csf prose: Perform threat hunting to look for signs of threat actors within the environment - id: ID.RA-03.158 name: example ns: https://csrc.nist.gov/ns/csf prose: Implement processes for identifying internal threat actors - id: ID.RA-04 class: subcategory title: ID.RA-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00004.00004 - name: label value: ID.RA-04 parts: - id: ID.RA-04_statement name: statement prose: Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded - id: ID.RA-04.159 name: example ns: https://csrc.nist.gov/ns/csf prose: Business leaders and cybersecurity risk management practitioners work together to estimate the likelihood and impact of risk scenarios and record them in risk registers - id: ID.RA-04.160 name: example ns: https://csrc.nist.gov/ns/csf prose: Enumerate the potential business impacts of unauthorized access to the organization's communications, systems, and data processed in or by those systems - id: ID.RA-04.161 name: example ns: https://csrc.nist.gov/ns/csf prose: Account for the potential impacts of cascading failures for systems of systems - id: ID.RA-05 class: subcategory title: ID.RA-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00004.00005 - name: label value: ID.RA-05 parts: - id: ID.RA-05_statement name: statement prose: Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization - id: ID.RA-05.162 name: example ns: https://csrc.nist.gov/ns/csf prose: Develop threat models to better understand risks to the data and identify appropriate risk responses - id: ID.RA-05.163 name: example ns: https://csrc.nist.gov/ns/csf prose: Prioritize cybersecurity resource allocations and investments based on estimated likelihoods and impacts - id: ID.RA-06 class: subcategory title: ID.RA-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00002.00004.00006 - name: label value: ID.RA-06 parts: - id: ID.RA-06_statement name: statement prose: Risk responses are chosen, prioritized, planned, tracked, and communicated - id: ID.RA-06.164 name: example ns: https://csrc.nist.gov/ns/csf prose: Apply the vulnerability management plan's criteria for deciding whether to accept, transfer, mitigate, or avoid risk - id: ID.RA-06.165 name: example ns: https://csrc.nist.gov/ns/csf prose: Apply the vulnerability management plan's criteria for selecting compensating controls to mitigate risk - id: ID.RA-06.166 name: example ns: https://csrc.nist.gov/ns/csf prose: Track the progress of risk response implementation (e.g., plan of action and milestones (POA&M), risk register, risk detail report) - id: ID.RA-06.167 name: example ns: https://csrc.nist.gov/ns/csf prose: Use risk assessment findings to inform risk response decisions and actions - id: ID.RA-06.168 name: example ns: https://csrc.nist.gov/ns/csf prose: Communicate planned risk responses to affected stakeholders in priority order - id: ID.RA-07 class: subcategory title: ID.RA-07 props: - name: sort-id value: 00002.00004.00007 - name: label value: ID.RA-07 parts: - id: ID.RA-07_statement name: statement prose: Changes and exceptions are managed, assessed for risk impact, recorded, and tracked - id: ID.RA-07.169 name: example ns: https://csrc.nist.gov/ns/csf prose: Implement and follow procedures for the formal documentation, review, testing, and approval of proposed changes and requested exceptions - id: ID.RA-07.170 name: example ns: https://csrc.nist.gov/ns/csf prose: Document the possible risks of making or not making each proposed change, and provide guidance on rolling back changes - id: ID.RA-07.171 name: example ns: https://csrc.nist.gov/ns/csf prose: Document the risks related to each requested exception and the plan for responding to those risks - id: ID.RA-07.172 name: example ns: https://csrc.nist.gov/ns/csf prose: Periodically review risks that were accepted based upon planned future actions or milestones - id: ID.RA-08 class: subcategory title: ID.RA-08 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00002.00004.00008 - name: label value: ID.RA-08 parts: - id: ID.RA-08_statement name: statement prose: Processes for receiving, analyzing, and responding to vulnerability disclosures are established - id: ID.RA-08.173 name: example ns: https://csrc.nist.gov/ns/csf prose: Conduct vulnerability information sharing between the organization and its suppliers following the rules and protocols defined in contracts - id: ID.RA-08.174 name: example ns: https://csrc.nist.gov/ns/csf prose: Assign responsibilities and verify the execution of procedures for processing, analyzing the impact of, and responding to cybersecurity threat, vulnerability, or incident disclosures by suppliers, customers, partners, and government cybersecurity organizations - id: ID.RA-09 class: subcategory title: ID.RA-09 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00002.00004.00009 - name: label value: ID.RA-09 parts: - id: ID.RA-09_statement name: statement prose: The authenticity and integrity of hardware and software are assessed prior to acquisition and use - id: ID.RA-09.175 name: example ns: https://csrc.nist.gov/ns/csf prose: Assess the authenticity and cybersecurity of critical technology products and services prior to acquisition and use - id: ID.RA-10 class: subcategory title: ID.RA-10 props: - name: sort-id value: 00002.00004.00010 - name: label value: ID.RA-10 parts: - id: ID.RA-10_statement name: statement prose: Critical suppliers are assessed prior to acquisition - id: ID.RA-10.176 name: example ns: https://csrc.nist.gov/ns/csf prose: Conduct supplier risk assessments against business and applicable cybersecurity requirements, including the supply chain - id: ID.RM class: category title: Risk Management Strategy props: - name: sort-id value: "00002.00005" - name: label value: Risk Management Strategy (ID.RM) - name: status value: withdrawn links: - href: GV.RM rel: incorporated_into parts: - id: ID.RM_statement name: statement controls: - id: ID.RM-01 class: subcategory title: ID.RM-01 props: - name: sort-id value: 00002.00005.00001 - name: label value: ID.RM-01 - name: status value: withdrawn links: - href: GV.RM-01 rel: incorporated_into - href: GV.RM-06 rel: incorporated_into - href: GV.RR-03 rel: incorporated_into parts: - id: ID.RM-01_statement name: statement prose: Risk management processes are established, managed, and agreed to by organizational stakeholders - id: ID.RM-02 class: subcategory title: ID.RM-02 props: - name: sort-id value: 00002.00005.00002 - name: label value: ID.RM-02 - name: status value: withdrawn links: - href: GV.RM-02 rel: incorporated_into - href: GV.RM-04 rel: incorporated_into parts: - id: ID.RM-02_statement name: statement prose: Organizational risk tolerance is determined and clearly expressed - id: ID.RM-03 class: subcategory title: ID.RM-03 props: - name: sort-id value: 00002.00005.00003 - name: label value: ID.RM-03 - name: status value: withdrawn links: - href: GV.RM-02 rel: moved_to parts: - id: ID.RM-03_statement name: statement prose: The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis - id: ID.SC class: category title: Supply Chain Risk Management props: - name: sort-id value: "00002.00006" - name: label value: Supply Chain Risk Management (ID.SC) - name: status value: withdrawn links: - href: GV.SC rel: incorporated_into parts: - id: ID.SC_statement name: statement controls: - id: ID.SC-01 class: subcategory title: ID.SC-01 props: - name: sort-id value: 00002.00006.00001 - name: label value: ID.SC-01 - name: status value: withdrawn links: - href: GV.RM-05 rel: incorporated_into - href: GV.SC-01 rel: incorporated_into - href: GV.SC-06 rel: incorporated_into - href: GV.SC-09 rel: incorporated_into - href: GV.SC-10 rel: incorporated_into parts: - id: ID.SC-01_statement name: statement prose: Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders - id: ID.SC-02 class: subcategory title: ID.SC-02 props: - name: sort-id value: 00002.00006.00002 - name: label value: ID.SC-02 - name: status value: withdrawn links: - href: GV.OC-02 rel: incorporated_into - href: GV.SC-03 rel: incorporated_into - href: GV.SC-04 rel: incorporated_into - href: GV.SC-07 rel: incorporated_into - href: ID.RA-10 rel: incorporated_into parts: - id: ID.SC-02_statement name: statement prose: Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process - id: ID.SC-03 class: subcategory title: ID.SC-03 props: - name: sort-id value: 00002.00006.00003 - name: label value: ID.SC-03 - name: status value: withdrawn links: - href: GV.SC-05 rel: moved_to parts: - id: ID.SC-03_statement name: statement prose: Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybersecurity program and Cyber Supply Chain Risk Management Plan. - id: ID.SC-04 class: subcategory title: ID.SC-04 props: - name: sort-id value: 00002.00006.00004 - name: label value: ID.SC-04 - name: status value: withdrawn links: - href: GV.SC-07 rel: incorporated_into - href: ID.RA-10 rel: incorporated_into parts: - id: ID.SC-04_statement name: statement prose: Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual obligations. - id: ID.SC-05 class: subcategory title: ID.SC-05 props: - name: sort-id value: 00002.00006.00005 - name: label value: ID.SC-05 - name: status value: withdrawn links: - href: GV.SC-08 rel: incorporated_into - href: ID.IM-02 rel: incorporated_into parts: - id: ID.SC-05_statement name: statement prose: Response and recovery planning and testing are conducted with suppliers and third-party providers - id: PR class: function title: PROTECT props: - name: sort-id value: "00003" - name: label value: PROTECT (PR) parts: - id: PR_overview name: overview prose: Safeguards to manage the organization's cybersecurity risks are used controls: - id: PR.AA class: category title: Identity Management, Authentication, and Access Control props: - name: sort-id value: "00003.00001" - name: label value: Identity Management, Authentication, and Access Control (PR.AA) parts: - id: PR.AA_statement name: statement prose: Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access controls: - id: PR.AA-01 class: subcategory title: PR.AA-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00001.00001 - name: label value: PR.AA-01 parts: - id: PR.AA-01_statement name: statement prose: Identities and credentials for authorized users, services, and hardware are managed by the organization - id: PR.AA-01.194 name: example ns: https://csrc.nist.gov/ns/csf prose: Initiate requests for new access or additional access for employees, contractors, and others, and track, review, and fulfill the requests, with permission from system or data owners when needed - id: PR.AA-01.195 name: example ns: https://csrc.nist.gov/ns/csf prose: Issue, manage, and revoke cryptographic certificates and identity tokens, cryptographic keys (i.e., key management), and other credentials - id: PR.AA-01.196 name: example ns: https://csrc.nist.gov/ns/csf prose: Select a unique identifier for each device from immutable hardware characteristics or an identifier securely provisioned to the device - id: PR.AA-01.197 name: example ns: https://csrc.nist.gov/ns/csf prose: Physically label authorized hardware with an identifier for inventory and servicing purposes - id: PR.AA-02 class: subcategory title: PR.AA-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00003.00001.00002 - name: label value: PR.AA-02 parts: - id: PR.AA-02_statement name: statement prose: Identities are proofed and bound to credentials based on the context of interactions - id: PR.AA-02.198 name: example ns: https://csrc.nist.gov/ns/csf prose: Verify a person's claimed identity at enrollment time using government-issued identity credentials (e.g., passport, visa, driver's license) - id: PR.AA-02.199 name: example ns: https://csrc.nist.gov/ns/csf prose: Issue a different credential for each person (i.e., no credential sharing) - id: PR.AA-03 class: subcategory title: PR.AA-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00001.00003 - name: label value: PR.AA-03 parts: - id: PR.AA-03_statement name: statement prose: Users, services, and hardware are authenticated - id: PR.AA-03.200 name: example ns: https://csrc.nist.gov/ns/csf prose: Require multifactor authentication - id: PR.AA-03.201 name: example ns: https://csrc.nist.gov/ns/csf prose: Enforce policies for the minimum strength of passwords, PINs, and similar authenticators - id: PR.AA-03.202 name: example ns: https://csrc.nist.gov/ns/csf prose: Periodically reauthenticate users, services, and hardware based on risk (e.g., in zero trust architectures) - id: PR.AA-03.203 name: example ns: https://csrc.nist.gov/ns/csf prose: Ensure that authorized personnel can access accounts essential for protecting safety under emergency conditions - id: PR.AA-04 class: subcategory title: PR.AA-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00001.00004 - name: label value: PR.AA-04 parts: - id: PR.AA-04_statement name: statement prose: Identity assertions are protected, conveyed, and verified - id: PR.AA-04.204 name: example ns: https://csrc.nist.gov/ns/csf prose: Protect identity assertions that are used to convey authentication and user information through single sign-on systems - id: PR.AA-04.205 name: example ns: https://csrc.nist.gov/ns/csf prose: Protect identity assertions that are used to convey authentication and user information between federated systems - id: PR.AA-04.206 name: example ns: https://csrc.nist.gov/ns/csf prose: Implement standards-based approaches for identity assertions in all contexts, and follow all guidance for the generation (e.g., data models, metadata), protection (e.g., digital signing, encryption), and verification (e.g., signature validation) of identity assertions - id: PR.AA-05 class: subcategory title: PR.AA-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00001.00005 - name: label value: PR.AA-05 parts: - id: PR.AA-05_statement name: statement prose: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties - id: PR.AA-05.207 name: example ns: https://csrc.nist.gov/ns/csf prose: Review logical and physical access privileges periodically and whenever someone changes roles or leaves the organization, and promptly rescind privileges that are no longer needed - id: PR.AA-05.208 name: example ns: https://csrc.nist.gov/ns/csf prose: Take attributes of the requester and the requested resource into account for authorization decisions (e.g., geolocation, day/time, requester endpoint's cyber health) - id: PR.AA-05.209 name: example ns: https://csrc.nist.gov/ns/csf prose: Restrict access and privileges to the minimum necessary (e.g., zero trust architecture) - id: PR.AA-05.210 name: example ns: https://csrc.nist.gov/ns/csf prose: Periodically review the privileges associated with critical business functions to confirm proper separation of duties - id: PR.AA-06 class: subcategory title: PR.AA-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00003.00001.00006 - name: label value: PR.AA-06 parts: - id: PR.AA-06_statement name: statement prose: Physical access to assets is managed, monitored, and enforced commensurate with risk - id: PR.AA-06.211 name: example ns: https://csrc.nist.gov/ns/csf prose: Use security guards, security cameras, locked entrances, alarm systems, and other physical controls to monitor facilities and restrict access - id: PR.AA-06.212 name: example ns: https://csrc.nist.gov/ns/csf prose: Employ additional physical security controls for areas that contain high-risk assets - id: PR.AA-06.213 name: example ns: https://csrc.nist.gov/ns/csf prose: Escort guests, vendors, and other third parties within areas that contain business-critical assets - id: PR.AC class: category title: Identity Management, Authentication and Access Control props: - name: sort-id value: "00003.00002" - name: label value: Identity Management, Authentication and Access Control (PR.AC) - name: status value: withdrawn links: - href: PR.AA rel: moved_to parts: - id: PR.AC_statement name: statement controls: - id: PR.AC-01 class: subcategory title: PR.AC-01 props: - name: sort-id value: 00003.00002.00001 - name: label value: PR.AC-01 - name: status value: withdrawn links: - href: PR.AA-01 rel: incorporated_into - href: PR.AA-05 rel: incorporated_into parts: - id: PR.AC-01_statement name: statement prose: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes - id: PR.AC-02 class: subcategory title: PR.AC-02 props: - name: sort-id value: 00003.00002.00002 - name: label value: PR.AC-02 - name: status value: withdrawn links: - href: PR.AA-06 rel: moved_to parts: - id: PR.AC-02_statement name: statement prose: Physical access to assets is managed and protected - id: PR.AC-03 class: subcategory title: PR.AC-03 props: - name: sort-id value: 00003.00002.00003 - name: label value: PR.AC-03 - name: status value: withdrawn links: - href: PR.AA-03 rel: incorporated_into - href: PR.AA-05 rel: incorporated_into - href: PR.IR-01 rel: incorporated_into parts: - id: PR.AC-03_statement name: statement prose: Remote access is managed - id: PR.AC-04 class: subcategory title: PR.AC-04 props: - name: sort-id value: 00003.00002.00004 - name: label value: PR.AC-04 - name: status value: withdrawn links: - href: PR.AA-05 rel: moved_to parts: - id: PR.AC-04_statement name: statement prose: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties - id: PR.AC-05 class: subcategory title: PR.AC-05 props: - name: sort-id value: 00003.00002.00005 - name: label value: PR.AC-05 - name: status value: withdrawn links: - href: PR.IR-01 rel: incorporated_into parts: - id: PR.AC-05_statement name: statement prose: Network integrity is protected (e.g., network segregation, network segmentation) - id: PR.AC-06 class: subcategory title: PR.AC-06 props: - name: sort-id value: 00003.00002.00006 - name: label value: PR.AC-06 - name: status value: withdrawn links: - href: PR.AA-02 rel: moved_to parts: - id: PR.AC-06_statement name: statement prose: Identities are proofed and bound to credentials and asserted in interactions - id: PR.AC-07 class: subcategory title: PR.AC-07 props: - name: sort-id value: 00003.00002.00006 - name: label value: PR.AC-07 - name: status value: withdrawn links: - href: PR.AA-03 rel: moved_to parts: - id: PR.AC-07_statement name: statement prose: Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individuals’ security and privacy risks and other organizational risks) - id: PR.AT class: category title: Awareness and Training props: - name: sort-id value: "00003.00003" - name: label value: Awareness and Training (PR.AT) parts: - id: PR.AT_statement name: statement prose: The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks controls: - id: PR.AT-01 class: subcategory title: PR.AT-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00003.00001 - name: label value: PR.AT-01 parts: - id: PR.AT-01_statement name: statement prose: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind - id: PR.AT-01.214 name: example ns: https://csrc.nist.gov/ns/csf prose: Provide basic cybersecurity awareness and training to employees, contractors, partners, suppliers, and all other users of the organization's non-public resources - id: PR.AT-01.215 name: example ns: https://csrc.nist.gov/ns/csf prose: Train personnel to recognize social engineering attempts and other common attacks, report attacks and suspicious activity, comply with acceptable use policies, and perform basic cyber hygiene tasks (e.g., patching software, choosing passwords, protecting credentials) - id: PR.AT-01.216 name: example ns: https://csrc.nist.gov/ns/csf prose: Explain the consequences of cybersecurity policy violations, both to individual users and the organization as a whole - id: PR.AT-01.217 name: example ns: https://csrc.nist.gov/ns/csf prose: Periodically assess or test users on their understanding of basic cybersecurity practices - id: PR.AT-01.218 name: example ns: https://csrc.nist.gov/ns/csf prose: Require annual refreshers to reinforce existing practices and introduce new practices - id: PR.AT-02 class: subcategory title: PR.AT-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00003.00003.00002 - name: label value: PR.AT-02 parts: - id: PR.AT-02_statement name: statement prose: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind - id: PR.AT-02.219 name: example ns: https://csrc.nist.gov/ns/csf prose: Identify the specialized roles within the organization that require additional cybersecurity training, such as physical and cybersecurity personnel, finance personnel, senior leadership, and anyone with access to business-critical data - id: PR.AT-02.220 name: example ns: https://csrc.nist.gov/ns/csf prose: Provide role-based cybersecurity awareness and training to all those in specialized roles, including contractors, partners, suppliers, and other third parties - id: PR.AT-02.221 name: example ns: https://csrc.nist.gov/ns/csf prose: Periodically assess or test users on their understanding of cybersecurity practices for their specialized roles - id: PR.AT-02.222 name: example ns: https://csrc.nist.gov/ns/csf prose: Require annual refreshers to reinforce existing practices and introduce new practices - id: PR.AT-03 class: subcategory title: PR.AT-03 props: - name: sort-id value: 00003.00003.00003 - name: label value: PR.AT-03 - name: status value: withdrawn links: - href: PR.AT-01 rel: incorporated_into - href: PR.AT-02 rel: incorporated_into parts: - id: PR.AT-03_statement name: statement prose: Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities - id: PR.AT-04 class: subcategory title: PR.AT-04 props: - name: sort-id value: 00003.00003.00004 - name: label value: PR.AT-04 - name: status value: withdrawn links: - href: PR.AT-02 rel: incorporated_into parts: - id: PR.AT-04_statement name: statement prose: Senior executives understand their roles and responsibilities - id: PR.AT-05 class: subcategory title: PR.AT-05 props: - name: sort-id value: 00003.00003.00005 - name: label value: PR.AT-05 - name: status value: withdrawn links: - href: PR.AT-02 rel: incorporated_into parts: - id: PR.AT-05_statement name: statement prose: Physical and cybersecurity personnel understand their roles and responsibilities - id: PR.DS class: category title: Data Security props: - name: sort-id value: "00003.00004" - name: label value: Data Security (PR.DS) parts: - id: PR.DS_statement name: statement prose: Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information controls: - id: PR.DS-01 class: subcategory title: PR.DS-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00004.00001 - name: label value: PR.DS-01 parts: - id: PR.DS-01_statement name: statement prose: The confidentiality, integrity, and availability of data-at-rest are protected - id: PR.DS-01.223 name: example ns: https://csrc.nist.gov/ns/csf prose: Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of stored data in files, databases, virtual machine disk images, container images, and other resources - id: PR.DS-01.224 name: example ns: https://csrc.nist.gov/ns/csf prose: Use full disk encryption to protect data stored on user endpoints - id: PR.DS-01.225 name: example ns: https://csrc.nist.gov/ns/csf prose: Confirm the integrity of software by validating signatures - id: PR.DS-01.226 name: example ns: https://csrc.nist.gov/ns/csf prose: Restrict the use of removable media to prevent data exfiltration - id: PR.DS-01.227 name: example ns: https://csrc.nist.gov/ns/csf prose: Physically secure removable media containing unencrypted sensitive information, such as within locked offices or file cabinets - id: PR.DS-02 class: subcategory title: PR.DS-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00004.00002 - name: label value: PR.DS-02 parts: - id: PR.DS-02_statement name: statement prose: The confidentiality, integrity, and availability of data-in-transit are protected - id: PR.DS-02.228 name: example ns: https://csrc.nist.gov/ns/csf prose: Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of network communications - id: PR.DS-02.229 name: example ns: https://csrc.nist.gov/ns/csf prose: Automatically encrypt or block outbound emails and other communications that contain sensitive data, depending on the data classification - id: PR.DS-02.230 name: example ns: https://csrc.nist.gov/ns/csf prose: Block access to personal email, file sharing, file storage services, and other personal communications applications and services from organizational systems and networks - id: PR.DS-02.231 name: example ns: https://csrc.nist.gov/ns/csf prose: Prevent reuse of sensitive data from production environments (e.g., customer records) in development, testing, and other non-production environments - id: PR.DS-03 class: subcategory title: PR.DS-03 props: - name: sort-id value: 00003.00004.00003 - name: label value: PR.DS-03 - name: status value: withdrawn links: - href: ID.AM-08 rel: incorporated_into - href: PR.PS-03 rel: incorporated_into parts: - id: PR.DS-03_statement name: statement prose: Assets are formally managed throughout removal, transfers, and disposition - id: PR.DS-04 class: subcategory title: PR.DS-04 props: - name: sort-id value: 00003.00004.00004 - name: label value: PR.DS-04 - name: status value: withdrawn links: - href: PR.IR-04 rel: moved_to parts: - id: PR.DS-04_statement name: statement prose: Adequate capacity to ensure availability is maintained - id: PR.DS-05 class: subcategory title: PR.DS-05 props: - name: sort-id value: 00003.00004.00005 - name: label value: PR.DS-05 - name: status value: withdrawn links: - href: PR.DS-01 rel: incorporated_into - href: PR.DS-02 rel: incorporated_into - href: PR.DS-10 rel: incorporated_into parts: - id: PR.DS-05_statement name: statement prose: Protections against data leaks are implemented - id: PR.DS-06 class: subcategory title: PR.DS-06 props: - name: sort-id value: 00003.00004.00006 - name: label value: PR.DS-06 - name: status value: withdrawn links: - href: PR.DS-01 rel: incorporated_into - href: DE.CM-09 rel: incorporated_into parts: - id: PR.DS-06_statement name: statement prose: Integrity checking mechanisms are used to verify software, firmware, and information integrity - id: PR.DS-07 class: subcategory title: PR.DS-07 props: - name: sort-id value: 00003.00004.00007 - name: label value: PR.DS-07 - name: status value: withdrawn links: - href: PR.IR-01 rel: incorporated_into parts: - id: PR.DS-07_statement name: statement prose: The development and testing environment(s) are separate from the production environment - id: PR.DS-08 class: subcategory title: PR.DS-08 props: - name: sort-id value: 00003.00004.00008 - name: label value: PR.DS-08 - name: status value: withdrawn links: - href: ID.RA-09 rel: incorporated_into - href: DE.CM-09 rel: incorporated_into parts: - id: PR.DS-08_statement name: statement prose: Integrity checking mechanisms are used to verify hardware integrity - id: PR.DS-10 class: subcategory title: PR.DS-10 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00004.00010 - name: label value: PR.DS-10 parts: - id: PR.DS-10_statement name: statement prose: The confidentiality, integrity, and availability of data-in-use are protected - id: PR.DS-10.232 name: example ns: https://csrc.nist.gov/ns/csf prose: Remove data that must remain confidential (e.g., from processors and memory) as soon as it is no longer needed - id: PR.DS-10.233 name: example ns: https://csrc.nist.gov/ns/csf prose: Protect data in use from access by other users and processes of the same platform - id: PR.DS-11 class: subcategory title: PR.DS-11 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00004.00011 - name: label value: PR.DS-11 parts: - id: PR.DS-11_statement name: statement prose: Backups of data are created, protected, maintained, and tested - id: PR.DS-11.234 name: example ns: https://csrc.nist.gov/ns/csf prose: Continuously back up critical data in near-real-time, and back up other data frequently at agreed-upon schedules - id: PR.DS-11.235 name: example ns: https://csrc.nist.gov/ns/csf prose: Test backups and restores for all types of data sources at least annually - id: PR.DS-11.236 name: example ns: https://csrc.nist.gov/ns/csf prose: Securely store some backups offline and offsite so that an incident or disaster will not damage them - id: PR.DS-11.237 name: example ns: https://csrc.nist.gov/ns/csf prose: Enforce geographic separation and geolocation restrictions for data backup storage - id: PR.IP class: category title: Information Protection Processes and Procedures props: - name: sort-id value: "00003.00005" - name: label value: Information Protection Processes and Procedures (PR.IP) - name: status value: withdrawn parts: - id: PR.IP_statement name: statement controls: - id: PR.IP-01 class: subcategory title: PR.IP-01 props: - name: sort-id value: 00003.00005.00001 - name: label value: PR.IP-01 - name: status value: withdrawn links: - href: PR.PS-01 rel: incorporated_into parts: - id: PR.IP-01_statement name: statement prose: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality) - id: PR.IP-02 class: subcategory title: PR.IP-02 props: - name: sort-id value: 00003.00005.00002 - name: label value: PR.IP-02 - name: status value: withdrawn links: - href: ID.AM-08 rel: incorporated_into - href: PR.PS-06 rel: incorporated_into parts: - id: PR.IP-02_statement name: statement prose: A System Development Life Cycle to manage systems is implemented - id: PR.IP-03 class: subcategory title: PR.IP-03 props: - name: sort-id value: 00003.00005.00003 - name: label value: PR.IP-03 - name: status value: withdrawn links: - href: ID.RA-07 rel: incorporated_into - href: PR.PS-01 rel: incorporated_into parts: - id: PR.IP-03_statement name: statement prose: Configuration change control processes are in place - id: PR.IP-04 class: subcategory title: PR.IP-04 props: - name: sort-id value: 00003.00005.00004 - name: label value: PR.IP-04 - name: status value: withdrawn links: - href: PR.DS-11 rel: moved_to parts: - id: PR.IP-04_statement name: statement prose: Backups of information are conducted, maintained, and tested - id: PR.IP-05 class: subcategory title: PR.IP-05 props: - name: sort-id value: 00003.00005.00005 - name: label value: PR.IP-05 - name: status value: withdrawn links: - href: PR.IR-02 rel: incorporated_into parts: - id: PR.IP-05_statement name: statement prose: Policy and regulations regarding the physical operating environment for organizational assets are met - id: PR.IP-06 class: subcategory title: PR.IP-06 props: - name: sort-id value: 00003.00005.00006 - name: label value: PR.IP-06 - name: status value: withdrawn links: - href: ID.AM-08 rel: incorporated_into parts: - id: PR.IP-06_statement name: statement prose: Data is destroyed according to policy - id: PR.IP-07 class: subcategory title: PR.IP-07 props: - name: sort-id value: 00003.00005.00007 - name: label value: PR.IP-07 - name: status value: withdrawn links: - href: ID.IM rel: incorporated_into - href: ID.IM-03 rel: incorporated_into parts: - id: PR.IP-07_statement name: statement prose: Protection processes are improved - id: PR.IP-08 class: subcategory title: PR.IP-08 props: - name: sort-id value: 00003.00005.00008 - name: label value: PR.IP-08 - name: status value: withdrawn links: - href: ID.IM-03 rel: moved_to parts: - id: PR.IP-08_statement name: statement prose: Effectiveness of protection technologies is shared - id: PR.IP-09 class: subcategory title: PR.IP-09 props: - name: sort-id value: 00003.00005.00009 - name: label value: PR.IP-09 - name: status value: withdrawn links: - href: ID.IM-04 rel: moved_to parts: - id: PR.IP-09_statement name: statement prose: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed - id: PR.IP-10 class: subcategory title: PR.IP-10 props: - name: sort-id value: 00003.00005.00010 - name: label value: PR.IP-10 - name: status value: withdrawn links: - href: ID.IM-02 rel: moved_to - href: ID.IM-04 rel: moved_to parts: - id: PR.IP-10_statement name: statement prose: Response and recovery plans are tested - id: PR.IP-11 class: subcategory title: PR.IP-11 props: - name: sort-id value: 00003.00005.00011 - name: label value: PR.IP-11 - name: status value: withdrawn links: - href: GV.RR-04 rel: moved_to parts: - id: PR.IP-11_statement name: statement prose: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening) - id: PR.IP-12 class: subcategory title: PR.IP-12 props: - name: sort-id value: 00003.00005.00012 - name: label value: PR.IP-12 - name: status value: withdrawn links: - href: ID.RA-01 rel: moved_to - href: PR.PS-02 rel: moved_to parts: - id: PR.IP-12_statement name: statement prose: A vulnerability management plan is developed and implemented - id: PR.IR class: category title: Technology Infrastructure Resilience props: - name: sort-id value: "00003.00009" - name: label value: Technology Infrastructure Resilience (PR.IR) parts: - id: PR.IR_statement name: statement prose: Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience controls: - id: PR.IR-01 class: subcategory title: PR.IR-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00003.00009.00001 - name: label value: PR.IR-01 parts: - id: PR.IR-01_statement name: statement prose: Networks and environments are protected from unauthorized logical access and usage - id: PR.IR-01.260 name: example ns: https://csrc.nist.gov/ns/csf prose: Logically segment organization networks and cloud-based platforms according to trust boundaries and platform types (e.g., IT, IoT, OT, mobile, guests), and permit required communications only between segments - id: PR.IR-01.261 name: example ns: https://csrc.nist.gov/ns/csf prose: Logically segment organization networks from external networks, and permit only necessary communications to enter the organization's networks from the external networks - id: PR.IR-01.262 name: example ns: https://csrc.nist.gov/ns/csf prose: Implement zero trust architectures to restrict network access to each resource to the minimum necessary - id: PR.IR-01.263 name: example ns: https://csrc.nist.gov/ns/csf prose: Check the cyber health of endpoints before allowing them to access and use production resources - id: PR.IR-02 class: subcategory title: PR.IR-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00003.00009.00002 - name: label value: PR.IR-02 parts: - id: PR.IR-02_statement name: statement prose: The organization's technology assets are protected from environmental threats - id: PR.IR-02.264 name: example ns: https://csrc.nist.gov/ns/csf prose: Protect organizational equipment from known environmental threats, such as flooding, fire, wind, and excessive heat and humidity - id: PR.IR-02.265 name: example ns: https://csrc.nist.gov/ns/csf prose: Include protection from environmental threats and provisions for adequate operating infrastructure in requirements for service providers that operate systems on the organization's behalf - id: PR.IR-03 class: subcategory title: PR.IR-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00009.00003 - name: label value: PR.IR-03 parts: - id: PR.IR-03_statement name: statement prose: Mechanisms are implemented to achieve resilience requirements in normal and adverse situations - id: PR.IR-03.266 name: example ns: https://csrc.nist.gov/ns/csf prose: Avoid single points of failure in systems and infrastructure - id: PR.IR-03.267 name: example ns: https://csrc.nist.gov/ns/csf prose: Use load balancing to increase capacity and improve reliability - id: PR.IR-03.268 name: example ns: https://csrc.nist.gov/ns/csf prose: Use high-availability components like redundant storage and power supplies to improve system reliability - id: PR.IR-04 class: subcategory title: PR.IR-04 props: - name: sort-id value: 00003.00009.00004 - name: label value: PR.IR-04 parts: - id: PR.IR-04_statement name: statement prose: Adequate resource capacity to ensure availability is maintained - id: PR.IR-04.269 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor usage of storage, power, compute, network bandwidth, and other resources - id: PR.IR-04.270 name: example ns: https://csrc.nist.gov/ns/csf prose: Forecast future needs, and scale resources accordingly - id: PR.MA class: category title: Maintenance props: - name: sort-id value: "00003.00006" - name: label value: Maintenance (PR.MA) - name: status value: withdrawn links: - href: ID.AM-08 rel: incorporated_into parts: - id: PR.MA_statement name: statement controls: - id: PR.MA-01 class: subcategory title: PR.MA-01 props: - name: sort-id value: 00003.00006.00001 - name: label value: PR.MA-01 - name: status value: withdrawn links: - href: ID.AM-08 rel: moved_to - href: PR.PS-03 rel: moved_to parts: - id: PR.MA-01_statement name: statement prose: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools - id: PR.MA-02 class: subcategory title: PR.MA-02 props: - name: sort-id value: 00003.00006.00002 - name: label value: PR.MA-02 - name: status value: withdrawn links: - href: ID.AM-08 rel: moved_to - href: PR.PS-02 rel: moved_to parts: - id: PR.MA-02_statement name: statement prose: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access - id: PR.PS class: category title: Platform Security props: - name: sort-id value: "00003.00008" - name: label value: Platform Security (PR.PS) parts: - id: PR.PS_statement name: statement prose: The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability controls: - id: PR.PS-01 class: subcategory title: PR.PS-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00008.00001 - name: label value: PR.PS-01 parts: - id: PR.PS-01_statement name: statement prose: Configuration management practices are established and applied - id: PR.PS-01.238 name: example ns: https://csrc.nist.gov/ns/csf prose: Establish, test, deploy, and maintain hardened baselines that enforce the organization's cybersecurity policies and provide only essential capabilities (i.e., principle of least functionality) - id: PR.PS-01.239 name: example ns: https://csrc.nist.gov/ns/csf prose: Review all default configuration settings that may potentially impact cybersecurity when installing or upgrading software - id: PR.PS-01.240 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor implemented software for deviations from approved baselines - id: PR.PS-02 class: subcategory title: PR.PS-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00008.00002 - name: label value: PR.PS-02 parts: - id: PR.PS-02_statement name: statement prose: Software is maintained, replaced, and removed commensurate with risk - id: PR.PS-02.241 name: example ns: https://csrc.nist.gov/ns/csf prose: Perform routine and emergency patching within the timeframes specified in the vulnerability management plan - id: PR.PS-02.242 name: example ns: https://csrc.nist.gov/ns/csf prose: Update container images, and deploy new container instances to replace rather than update existing instances - id: PR.PS-02.243 name: example ns: https://csrc.nist.gov/ns/csf prose: Replace end-of-life software and service versions with supported, maintained versions - id: PR.PS-02.244 name: example ns: https://csrc.nist.gov/ns/csf prose: Uninstall and remove unauthorized software and services that pose undue risks - id: PR.PS-02.245 name: example ns: https://csrc.nist.gov/ns/csf prose: Uninstall and remove any unnecessary software components (e.g., operating system utilities) that attackers might misuse - id: PR.PS-02.246 name: example ns: https://csrc.nist.gov/ns/csf prose: Define and implement plans for software and service end-of-life maintenance support and obsolescence - id: PR.PS-03 class: subcategory title: PR.PS-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00003.00008.00003 - name: label value: PR.PS-03 parts: - id: PR.PS-03_statement name: statement prose: Hardware is maintained, replaced, and removed commensurate with risk - id: PR.PS-03.247 name: example ns: https://csrc.nist.gov/ns/csf prose: Replace hardware when it lacks needed security capabilities or when it cannot support software with needed security capabilities - id: PR.PS-03.248 name: example ns: https://csrc.nist.gov/ns/csf prose: Define and implement plans for hardware end-of-life maintenance support and obsolescence - id: PR.PS-03.249 name: example ns: https://csrc.nist.gov/ns/csf prose: Perform hardware disposal in a secure, responsible, and auditable manner - id: PR.PS-04 class: subcategory title: PR.PS-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00008.00004 - name: label value: PR.PS-04 parts: - id: PR.PS-04_statement name: statement prose: Log records are generated and made available for continuous monitoring - id: PR.PS-04.250 name: example ns: https://csrc.nist.gov/ns/csf prose: Configure all operating systems, applications, and services (including cloud-based services) to generate log records - id: PR.PS-04.251 name: example ns: https://csrc.nist.gov/ns/csf prose: Configure log generators to securely share their logs with the organization's logging infrastructure systems and services - id: PR.PS-04.252 name: example ns: https://csrc.nist.gov/ns/csf prose: Configure log generators to record the data needed by zero-trust architectures - id: PR.PS-05 class: subcategory title: PR.PS-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00008.00005 - name: label value: PR.PS-05 parts: - id: PR.PS-05_statement name: statement prose: Installation and execution of unauthorized software are prevented - id: PR.PS-05.253 name: example ns: https://csrc.nist.gov/ns/csf prose: When risk warrants it, restrict software execution to permitted products only or deny the execution of prohibited and unauthorized software - id: PR.PS-05.254 name: example ns: https://csrc.nist.gov/ns/csf prose: Verify the source of new software and the software's integrity before installing it - id: PR.PS-05.255 name: example ns: https://csrc.nist.gov/ns/csf prose: Configure platforms to use only approved DNS services that block access to known malicious domains - id: PR.PS-05.256 name: example ns: https://csrc.nist.gov/ns/csf prose: Configure platforms to allow the installation of organization-approved software only - id: PR.PS-06 class: subcategory title: PR.PS-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00003.00008.00006 - name: label value: PR.PS-06 parts: - id: PR.PS-06_statement name: statement prose: Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle - id: PR.PS-06.257 name: example ns: https://csrc.nist.gov/ns/csf prose: Protect all components of organization-developed software from tampering and unauthorized access - id: PR.PS-06.258 name: example ns: https://csrc.nist.gov/ns/csf prose: Secure all software produced by the organization, with minimal vulnerabilities in their releases - id: PR.PS-06.259 name: example ns: https://csrc.nist.gov/ns/csf prose: Maintain the software used in production environments, and securely dispose of software once it is no longer needed - id: PR.PT class: category title: Protective Technology props: - name: sort-id value: "00003.00007" - name: label value: Protective Technology (PR.PT) - name: status value: withdrawn parts: - id: PR.PT_statement name: statement controls: - id: PR.PT-01 class: subcategory title: PR.PT-01 props: - name: sort-id value: 00003.00007.00001 - name: label value: PR.PT-01 - name: status value: withdrawn links: - href: PR.PS-04 rel: incorporated_into parts: - id: PR.PT-01_statement name: statement prose: Audit/log records are determined, documented, implemented, and reviewed in accordance with policy - id: PR.PT-02 class: subcategory title: PR.PT-02 props: - name: sort-id value: 00003.00007.00002 - name: label value: PR.PT-02 - name: status value: withdrawn links: - href: PR.DS-01 rel: incorporated_into - href: PR.PS-01 rel: incorporated_into parts: - id: PR.PT-02_statement name: statement prose: Removable media is protected and its use restricted according to policy - id: PR.PT-03 class: subcategory title: PR.PT-03 props: - name: sort-id value: 00003.00007.00003 - name: label value: PR.PT-03 - name: status value: withdrawn links: - href: PR.PS-01 rel: incorporated_into parts: - id: PR.PT-03_statement name: statement prose: The principle of least functionality is incorporated by configuring systems to provide only essential capabilities - id: PR.PT-04 class: subcategory title: PR.PT-04 props: - name: sort-id value: 00003.00007.00004 - name: label value: PR.PT-04 - name: status value: withdrawn links: - href: PR.AA-06 rel: incorporated_into - href: PR.IR-01 rel: incorporated_into parts: - id: PR.PT-04_statement name: statement prose: Communications and control networks are protected - id: PR.PT-05 class: subcategory title: PR.PT-05 props: - name: sort-id value: 00003.00007.00005 - name: label value: PR.PT-05 - name: status value: withdrawn links: - href: PR.IR-03 rel: incorporated_into parts: - id: PR.PT-05_statement name: statement prose: Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations - id: DE class: function title: DETECT props: - name: sort-id value: "00004" - name: label value: DETECT (DE) parts: - id: DE_overview name: overview prose: Possible cybersecurity attacks and compromises are found and analyzed controls: - id: DE.AE class: category title: Adverse Event Analysis props: - name: sort-id value: "00004.00001" - name: label value: Adverse Event Analysis (DE.AE) parts: - id: DE.AE_statement name: statement prose: Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents controls: - id: DE.AE-01 class: subcategory title: DE.AE-01 props: - name: sort-id value: 00004.00001.00001 - name: label value: DE.AE-01 - name: status value: withdrawn links: - href: ID.AM-03 rel: incorporated_into parts: - id: DE.AE-01_statement name: statement prose: A baseline of network operations and expected data flows for users and systems is established and managed - id: DE.AE-02 class: subcategory title: DE.AE-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00001.00002 - name: label value: DE.AE-02 parts: - id: DE.AE-02_statement name: statement prose: Potentially adverse events are analyzed to better understand associated activities - id: DE.AE-02.290 name: example ns: https://csrc.nist.gov/ns/csf prose: Use security information and event management (SIEM) or other tools to continuously monitor log events for known malicious and suspicious activity - id: DE.AE-02.291 name: example ns: https://csrc.nist.gov/ns/csf prose: Utilize up-to-date cyber threat intelligence in log analysis tools to improve detection accuracy and characterize threat actors, their methods, and indicators of compromise - id: DE.AE-02.292 name: example ns: https://csrc.nist.gov/ns/csf prose: Regularly conduct manual reviews of log events for technologies that cannot be sufficiently monitored through automation - id: DE.AE-02.293 name: example ns: https://csrc.nist.gov/ns/csf prose: Use log analysis tools to generate reports on their findings - id: DE.AE-03 class: subcategory title: DE.AE-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00001.00003 - name: label value: DE.AE-03 parts: - id: DE.AE-03_statement name: statement prose: Information is correlated from multiple sources - id: DE.AE-03.294 name: example ns: https://csrc.nist.gov/ns/csf prose: Constantly transfer log data generated by other sources to a relatively small number of log servers - id: DE.AE-03.295 name: example ns: https://csrc.nist.gov/ns/csf prose: Use event correlation technology (e.g., SIEM) to collect information captured by multiple sources - id: DE.AE-03.296 name: example ns: https://csrc.nist.gov/ns/csf prose: Utilize cyber threat intelligence to help correlate events among log sources - id: DE.AE-04 class: subcategory title: DE.AE-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00001.00004 - name: label value: DE.AE-04 parts: - id: DE.AE-04_statement name: statement prose: The estimated impact and scope of adverse events are understood - id: DE.AE-04.297 name: example ns: https://csrc.nist.gov/ns/csf prose: Use SIEMs or other tools to estimate impact and scope, and review and refine the estimates - id: DE.AE-04.298 name: example ns: https://csrc.nist.gov/ns/csf prose: A person creates their own estimates of impact and scope - id: DE.AE-05 class: subcategory title: DE.AE-05 props: - name: sort-id value: 00004.00001.00005 - name: label value: DE.AE-05 - name: status value: withdrawn links: - href: DE.AE-08 rel: moved_to parts: - id: DE.AE-05_statement name: statement prose: Incident alert thresholds are established - id: DE.AE-06 class: subcategory title: DE.AE-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00001.00006 - name: label value: DE.AE-06 parts: - id: DE.AE-06_statement name: statement prose: Information on adverse events is provided to authorized staff and tools - id: DE.AE-06.299 name: example ns: https://csrc.nist.gov/ns/csf prose: Use cybersecurity software to generate alerts and provide them to the security operations center (SOC), incident responders, and incident response tools - id: DE.AE-06.300 name: example ns: https://csrc.nist.gov/ns/csf prose: Incident responders and other authorized personnel can access log analysis findings at all times - id: DE.AE-06.301 name: example ns: https://csrc.nist.gov/ns/csf prose: Automatically create and assign tickets in the organization's ticketing system when certain types of alerts occur - id: DE.AE-06.302 name: example ns: https://csrc.nist.gov/ns/csf prose: Manually create and assign tickets in the organization's ticketing system when technical staff discover indicators of compromise - id: DE.AE-07 class: subcategory title: DE.AE-07 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00001.00007 - name: label value: DE.AE-07 parts: - id: DE.AE-07_statement name: statement prose: Cyber threat intelligence and other contextual information are integrated into the analysis - id: DE.AE-07.303 name: example ns: https://csrc.nist.gov/ns/csf prose: Securely provide cyber threat intelligence feeds to detection technologies, processes, and personnel - id: DE.AE-07.304 name: example ns: https://csrc.nist.gov/ns/csf prose: Securely provide information from asset inventories to detection technologies, processes, and personnel - id: DE.AE-07.305 name: example ns: https://csrc.nist.gov/ns/csf prose: Rapidly acquire and analyze vulnerability disclosures for the organization's technologies from suppliers, vendors, and third-party security advisories - id: DE.AE-08 class: subcategory title: DE.AE-08 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00001.00008 - name: label value: DE.AE-08 parts: - id: DE.AE-08_statement name: statement prose: Incidents are declared when adverse events meet the defined incident criteria - id: DE.AE-08.306 name: example ns: https://csrc.nist.gov/ns/csf prose: Apply incident criteria to known and assumed characteristics of activity in order to determine whether an incident should be declared - id: DE.AE-08.307 name: example ns: https://csrc.nist.gov/ns/csf prose: Take known false positives into account when applying incident criteria - id: DE.CM class: category title: Continuous Monitoring props: - name: sort-id value: "00004.00002" - name: label value: Continuous Monitoring (DE.CM) parts: - id: DE.CM_statement name: statement prose: Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events controls: - id: DE.CM-01 class: subcategory title: DE.CM-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00002.00001 - name: label value: DE.CM-01 parts: - id: DE.CM-01_statement name: statement prose: Networks and network services are monitored to find potentially adverse events - id: DE.CM-01.271 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor DNS, BGP, and other network services for adverse events - id: DE.CM-01.272 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor wired and wireless networks for connections from unauthorized endpoints - id: DE.CM-01.273 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor facilities for unauthorized or rogue wireless networks - id: DE.CM-01.274 name: example ns: https://csrc.nist.gov/ns/csf prose: Compare actual network flows against baselines to detect deviations - id: DE.CM-01.275 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor network communications to identify changes in security postures for zero trust purposes - id: DE.CM-02 class: subcategory title: DE.CM-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00002.00002 - name: label value: DE.CM-02 parts: - id: DE.CM-02_statement name: statement prose: The physical environment is monitored to find potentially adverse events - id: DE.CM-02.276 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor logs from physical access control systems (e.g., badge readers) to find unusual access patterns (e.g., deviations from the norm) and failed access attempts - id: DE.CM-02.277 name: example ns: https://csrc.nist.gov/ns/csf prose: Review and monitor physical access records (e.g., from visitor registration, sign-in sheets) - id: DE.CM-02.278 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor physical access controls (e.g., locks, latches, hinge pins, alarms) for signs of tampering - id: DE.CM-02.279 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor the physical environment using alarm systems, cameras, and security guards - id: DE.CM-03 class: subcategory title: DE.CM-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00002.00003 - name: label value: DE.CM-03 parts: - id: DE.CM-03_statement name: statement prose: Personnel activity and technology usage are monitored to find potentially adverse events - id: DE.CM-03.280 name: example ns: https://csrc.nist.gov/ns/csf prose: Use behavior analytics software to detect anomalous user activity to mitigate insider threats - id: DE.CM-03.281 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor logs from logical access control systems to find unusual access patterns and failed access attempts - id: DE.CM-03.282 name: example ns: https://csrc.nist.gov/ns/csf prose: Continuously monitor deception technology, including user accounts, for any usage - id: DE.CM-04 class: subcategory title: DE.CM-04 props: - name: sort-id value: 00004.00002.00004 - name: label value: DE.CM-04 - name: status value: withdrawn links: - href: DE.CM-01 rel: incorporated_into - href: DE.CM-09 rel: incorporated_into parts: - id: DE.CM-04_statement name: statement prose: Malicious code is detected - id: DE.CM-05 class: subcategory title: DE.CM-05 props: - name: sort-id value: 00004.00002.00005 - name: label value: DE.CM-05 - name: status value: withdrawn links: - href: DE.CM-01 rel: incorporated_into - href: DE.CM-09 rel: incorporated_into parts: - id: DE.CM-05_statement name: statement prose: Unauthorized mobile code is detected - id: DE.CM-06 class: subcategory title: DE.CM-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00004.00002.00006 - name: label value: DE.CM-06 parts: - id: DE.CM-06_statement name: statement prose: External service provider activities and services are monitored to find potentially adverse events - id: DE.CM-06.283 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor remote and onsite administration and maintenance activities that external providers perform on organizational systems - id: DE.CM-06.284 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor activity from cloud-based services, internet service providers, and other service providers for deviations from expected behavior - id: DE.CM-07 class: subcategory title: DE.CM-07 props: - name: sort-id value: 00004.00002.00007 - name: label value: DE.CM-07 - name: status value: withdrawn links: - href: DE.CM-01 rel: incorporated_into - href: DE.CM-03 rel: incorporated_into - href: DE.CM-06 rel: incorporated_into - href: DE.CM-09 rel: incorporated_into parts: - id: DE.CM-07_statement name: statement prose: Monitoring for unauthorized personnel, connections, devices, and software is performed - id: DE.CM-08 class: subcategory title: DE.CM-08 props: - name: sort-id value: 00004.00002.00008 - name: label value: DE.CM-08 - name: status value: withdrawn links: - href: ID.RA-01 rel: incorporated_into parts: - id: DE.CM-08_statement name: statement prose: Vulnerability scans are performed - id: DE.CM-09 class: subcategory title: DE.CM-09 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00004.00002.00009 - name: label value: DE.CM-09 parts: - id: DE.CM-09_statement name: statement prose: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events - id: DE.CM-09.285 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor email, web, file sharing, collaboration services, and other common attack vectors to detect malware, phishing, data leaks and exfiltration, and other adverse events - id: DE.CM-09.286 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor authentication attempts to identify attacks against credentials and unauthorized credential reuse - id: DE.CM-09.287 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor software configurations for deviations from security baselines - id: DE.CM-09.288 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor hardware and software for signs of tampering - id: DE.CM-09.289 name: example ns: https://csrc.nist.gov/ns/csf prose: Use technologies with a presence on endpoints to detect cyber health issues (e.g., missing patches, malware infections, unauthorized software), and redirect the endpoints to a remediation environment before access is authorized - id: DE.DP class: category title: Detection Processes props: - name: sort-id value: "00004.00003" - name: label value: Detection Processes (DE.DP) - name: status value: withdrawn parts: - id: DE.DP_statement name: statement controls: - id: DE.DP-01 class: subcategory title: DE.DP-01 props: - name: sort-id value: 00004.00003.00001 - name: label value: DE.DP-01 - name: status value: withdrawn links: - href: GV.RR-02 rel: incorporated_into parts: - id: DE.DP-01_statement name: statement prose: Roles and responsibilities for detection are well defined to ensure accountability - id: DE.DP-02 class: subcategory title: DE.DP-02 props: - name: sort-id value: 00004.00003.00002 - name: label value: DE.DP-02 - name: status value: withdrawn links: - href: DE.AE rel: incorporated_into parts: - id: DE.DP-02_statement name: statement prose: Detection activities comply with all applicable requirements - id: DE.DP-03 class: subcategory title: DE.DP-03 props: - name: sort-id value: 00004.00003.00003 - name: label value: DE.DP-03 - name: status value: withdrawn links: - href: ID.IM-02 rel: incorporated_into parts: - id: DE.DP-03_statement name: statement prose: Detection processes are tested - id: DE.DP-04 class: subcategory title: DE.DP-04 props: - name: sort-id value: 00004.00003.00004 - name: label value: DE.DP-04 - name: status value: withdrawn links: - href: DE.AE-06 rel: incorporated_into parts: - id: DE.DP-04_statement name: statement prose: Event detection information is communicated - id: DE.DP-05 class: subcategory title: DE.DP-05 props: - name: sort-id value: 00004.00003.00005 - name: label value: DE.DP-05 - name: status value: withdrawn links: - href: ID.IM rel: incorporated_into - href: ID.IM-03 rel: incorporated_into parts: - id: DE.DP-05_statement name: statement prose: Detection processes are continuously improved - id: RS class: function title: RESPOND props: - name: sort-id value: "00005" - name: label value: RESPOND (RS) parts: - id: RS_overview name: overview prose: Actions regarding a detected cybersecurity incident are taken controls: - id: RS.AN class: category title: Incident Analysis props: - name: sort-id value: "00005.00003" - name: label value: Incident Analysis (RS.AN) parts: - id: RS.AN_statement name: statement prose: Investigations are conducted to ensure effective response and support forensics and recovery activities controls: - id: RS.AN-01 class: subcategory title: RS.AN-01 props: - name: sort-id value: 00005.00003.00001 - name: label value: RS.AN-01 - name: status value: withdrawn links: - href: RS.MA-02 rel: incorporated_into parts: - id: RS.AN-01_statement name: statement prose: Notifications from detection systems are investigated - id: RS.AN-02 class: subcategory title: RS.AN-02 props: - name: sort-id value: 00005.00003.00002 - name: label value: RS.AN-02 - name: status value: withdrawn links: - href: RS.MA-02 rel: incorporated_into - href: RS.MA-03 rel: incorporated_into - href: RS.MA-04 rel: incorporated_into parts: - id: RS.AN-02_statement name: statement prose: The impact of the incident is understood - id: RS.AN-03 class: subcategory title: RS.AN-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00005.00003.00003 - name: label value: RS.AN-03 parts: - id: RS.AN-03_statement name: statement prose: Analysis is performed to establish what has taken place during an incident and the root cause of the incident - id: RS.AN-03.321 name: example ns: https://csrc.nist.gov/ns/csf prose: Determine the sequence of events that occurred during the incident and which assets and resources were involved in each event - id: RS.AN-03.322 name: example ns: https://csrc.nist.gov/ns/csf prose: Attempt to determine what vulnerabilities, threats, and threat actors were directly or indirectly involved in the incident - id: RS.AN-03.323 name: example ns: https://csrc.nist.gov/ns/csf prose: Analyze the incident to find the underlying, systemic root causes - id: RS.AN-03.324 name: example ns: https://csrc.nist.gov/ns/csf prose: Check any cyber deception technology for additional information on attacker behavior - id: RS.AN-04 class: subcategory title: RS.AN-04 props: - name: sort-id value: 00005.00003.00004 - name: label value: RS.AN-04 - name: status value: withdrawn links: - href: RS.MA-03 rel: moved_to parts: - id: RS.AN-04_statement name: statement prose: Incidents are categorized consistent with response plans - id: RS.AN-05 class: subcategory title: RS.AN-05 props: - name: sort-id value: 00005.00003.00005 - name: label value: RS.AN-05 - name: status value: withdrawn links: - href: ID.RA-08 rel: moved_to parts: - id: RS.AN-05_statement name: statement prose: Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g. internal testing, security bulletins, or security researchers) - id: RS.AN-06 class: subcategory title: RS.AN-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00005.00003.00006 - name: label value: RS.AN-06 parts: - id: RS.AN-06_statement name: statement prose: Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved - id: RS.AN-06.325 name: example ns: https://csrc.nist.gov/ns/csf prose: Require each incident responder and others (e.g., system administrators, cybersecurity engineers) who perform incident response tasks to record their actions and make the record immutable - id: RS.AN-06.326 name: example ns: https://csrc.nist.gov/ns/csf prose: Require the incident lead to document the incident in detail and be responsible for preserving the integrity of the documentation and the sources of all information being reported - id: RS.AN-07 class: subcategory title: RS.AN-07 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00005.00003.00007 - name: label value: RS.AN-07 parts: - id: RS.AN-07_statement name: statement prose: Incident data and metadata are collected, and their integrity and provenance are preserved - id: RS.AN-07.327 name: example ns: https://csrc.nist.gov/ns/csf prose: Collect, preserve, and safeguard the integrity of all pertinent incident data and metadata (e.g., data source, date/time of collection) based on evidence preservation and chain-of-custody procedures - id: RS.AN-08 class: subcategory title: RS.AN-08 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00005.00003.00008 - name: label value: RS.AN-08 parts: - id: RS.AN-08_statement name: statement prose: An incident's magnitude is estimated and validated - id: RS.AN-08.328 name: example ns: https://csrc.nist.gov/ns/csf prose: Review other potential targets of the incident to search for indicators of compromise and evidence of persistence - id: RS.AN-08.329 name: example ns: https://csrc.nist.gov/ns/csf prose: Automatically run tools on targets to look for indicators of compromise and evidence of persistence - id: RS.CO class: category title: Incident Response Reporting and Communication props: - name: sort-id value: "00005.00004" - name: label value: Incident Response Reporting and Communication (RS.CO) parts: - id: RS.CO_statement name: statement prose: Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies controls: - id: RS.CO-01 class: subcategory title: RS.CO-01 props: - name: sort-id value: 00005.00004.00001 - name: label value: RS.CO-01 - name: status value: withdrawn links: - href: PR.AT-01 rel: incorporated_into parts: - id: RS.CO-01_statement name: statement prose: Personnel know their roles and order of operations when a response is needed - id: RS.CO-02 class: subcategory title: RS.CO-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00005.00004.00002 - name: label value: RS.CO-02 parts: - id: RS.CO-02_statement name: statement prose: Internal and external stakeholders are notified of incidents - id: RS.CO-02.330 name: example ns: https://csrc.nist.gov/ns/csf prose: Follow the organization's breach notification procedures after discovering a data breach incident, including notifying affected customers - id: RS.CO-02.331 name: example ns: https://csrc.nist.gov/ns/csf prose: Notify business partners and customers of incidents in accordance with contractual requirements - id: RS.CO-02.332 name: example ns: https://csrc.nist.gov/ns/csf prose: Notify law enforcement agencies and regulatory bodies of incidents based on criteria in the incident response plan and management approval - id: RS.CO-03 class: subcategory title: RS.CO-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00005.00004.00003 - name: label value: RS.CO-03 parts: - id: RS.CO-03_statement name: statement prose: Information is shared with designated internal and external stakeholders - id: RS.CO-03.333 name: example ns: https://csrc.nist.gov/ns/csf prose: Securely share information consistent with response plans and information sharing agreements - id: RS.CO-03.334 name: example ns: https://csrc.nist.gov/ns/csf prose: Voluntarily share information about an attacker's observed TTPs, with all sensitive data removed, with an Information Sharing and Analysis Center (ISAC) - id: RS.CO-03.335 name: example ns: https://csrc.nist.gov/ns/csf prose: Notify HR when malicious insider activity occurs - id: RS.CO-03.336 name: example ns: https://csrc.nist.gov/ns/csf prose: Regularly update senior leadership on the status of major incidents - id: RS.CO-03.337 name: example ns: https://csrc.nist.gov/ns/csf prose: Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers - id: RS.CO-03.338 name: example ns: https://csrc.nist.gov/ns/csf prose: Coordinate crisis communication methods between the organization and its critical suppliers - id: RS.CO-04 class: subcategory title: RS.CO-04 props: - name: sort-id value: 00005.00004.00004 - name: label value: RS.CO-04 - name: status value: withdrawn links: - href: RS.MA-01 rel: incorporated_into - href: RS.MA-04 rel: incorporated_into parts: - id: RS.CO-04_statement name: statement prose: Coordination with stakeholders occurs consistent with response plans - id: RS.CO-05 class: subcategory title: RS.CO-05 props: - name: sort-id value: 00005.00004.00005 - name: label value: RS.CO-05 - name: status value: withdrawn links: - href: RS.CO-03 rel: incorporated_into parts: - id: RS.CO-05_statement name: statement prose: Voluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness - id: RS.IM class: category title: Improvements props: - name: sort-id value: "00005.00006" - name: label value: Improvements (RS.IM) - name: status value: withdrawn links: - href: ID.IM rel: incorporated_into parts: - id: RS.IM_statement name: statement controls: - id: RS.IM-01 class: subcategory title: RS.IM-01 props: - name: sort-id value: 00005.00006.00001 - name: label value: RS.IM-01 - name: status value: withdrawn links: - href: ID.IM-03 rel: incorporated_into - href: ID.IM-04 rel: incorporated_into parts: - id: RS.IM-01_statement name: statement prose: Response plans incorporate lessons learned - id: RS.IM-02 class: subcategory title: RS.IM-02 props: - name: sort-id value: 00005.00006.00002 - name: label value: RS.IM-02 - name: status value: withdrawn links: - href: ID.IM-03 rel: incorporated_into parts: - id: RS.IM-02_statement name: statement prose: Response strategies are updated - id: RS.MA class: category title: Incident Management props: - name: sort-id value: "00005.00001" - name: label value: Incident Management (RS.MA) parts: - id: RS.MA_statement name: statement prose: Responses to detected cybersecurity incidents are managed controls: - id: RS.MA-01 class: subcategory title: RS.MA-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00005.00001.00001 - name: label value: RS.MA-01 parts: - id: RS.MA-01_statement name: statement prose: The incident response plan is executed in coordination with relevant third parties once an incident is declared - id: RS.MA-01.308 name: example ns: https://csrc.nist.gov/ns/csf prose: Detection technologies automatically report confirmed incidents - id: RS.MA-01.309 name: example ns: https://csrc.nist.gov/ns/csf prose: Request incident response assistance from the organization's incident response outsourcer - id: RS.MA-01.310 name: example ns: https://csrc.nist.gov/ns/csf prose: Designate an incident lead for each incident - id: RS.MA-01.311 name: example ns: https://csrc.nist.gov/ns/csf prose: Initiate execution of additional cybersecurity plans as needed to support incident response (for example, business continuity and disaster recovery) - id: RS.MA-02 class: subcategory title: RS.MA-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00005.00001.00002 - name: label value: RS.MA-02 parts: - id: RS.MA-02_statement name: statement prose: Incident reports are triaged and validated - id: RS.MA-02.312 name: example ns: https://csrc.nist.gov/ns/csf prose: Preliminarily review incident reports to confirm that they are cybersecurity-related and necessitate incident response activities - id: RS.MA-02.313 name: example ns: https://csrc.nist.gov/ns/csf prose: Apply criteria to estimate the severity of an incident - id: RS.MA-03 class: subcategory title: RS.MA-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00005.00001.00003 - name: label value: RS.MA-03 parts: - id: RS.MA-03_statement name: statement prose: Incidents are categorized and prioritized - id: RS.MA-03.314 name: example ns: https://csrc.nist.gov/ns/csf prose: Further review and categorize incidents based on the type of incident (e.g., data breach, ransomware, DDoS, account compromise) - id: RS.MA-03.315 name: example ns: https://csrc.nist.gov/ns/csf prose: Prioritize incidents based on their scope, likely impact, and time-critical nature - id: RS.MA-03.316 name: example ns: https://csrc.nist.gov/ns/csf prose: Select incident response strategies for active incidents by balancing the need to quickly recover from an incident with the need to observe the attacker or conduct a more thorough investigation - id: RS.MA-04 class: subcategory title: RS.MA-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00005.00001.00004 - name: label value: RS.MA-04 parts: - id: RS.MA-04_statement name: statement prose: Incidents are escalated or elevated as needed - id: RS.MA-04.317 name: example ns: https://csrc.nist.gov/ns/csf prose: Track and validate the status of all ongoing incidents - id: RS.MA-04.318 name: example ns: https://csrc.nist.gov/ns/csf prose: Coordinate incident escalation or elevation with designated internal and external stakeholders - id: RS.MA-05 class: subcategory title: RS.MA-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00005.00001.00005 - name: label value: RS.MA-05 parts: - id: RS.MA-05_statement name: statement prose: The criteria for initiating incident recovery are applied - id: RS.MA-05.319 name: example ns: https://csrc.nist.gov/ns/csf prose: Apply incident recovery criteria to known and assumed characteristics of the incident to determine whether incident recovery processes should be initiated - id: RS.MA-05.320 name: example ns: https://csrc.nist.gov/ns/csf prose: Take the possible operational disruption of incident recovery activities into account - id: RS.MI class: category title: Incident Mitigation props: - name: sort-id value: "00005.00005" - name: label value: Incident Mitigation (RS.MI) parts: - id: RS.MI_statement name: statement prose: Activities are performed to prevent expansion of an event and mitigate its effects controls: - id: RS.MI-01 class: subcategory title: RS.MI-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00005.00005.00001 - name: label value: RS.MI-01 parts: - id: RS.MI-01_statement name: statement prose: Incidents are contained - id: RS.MI-01.339 name: example ns: https://csrc.nist.gov/ns/csf prose: Cybersecurity technologies (e.g., antivirus software) and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform containment actions - id: RS.MI-01.340 name: example ns: https://csrc.nist.gov/ns/csf prose: Allow incident responders to manually select and perform containment actions - id: RS.MI-01.341 name: example ns: https://csrc.nist.gov/ns/csf prose: Allow a third party (e.g., internet service provider, managed security service provider) to perform containment actions on behalf of the organization - id: RS.MI-01.342 name: example ns: https://csrc.nist.gov/ns/csf prose: Automatically transfer compromised endpoints to a remediation virtual local area network (VLAN) - id: RS.MI-02 class: subcategory title: RS.MI-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00005.00005.00002 - name: label value: RS.MI-02 parts: - id: RS.MI-02_statement name: statement prose: Incidents are eradicated - id: RS.MI-02.343 name: example ns: https://csrc.nist.gov/ns/csf prose: Cybersecurity technologies and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform eradication actions - id: RS.MI-02.344 name: example ns: https://csrc.nist.gov/ns/csf prose: Allow incident responders to manually select and perform eradication actions - id: RS.MI-02.345 name: example ns: https://csrc.nist.gov/ns/csf prose: Allow a third party (e.g., managed security service provider) to perform eradication actions on behalf of the organization - id: RS.MI-03 class: subcategory title: RS.MI-03 props: - name: sort-id value: 00005.00005.00003 - name: label value: RS.MI-03 - name: status value: withdrawn links: - href: ID.RA-06 rel: incorporated_into parts: - id: RS.MI-03_statement name: statement prose: Newly identified vulnerabilities are mitigated or documented as accepted risks - id: RS.RP class: category title: Response Planning props: - name: sort-id value: "00005.00002" - name: label value: Response Planning (RS.RP) - name: status value: withdrawn parts: - id: RS.RP_statement name: statement controls: - id: RS.RP-01 class: subcategory title: RS.RP-01 props: - name: sort-id value: 00005.00002.00001 - name: label value: RS.RP-01 - name: status value: withdrawn links: - href: RS.MA-01 rel: incorporated_into parts: - id: RS.RP-01_statement name: statement prose: Response plan is executed during or after an incident - id: RC class: function title: RECOVER props: - name: sort-id value: "00006" - name: label value: RECOVER (RC) parts: - id: RC_overview name: overview prose: Assets and operations affected by a cybersecurity incident are restored controls: - id: RC.CO class: category title: Incident Recovery Communication props: - name: sort-id value: "00006.00002" - name: label value: Incident Recovery Communication (RC.CO) parts: - id: RC.CO_statement name: statement prose: Restoration activities are coordinated with internal and external parties controls: - id: RC.CO-01 class: subcategory title: RC.CO-01 props: - name: sort-id value: 00006.00002.00001 - name: label value: RC.CO-01 - name: status value: withdrawn links: - href: RC.CO-04 rel: incorporated_into parts: - id: RC.CO-01_statement name: statement prose: Public relations are managed - id: RC.CO-02 class: subcategory title: RC.CO-02 props: - name: sort-id value: 00006.00002.00002 - name: label value: RC.CO-02 - name: status value: withdrawn links: - href: RC.CO-04 rel: incorporated_into parts: - id: RC.CO-02_statement name: statement prose: Reputation is repaired after an incident - id: RC.CO-03 class: subcategory title: RC.CO-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 3rd remarks: 3rd Party Risk - name: sort-id value: 00006.00002.00003 - name: label value: RC.CO-03 parts: - id: RC.CO-03_statement name: statement prose: Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders - id: RC.CO-03.358 name: example ns: https://csrc.nist.gov/ns/csf prose: Securely share recovery information, including restoration progress, consistent with response plans and information sharing agreements - id: RC.CO-03.359 name: example ns: https://csrc.nist.gov/ns/csf prose: Regularly update senior leadership on recovery status and restoration progress for major incidents - id: RC.CO-03.360 name: example ns: https://csrc.nist.gov/ns/csf prose: Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers - id: RC.CO-03.361 name: example ns: https://csrc.nist.gov/ns/csf prose: Coordinate crisis communication between the organization and its critical suppliers - id: RC.CO-04 class: subcategory title: RC.CO-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00006.00002.00004 - name: label value: RC.CO-04 parts: - id: RC.CO-04_statement name: statement prose: Public updates on incident recovery are shared using approved methods and messaging - id: RC.CO-04.362 name: example ns: https://csrc.nist.gov/ns/csf prose: Follow the organization's breach notification procedures for recovering from a data breach incident - id: RC.CO-04.363 name: example ns: https://csrc.nist.gov/ns/csf prose: Explain the steps being taken to recover from the incident and to prevent a recurrence - id: RC.IM class: category title: Improvements props: - name: sort-id value: "00006.00002" - name: label value: Improvements (RC.IM) - name: status value: withdrawn links: - href: ID.IM rel: incorporated_into parts: - id: RC.IM_statement name: statement controls: - id: RC.IM-01 class: subcategory title: RC.IM-01 props: - name: sort-id value: 00006.00002.00001 - name: label value: RC.IM-01 - name: status value: withdrawn links: - href: ID.IM-03 rel: incorporated_into - href: ID.IM-04 rel: incorporated_into parts: - id: RC.IM-01_statement name: statement prose: Recovery plans incorporate lessons learned - id: RC.IM-02 class: subcategory title: RC.IM-02 props: - name: sort-id value: 00006.00002.00002 - name: label value: RC.IM-02 - name: status value: withdrawn links: - href: ID.IM-03 rel: incorporated_into parts: - id: RC.IM-02_statement name: statement prose: Recovery strategies are updated - id: RC.RP class: category title: Incident Recovery Plan Execution props: - name: sort-id value: "00006.00001" - name: label value: Incident Recovery Plan Execution (RC.RP) parts: - id: RC.RP_statement name: statement prose: Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents controls: - id: RC.RP-01 class: subcategory title: RC.RP-01 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00006.00001.00001 - name: label value: RC.RP-01 parts: - id: RC.RP-01_statement name: statement prose: The recovery portion of the incident response plan is executed once initiated from the incident response process - id: RC.RP-01.346 name: example ns: https://csrc.nist.gov/ns/csf prose: Begin recovery procedures during or after incident response processes - id: RC.RP-01.347 name: example ns: https://csrc.nist.gov/ns/csf prose: Make all individuals with recovery responsibilities aware of the plans for recovery and the authorizations required to implement each aspect of the plans - id: RC.RP-02 class: subcategory title: RC.RP-02 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00006.00001.00002 - name: label value: RC.RP-02 parts: - id: RC.RP-02_statement name: statement prose: Recovery actions are selected, scoped, prioritized, and performed - id: RC.RP-02.348 name: example ns: https://csrc.nist.gov/ns/csf prose: Select recovery actions based on the criteria defined in the incident response plan and available resources - id: RC.RP-02.349 name: example ns: https://csrc.nist.gov/ns/csf prose: Change planned recovery actions based on a reassessment of organizational needs and resources - id: RC.RP-03 class: subcategory title: RC.RP-03 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00006.00001.00003 - name: label value: RC.RP-03 parts: - id: RC.RP-03_statement name: statement prose: The integrity of backups and other restoration assets is verified before using them for restoration - id: RC.RP-03.350 name: example ns: https://csrc.nist.gov/ns/csf prose: Check restoration assets for indicators of compromise, file corruption, and other integrity issues before use - id: RC.RP-04 class: subcategory title: RC.RP-04 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00006.00001.00004 - name: label value: RC.RP-04 parts: - id: RC.RP-04_statement name: statement prose: Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms - id: RC.RP-04.351 name: example ns: https://csrc.nist.gov/ns/csf prose: Use business impact and system categorization records (including service delivery objectives) to validate that essential services are restored in the appropriate order - id: RC.RP-04.352 name: example ns: https://csrc.nist.gov/ns/csf prose: Work with system owners to confirm the successful restoration of systems and the return to normal operations - id: RC.RP-04.353 name: example ns: https://csrc.nist.gov/ns/csf prose: Monitor the performance of restored systems to verify the adequacy of the restoration - id: RC.RP-05 class: subcategory title: RC.RP-05 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00006.00001.00005 - name: label value: RC.RP-05 parts: - id: RC.RP-05_statement name: statement prose: The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed - id: RC.RP-05.354 name: example ns: https://csrc.nist.gov/ns/csf prose: Check restored assets for indicators of compromise and remediation of root causes of the incident before production use - id: RC.RP-05.355 name: example ns: https://csrc.nist.gov/ns/csf prose: Verify the correctness and adequacy of the restoration actions taken before putting a restored system online - id: RC.RP-06 class: subcategory title: RC.RP-06 props: - name: risk-party ns: https://csrc.nist.gov/ns/csf value: 1st remarks: 1st Party Risk - name: sort-id value: 00006.00001.00006 - name: label value: RC.RP-06 parts: - id: RC.RP-06_statement name: statement prose: The end of incident recovery is declared based on criteria, and incident-related documentation is completed - id: RC.RP-06.356 name: example ns: https://csrc.nist.gov/ns/csf prose: Prepare an after-action report that documents the incident itself, the response and recovery actions taken, and lessons learned - id: RC.RP-06.357 name: example ns: https://csrc.nist.gov/ns/csf prose: Declare the end of incident recovery once the criteria are met back-matter: resources: - uuid: 3ab41d8a-66e3-4732-ae28-07405dad5127 title: The NIST Cybersecurity Framework 2.0 (PDF) rlinks: - href: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.ipd.pdf media-type: application/pdf - uuid: 0451580b-8ef9-4f52-9182-bc887d6cf369 title: The NIST Cybersecurity Framework 2.0 (DOI link) rlinks: - href: https://doi.org/10.6028/NIST.CSWP.29.ipd media-type: application/pdf - uuid: a7f54afa-16cf-4200-a043-85aa554b93e4 title: The NIST Cybersecurity Framework rlinks: - href: https://www.nist.gov/cyberframework media-type: application/html - uuid: 720a010b-253c-4a94-bb65-cb58400966f5 title: NIST CSF v2.0 content in OSCAL 1.1.3 rlinks: - href: https://github.com/usnistgov/oscal-content/releases/tag/v1.4.0