NIST

NIST Cybersecurity Framework (CSF) 2.0

2.0

Publié par NIST
Version 2.0
Date de publication 2024-02-26
Langue en
Exigences 225
Document source csf.xlsx
Clé de plateforme arcate:compliance:frameworks/nist-csf/2.0

Exigences

GV — GOVERN

The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored

arcate:compliance:requirements/nist-csf/2.0/GV · row 3 of sheet 'CSF 2.0'

GV.OC — Organizational Context

The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood

arcate:compliance:requirements/nist-csf/2.0/GV.OC · row 4 of sheet 'CSF 2.0'

GV.OC-01

The organizational mission is understood and informs cybersecurity risk management

arcate:compliance:requirements/nist-csf/2.0/GV.OC-01 · row 5 of sheet 'CSF 2.0'

GV.OC-02

Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered

arcate:compliance:requirements/nist-csf/2.0/GV.OC-02 · row 6 of sheet 'CSF 2.0'

GV.OC-03

Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

arcate:compliance:requirements/nist-csf/2.0/GV.OC-03 · row 7 of sheet 'CSF 2.0'

GV.OC-04

Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

arcate:compliance:requirements/nist-csf/2.0/GV.OC-04 · row 8 of sheet 'CSF 2.0'

GV.OC-05

Outcomes, capabilities, and services that the organization depends on are understood and communicated

arcate:compliance:requirements/nist-csf/2.0/GV.OC-05 · row 9 of sheet 'CSF 2.0'

GV.RM — Risk Management Strategy

The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions

arcate:compliance:requirements/nist-csf/2.0/GV.RM · row 10 of sheet 'CSF 2.0'

GV.RM-01

Risk management objectives are established and agreed to by organizational stakeholders

arcate:compliance:requirements/nist-csf/2.0/GV.RM-01 · row 11 of sheet 'CSF 2.0'

GV.RM-02

Risk appetite and risk tolerance statements are established, communicated, and maintained

arcate:compliance:requirements/nist-csf/2.0/GV.RM-02 · row 12 of sheet 'CSF 2.0'

GV.RM-03

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

arcate:compliance:requirements/nist-csf/2.0/GV.RM-03 · row 13 of sheet 'CSF 2.0'

GV.RM-04

Strategic direction that describes appropriate risk response options is established and communicated

arcate:compliance:requirements/nist-csf/2.0/GV.RM-04 · row 14 of sheet 'CSF 2.0'

GV.RM-05

Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

arcate:compliance:requirements/nist-csf/2.0/GV.RM-05 · row 15 of sheet 'CSF 2.0'

GV.RM-06

A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

arcate:compliance:requirements/nist-csf/2.0/GV.RM-06 · row 16 of sheet 'CSF 2.0'

GV.RM-07

Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions

arcate:compliance:requirements/nist-csf/2.0/GV.RM-07 · row 17 of sheet 'CSF 2.0'

GV.RR — Roles, Responsibilities, and Authorities

Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated

arcate:compliance:requirements/nist-csf/2.0/GV.RR · row 18 of sheet 'CSF 2.0'

GV.RR-01

Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

arcate:compliance:requirements/nist-csf/2.0/GV.RR-01 · row 19 of sheet 'CSF 2.0'

GV.RR-02

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

arcate:compliance:requirements/nist-csf/2.0/GV.RR-02 · row 20 of sheet 'CSF 2.0'

GV.RR-03

Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

arcate:compliance:requirements/nist-csf/2.0/GV.RR-03 · row 21 of sheet 'CSF 2.0'

GV.RR-04

Cybersecurity is included in human resources practices

arcate:compliance:requirements/nist-csf/2.0/GV.RR-04 · row 22 of sheet 'CSF 2.0'

GV.PO — Policy

Organizational cybersecurity policy is established, communicated, and enforced

arcate:compliance:requirements/nist-csf/2.0/GV.PO · row 23 of sheet 'CSF 2.0'

GV.PO-01

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

arcate:compliance:requirements/nist-csf/2.0/GV.PO-01 · row 24 of sheet 'CSF 2.0'

GV.PO-02

Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission

arcate:compliance:requirements/nist-csf/2.0/GV.PO-02 · row 25 of sheet 'CSF 2.0'

GV.OV — Oversight

Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy

arcate:compliance:requirements/nist-csf/2.0/GV.OV · row 26 of sheet 'CSF 2.0'