PR.AA
— Identity Management, Authentication, and Access Control
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access
Safeguards to manage the organization's cybersecurity risks are used
| Citation | PR |
|---|---|
| Clé de plateforme | arcate:compliance:requirements/nist-csf/2.0/PR |
| Emplacement dans la source | row 90 of sheet 'CSF 2.0' |
| Publié par | NIST |
PR.AA
— Identity Management, Authentication, and Access Control
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access
PR.AT
— Awareness and Training
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
PR.DS
— Data Security
Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
PR.PS
— Platform Security
The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability
PR.IR
— Technology Infrastructure Resilience
Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience
PR.AC
— Identity Management, Authentication and Access Control
[Withdrawn: Moved to PR.AA]
PR.IP
— Information Protection Processes and Procedures
[Withdrawn: Incorporated into other Categories and Functions]
PR.MA
— Maintenance
[Withdrawn: Incorporated into ID.AM-08]
PR.PT
— Protective Technology
[Withdrawn: Incorporated into other Protect Categories]