NIST

NIST Cybersecurity Framework (CSF) 2.0

2.0

Publié par NIST
Version 2.0
Date de publication 2024-02-26
Langue en
Exigences 225
Document source csf.xlsx
Clé de plateforme arcate:compliance:frameworks/nist-csf/2.0

Exigences

GV.OV-01

Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction

arcate:compliance:requirements/nist-csf/2.0/GV.OV-01 · row 27 of sheet 'CSF 2.0'

GV.OV-02

The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

arcate:compliance:requirements/nist-csf/2.0/GV.OV-02 · row 28 of sheet 'CSF 2.0'

GV.OV-03

Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

arcate:compliance:requirements/nist-csf/2.0/GV.OV-03 · row 29 of sheet 'CSF 2.0'

GV.SC — Cybersecurity Supply Chain Risk Management

Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders

arcate:compliance:requirements/nist-csf/2.0/GV.SC · row 30 of sheet 'CSF 2.0'

GV.SC-01

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

arcate:compliance:requirements/nist-csf/2.0/GV.SC-01 · row 31 of sheet 'CSF 2.0'

GV.SC-02

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally

arcate:compliance:requirements/nist-csf/2.0/GV.SC-02 · row 32 of sheet 'CSF 2.0'

GV.SC-03

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

arcate:compliance:requirements/nist-csf/2.0/GV.SC-03 · row 33 of sheet 'CSF 2.0'

GV.SC-04

Suppliers are known and prioritized by criticality

arcate:compliance:requirements/nist-csf/2.0/GV.SC-04 · row 34 of sheet 'CSF 2.0'

GV.SC-05

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

arcate:compliance:requirements/nist-csf/2.0/GV.SC-05 · row 35 of sheet 'CSF 2.0'

GV.SC-06

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

arcate:compliance:requirements/nist-csf/2.0/GV.SC-06 · row 36 of sheet 'CSF 2.0'

GV.SC-07

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

arcate:compliance:requirements/nist-csf/2.0/GV.SC-07 · row 37 of sheet 'CSF 2.0'

GV.SC-08

Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

arcate:compliance:requirements/nist-csf/2.0/GV.SC-08 · row 38 of sheet 'CSF 2.0'

GV.SC-09

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

arcate:compliance:requirements/nist-csf/2.0/GV.SC-09 · row 39 of sheet 'CSF 2.0'

GV.SC-10

Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

arcate:compliance:requirements/nist-csf/2.0/GV.SC-10 · row 40 of sheet 'CSF 2.0'

ID — IDENTIFY

The organization's current cybersecurity risks are understood

arcate:compliance:requirements/nist-csf/2.0/ID · row 42 of sheet 'CSF 2.0'

ID.AM — Asset Management

Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization's risk strategy

arcate:compliance:requirements/nist-csf/2.0/ID.AM · row 43 of sheet 'CSF 2.0'

ID.AM-01

Inventories of hardware managed by the organization are maintained

arcate:compliance:requirements/nist-csf/2.0/ID.AM-01 · row 44 of sheet 'CSF 2.0'

ID.AM-02

Inventories of software, services, and systems managed by the organization are maintained

arcate:compliance:requirements/nist-csf/2.0/ID.AM-02 · row 45 of sheet 'CSF 2.0'

ID.AM-03

Representations of the organization's authorized network communication and internal and external network data flows are maintained

arcate:compliance:requirements/nist-csf/2.0/ID.AM-03 · row 46 of sheet 'CSF 2.0'

ID.AM-04

Inventories of services provided by suppliers are maintained

arcate:compliance:requirements/nist-csf/2.0/ID.AM-04 · row 47 of sheet 'CSF 2.0'

ID.AM-05

Assets are prioritized based on classification, criticality, resources, and impact on the mission

arcate:compliance:requirements/nist-csf/2.0/ID.AM-05 · row 48 of sheet 'CSF 2.0'

ID.AM-06

[Withdrawn: Incorporated into GV.RR-02, GV.SC-02]

arcate:compliance:requirements/nist-csf/2.0/ID.AM-06 · row 49 of sheet 'CSF 2.0'

ID.AM-07

Inventories of data and corresponding metadata for designated data types are maintained

arcate:compliance:requirements/nist-csf/2.0/ID.AM-07 · row 50 of sheet 'CSF 2.0'

ID.AM-08

Systems, hardware, software, services, and data are managed throughout their life cycles

arcate:compliance:requirements/nist-csf/2.0/ID.AM-08 · row 51 of sheet 'CSF 2.0'