Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
| Publié par | NIST |
|---|---|
| Version | 2.0 |
| Date de publication | 2024-02-26 |
| Langue | en |
| Exigences | 225 |
| Document source | csf.xlsx |
| Clé de plateforme | arcate:compliance:frameworks/nist-csf/2.0 |
Exigences
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
GV.SC
— Cybersecurity Supply Chain Risk Management
Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
Suppliers are known and prioritized by criticality
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
ID
— IDENTIFY
The organization's current cybersecurity risks are understood
ID.AM
— Asset Management
Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization's risk strategy
Inventories of hardware managed by the organization are maintained
Inventories of software, services, and systems managed by the organization are maintained
Representations of the organization's authorized network communication and internal and external network data flows are maintained
Inventories of services provided by suppliers are maintained
Assets are prioritized based on classification, criticality, resources, and impact on the mission
[Withdrawn: Incorporated into GV.RR-02, GV.SC-02]
Inventories of data and corresponding metadata for designated data types are maintained
Systems, hardware, software, services, and data are managed throughout their life cycles