ID.RA
— Risk Assessment
The cybersecurity risk to the organization, assets, and individuals is understood by the organization
| Publié par | NIST |
|---|---|
| Version | 2.0 |
| Date de publication | 2024-02-26 |
| Langue | en |
| Exigences | 225 |
| Document source | csf.xlsx |
| Clé de plateforme | arcate:compliance:frameworks/nist-csf/2.0 |
ID.RA
— Risk Assessment
The cybersecurity risk to the organization, assets, and individuals is understood by the organization
Vulnerabilities in assets are identified, validated, and recorded
Cyber threat intelligence is received from information sharing forums and sources
Internal and external threats to the organization are identified and recorded
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Risk responses are chosen, prioritized, planned, tracked, and communicated
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
Processes for receiving, analyzing, and responding to vulnerability disclosures are established
The authenticity and integrity of hardware and software are assessed prior to acquisition and use
Critical suppliers are assessed prior to acquisition
ID.IM
— Improvement
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
Improvements are identified from evaluations
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Improvements are identified from execution of operational processes, procedures, and activities
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
ID.BE
— Business Environment
[Withdrawn: Incorporated into GV.OC]
[Withdrawn: Incorporated into GV.OC-05]
[Withdrawn: Incorporated into GV.OC-01]
[Withdrawn: Incorporated into GV.OC-01]
[Withdrawn: Incorporated into GV.OC-04, GV.OC-05]
[Withdrawn: Incorporated into GV.OC-04]
ID.GV
— Governance
[Withdrawn: Incorporated into GV]
[Withdrawn: Incorporated into GV.PO, GV.PO-01, GV.PO-02]