NIST

NIST Cybersecurity Framework (CSF) 2.0

2.0

Publié par NIST
Version 2.0
Date de publication 2024-02-26
Langue en
Exigences 225
Document source csf.xlsx
Clé de plateforme arcate:compliance:frameworks/nist-csf/2.0

Exigences

ID.RA — Risk Assessment

The cybersecurity risk to the organization, assets, and individuals is understood by the organization

arcate:compliance:requirements/nist-csf/2.0/ID.RA · row 52 of sheet 'CSF 2.0'

ID.RA-01

Vulnerabilities in assets are identified, validated, and recorded

arcate:compliance:requirements/nist-csf/2.0/ID.RA-01 · row 53 of sheet 'CSF 2.0'

ID.RA-02

Cyber threat intelligence is received from information sharing forums and sources

arcate:compliance:requirements/nist-csf/2.0/ID.RA-02 · row 54 of sheet 'CSF 2.0'

ID.RA-03

Internal and external threats to the organization are identified and recorded

arcate:compliance:requirements/nist-csf/2.0/ID.RA-03 · row 55 of sheet 'CSF 2.0'

ID.RA-04

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

arcate:compliance:requirements/nist-csf/2.0/ID.RA-04 · row 56 of sheet 'CSF 2.0'

ID.RA-05

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

arcate:compliance:requirements/nist-csf/2.0/ID.RA-05 · row 57 of sheet 'CSF 2.0'

ID.RA-06

Risk responses are chosen, prioritized, planned, tracked, and communicated

arcate:compliance:requirements/nist-csf/2.0/ID.RA-06 · row 58 of sheet 'CSF 2.0'

ID.RA-07

Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

arcate:compliance:requirements/nist-csf/2.0/ID.RA-07 · row 59 of sheet 'CSF 2.0'

ID.RA-08

Processes for receiving, analyzing, and responding to vulnerability disclosures are established

arcate:compliance:requirements/nist-csf/2.0/ID.RA-08 · row 60 of sheet 'CSF 2.0'

ID.RA-09

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

arcate:compliance:requirements/nist-csf/2.0/ID.RA-09 · row 61 of sheet 'CSF 2.0'

ID.RA-10

Critical suppliers are assessed prior to acquisition

arcate:compliance:requirements/nist-csf/2.0/ID.RA-10 · row 62 of sheet 'CSF 2.0'

ID.IM — Improvement

Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions

arcate:compliance:requirements/nist-csf/2.0/ID.IM · row 63 of sheet 'CSF 2.0'

ID.IM-01

Improvements are identified from evaluations

arcate:compliance:requirements/nist-csf/2.0/ID.IM-01 · row 64 of sheet 'CSF 2.0'

ID.IM-02

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

arcate:compliance:requirements/nist-csf/2.0/ID.IM-02 · row 65 of sheet 'CSF 2.0'

ID.IM-03

Improvements are identified from execution of operational processes, procedures, and activities

arcate:compliance:requirements/nist-csf/2.0/ID.IM-03 · row 66 of sheet 'CSF 2.0'

ID.IM-04

Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

arcate:compliance:requirements/nist-csf/2.0/ID.IM-04 · row 67 of sheet 'CSF 2.0'

ID.BE — Business Environment

[Withdrawn: Incorporated into GV.OC]

arcate:compliance:requirements/nist-csf/2.0/ID.BE · row 68 of sheet 'CSF 2.0'

ID.BE-01

[Withdrawn: Incorporated into GV.OC-05]

arcate:compliance:requirements/nist-csf/2.0/ID.BE-01 · row 69 of sheet 'CSF 2.0'

ID.BE-02

[Withdrawn: Incorporated into GV.OC-01]

arcate:compliance:requirements/nist-csf/2.0/ID.BE-02 · row 70 of sheet 'CSF 2.0'

ID.BE-03

[Withdrawn: Incorporated into GV.OC-01]

arcate:compliance:requirements/nist-csf/2.0/ID.BE-03 · row 71 of sheet 'CSF 2.0'

ID.BE-04

[Withdrawn: Incorporated into GV.OC-04, GV.OC-05]

arcate:compliance:requirements/nist-csf/2.0/ID.BE-04 · row 72 of sheet 'CSF 2.0'

ID.BE-05

[Withdrawn: Incorporated into GV.OC-04]

arcate:compliance:requirements/nist-csf/2.0/ID.BE-05 · row 73 of sheet 'CSF 2.0'

ID.GV — Governance

[Withdrawn: Incorporated into GV]

arcate:compliance:requirements/nist-csf/2.0/ID.GV · row 74 of sheet 'CSF 2.0'

ID.GV-01

[Withdrawn: Incorporated into GV.PO, GV.PO-01, GV.PO-02]

arcate:compliance:requirements/nist-csf/2.0/ID.GV-01 · row 75 of sheet 'CSF 2.0'