NIST

NIST Cybersecurity Framework (CSF) 2.0

2.0

Publié par NIST
Version 2.0
Date de publication 2024-02-26
Langue en
Exigences 225
Document source csf.xlsx
Clé de plateforme arcate:compliance:frameworks/nist-csf/2.0

Exigences

ID.GV-02

[Withdrawn: Incorporated into GV.OC-02, GV.RR, GV.RR-02]

arcate:compliance:requirements/nist-csf/2.0/ID.GV-02 · row 76 of sheet 'CSF 2.0'

ID.GV-03

[Withdrawn: Moved to GV.OC-03]

arcate:compliance:requirements/nist-csf/2.0/ID.GV-03 · row 77 of sheet 'CSF 2.0'

ID.GV-04

[Withdrawn: Moved to GV.RM-04]

arcate:compliance:requirements/nist-csf/2.0/ID.GV-04 · row 78 of sheet 'CSF 2.0'

ID.RM — Risk Management Strategy

[Withdrawn: Incorporated into GV.RM]

arcate:compliance:requirements/nist-csf/2.0/ID.RM · row 79 of sheet 'CSF 2.0'

ID.RM-01

[Withdrawn: Incorporated into GV.RM-01, GV.RM-06, GV.RR-03]

arcate:compliance:requirements/nist-csf/2.0/ID.RM-01 · row 80 of sheet 'CSF 2.0'

ID.RM-02

[Withdrawn: Incorporated into GV.RM-02, GV.RM-04]

arcate:compliance:requirements/nist-csf/2.0/ID.RM-02 · row 81 of sheet 'CSF 2.0'

ID.RM-03

[Withdrawn: Moved into GV.RM-02]

arcate:compliance:requirements/nist-csf/2.0/ID.RM-03 · row 82 of sheet 'CSF 2.0'

ID.SC — Supply Chain Risk Management

[Withdrawn: Incorporated into GV.SC]

arcate:compliance:requirements/nist-csf/2.0/ID.SC · row 83 of sheet 'CSF 2.0'

ID.SC-01

[Withdrawn: Incorporated into GV.RM-05, GV.SC-01, GV.SC-06, GV.SC-09, GV.SC-10]

arcate:compliance:requirements/nist-csf/2.0/ID.SC-01 · row 84 of sheet 'CSF 2.0'

ID.SC-02

[Withdrawn: Incorporated into GV.OC-02, GV.SC-03, GV.SC-04, GV.SC-07, ID.RA-10]

arcate:compliance:requirements/nist-csf/2.0/ID.SC-02 · row 85 of sheet 'CSF 2.0'

ID.SC-03

[Withdrawn: Moved to GV.SC-05]

arcate:compliance:requirements/nist-csf/2.0/ID.SC-03 · row 86 of sheet 'CSF 2.0'

ID.SC-04

[Withdrawn: Incorporated into GV.SC-07, ID.RA-10]

arcate:compliance:requirements/nist-csf/2.0/ID.SC-04 · row 87 of sheet 'CSF 2.0'

ID.SC-05

[Withdrawn: Incorporated into GV.SC-08, ID.IM-02]

arcate:compliance:requirements/nist-csf/2.0/ID.SC-05 · row 88 of sheet 'CSF 2.0'

PR — PROTECT

Safeguards to manage the organization's cybersecurity risks are used

arcate:compliance:requirements/nist-csf/2.0/PR · row 90 of sheet 'CSF 2.0'

PR.AA — Identity Management, Authentication, and Access Control

Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access

arcate:compliance:requirements/nist-csf/2.0/PR.AA · row 91 of sheet 'CSF 2.0'

PR.AA-01

Identities and credentials for authorized users, services, and hardware are managed by the organization

arcate:compliance:requirements/nist-csf/2.0/PR.AA-01 · row 92 of sheet 'CSF 2.0'

PR.AA-02

Identities are proofed and bound to credentials based on the context of interactions

arcate:compliance:requirements/nist-csf/2.0/PR.AA-02 · row 93 of sheet 'CSF 2.0'

PR.AA-03

Users, services, and hardware are authenticated

arcate:compliance:requirements/nist-csf/2.0/PR.AA-03 · row 94 of sheet 'CSF 2.0'

PR.AA-04

Identity assertions are protected, conveyed, and verified

arcate:compliance:requirements/nist-csf/2.0/PR.AA-04 · row 95 of sheet 'CSF 2.0'

PR.AA-05

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

arcate:compliance:requirements/nist-csf/2.0/PR.AA-05 · row 96 of sheet 'CSF 2.0'

PR.AA-06

Physical access to assets is managed, monitored, and enforced commensurate with risk

arcate:compliance:requirements/nist-csf/2.0/PR.AA-06 · row 97 of sheet 'CSF 2.0'

PR.AT — Awareness and Training

The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks

arcate:compliance:requirements/nist-csf/2.0/PR.AT · row 98 of sheet 'CSF 2.0'

PR.AT-01

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

arcate:compliance:requirements/nist-csf/2.0/PR.AT-01 · row 99 of sheet 'CSF 2.0'

PR.AT-02

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

arcate:compliance:requirements/nist-csf/2.0/PR.AT-02 · row 100 of sheet 'CSF 2.0'