[Withdrawn: Incorporated into GV.OC-02, GV.RR, GV.RR-02]
| Publié par | NIST |
|---|---|
| Version | 2.0 |
| Date de publication | 2024-02-26 |
| Langue | en |
| Exigences | 225 |
| Document source | csf.xlsx |
| Clé de plateforme | arcate:compliance:frameworks/nist-csf/2.0 |
Exigences
[Withdrawn: Moved to GV.OC-03]
[Withdrawn: Moved to GV.RM-04]
ID.RM
— Risk Management Strategy
[Withdrawn: Incorporated into GV.RM]
[Withdrawn: Incorporated into GV.RM-01, GV.RM-06, GV.RR-03]
[Withdrawn: Incorporated into GV.RM-02, GV.RM-04]
[Withdrawn: Moved into GV.RM-02]
ID.SC
— Supply Chain Risk Management
[Withdrawn: Incorporated into GV.SC]
[Withdrawn: Incorporated into GV.RM-05, GV.SC-01, GV.SC-06, GV.SC-09, GV.SC-10]
[Withdrawn: Incorporated into GV.OC-02, GV.SC-03, GV.SC-04, GV.SC-07, ID.RA-10]
[Withdrawn: Moved to GV.SC-05]
[Withdrawn: Incorporated into GV.SC-07, ID.RA-10]
[Withdrawn: Incorporated into GV.SC-08, ID.IM-02]
PR
— PROTECT
Safeguards to manage the organization's cybersecurity risks are used
PR.AA
— Identity Management, Authentication, and Access Control
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access
Identities and credentials for authorized users, services, and hardware are managed by the organization
Identities are proofed and bound to credentials based on the context of interactions
Users, services, and hardware are authenticated
Identity assertions are protected, conveyed, and verified
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Physical access to assets is managed, monitored, and enforced commensurate with risk
PR.AT
— Awareness and Training
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind