[Withdrawn: Incorporated into PR.AT-01, PR.AT-02]
| Publié par | NIST |
|---|---|
| Version | 2.0 |
| Date de publication | 2024-02-26 |
| Langue | en |
| Exigences | 225 |
| Document source | csf.xlsx |
| Clé de plateforme | arcate:compliance:frameworks/nist-csf/2.0 |
Exigences
[Withdrawn: Incorporated into PR.AT-02]
[Withdrawn: Incorporated into PR.AT-02]
PR.DS
— Data Security
Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
The confidentiality, integrity, and availability of data-at-rest are protected
The confidentiality, integrity, and availability of data-in-transit are protected
[Withdrawn: Incorporated into ID.AM-08, PR.PS-03]
[Withdrawn: Moved to PR.IR-04]
[Withdrawn: Incorporated into PR.DS-01, PR.DS-02, PR.DS-10]
[Withdrawn: Incorporated into PR.DS-01, DE.CM-09]
[Withdrawn: Incorporated into PR.IR-01]
[Withdrawn: Incorporated into ID.RA-09, DE.CM-09]
The confidentiality, integrity, and availability of data-in-use are protected
Backups of data are created, protected, maintained, and tested
PR.PS
— Platform Security
The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability
Configuration management practices are established and applied
Software is maintained, replaced, and removed commensurate with risk
Hardware is maintained, replaced, and removed commensurate with risk
Log records are generated and made available for continuous monitoring
Installation and execution of unauthorized software are prevented
Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
PR.IR
— Technology Infrastructure Resilience
Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience
Networks and environments are protected from unauthorized logical access and usage
The organization's technology assets are protected from environmental threats