NIST

NIST Cybersecurity Framework (CSF) 2.0

2.0

Publié par NIST
Version 2.0
Date de publication 2024-02-26
Langue en
Exigences 225
Document source csf.xlsx
Clé de plateforme arcate:compliance:frameworks/nist-csf/2.0

Exigences

PR.AT-03

[Withdrawn: Incorporated into PR.AT-01, PR.AT-02]

arcate:compliance:requirements/nist-csf/2.0/PR.AT-03 · row 101 of sheet 'CSF 2.0'

PR.AT-04

[Withdrawn: Incorporated into PR.AT-02]

arcate:compliance:requirements/nist-csf/2.0/PR.AT-04 · row 102 of sheet 'CSF 2.0'

PR.AT-05

[Withdrawn: Incorporated into PR.AT-02]

arcate:compliance:requirements/nist-csf/2.0/PR.AT-05 · row 103 of sheet 'CSF 2.0'

PR.DS — Data Security

Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information

arcate:compliance:requirements/nist-csf/2.0/PR.DS · row 104 of sheet 'CSF 2.0'

PR.DS-01

The confidentiality, integrity, and availability of data-at-rest are protected

arcate:compliance:requirements/nist-csf/2.0/PR.DS-01 · row 105 of sheet 'CSF 2.0'

PR.DS-02

The confidentiality, integrity, and availability of data-in-transit are protected

arcate:compliance:requirements/nist-csf/2.0/PR.DS-02 · row 106 of sheet 'CSF 2.0'

PR.DS-03

[Withdrawn: Incorporated into ID.AM-08, PR.PS-03]

arcate:compliance:requirements/nist-csf/2.0/PR.DS-03 · row 107 of sheet 'CSF 2.0'

PR.DS-04

[Withdrawn: Moved to PR.IR-04]

arcate:compliance:requirements/nist-csf/2.0/PR.DS-04 · row 108 of sheet 'CSF 2.0'

PR.DS-05

[Withdrawn: Incorporated into PR.DS-01, PR.DS-02, PR.DS-10]

arcate:compliance:requirements/nist-csf/2.0/PR.DS-05 · row 109 of sheet 'CSF 2.0'

PR.DS-06

[Withdrawn: Incorporated into PR.DS-01, DE.CM-09]

arcate:compliance:requirements/nist-csf/2.0/PR.DS-06 · row 110 of sheet 'CSF 2.0'

PR.DS-07

[Withdrawn: Incorporated into PR.IR-01]

arcate:compliance:requirements/nist-csf/2.0/PR.DS-07 · row 111 of sheet 'CSF 2.0'

PR.DS-08

[Withdrawn: Incorporated into ID.RA-09, DE.CM-09]

arcate:compliance:requirements/nist-csf/2.0/PR.DS-08 · row 112 of sheet 'CSF 2.0'

PR.DS-10

The confidentiality, integrity, and availability of data-in-use are protected

arcate:compliance:requirements/nist-csf/2.0/PR.DS-10 · row 113 of sheet 'CSF 2.0'

PR.DS-11

Backups of data are created, protected, maintained, and tested

arcate:compliance:requirements/nist-csf/2.0/PR.DS-11 · row 114 of sheet 'CSF 2.0'

PR.PS — Platform Security

The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability

arcate:compliance:requirements/nist-csf/2.0/PR.PS · row 115 of sheet 'CSF 2.0'

PR.PS-01

Configuration management practices are established and applied

arcate:compliance:requirements/nist-csf/2.0/PR.PS-01 · row 116 of sheet 'CSF 2.0'

PR.PS-02

Software is maintained, replaced, and removed commensurate with risk

arcate:compliance:requirements/nist-csf/2.0/PR.PS-02 · row 117 of sheet 'CSF 2.0'

PR.PS-03

Hardware is maintained, replaced, and removed commensurate with risk

arcate:compliance:requirements/nist-csf/2.0/PR.PS-03 · row 118 of sheet 'CSF 2.0'

PR.PS-04

Log records are generated and made available for continuous monitoring

arcate:compliance:requirements/nist-csf/2.0/PR.PS-04 · row 119 of sheet 'CSF 2.0'

PR.PS-05

Installation and execution of unauthorized software are prevented

arcate:compliance:requirements/nist-csf/2.0/PR.PS-05 · row 120 of sheet 'CSF 2.0'

PR.PS-06

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

arcate:compliance:requirements/nist-csf/2.0/PR.PS-06 · row 121 of sheet 'CSF 2.0'

PR.IR — Technology Infrastructure Resilience

Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience

arcate:compliance:requirements/nist-csf/2.0/PR.IR · row 122 of sheet 'CSF 2.0'

PR.IR-01

Networks and environments are protected from unauthorized logical access and usage

arcate:compliance:requirements/nist-csf/2.0/PR.IR-01 · row 123 of sheet 'CSF 2.0'

PR.IR-02

The organization's technology assets are protected from environmental threats

arcate:compliance:requirements/nist-csf/2.0/PR.IR-02 · row 124 of sheet 'CSF 2.0'