NIST

NIST Cybersecurity Framework (CSF) 2.0

2.0

Publié par NIST
Version 2.0
Date de publication 2024-02-26
Langue en
Exigences 225
Document source csf.xlsx
Clé de plateforme arcate:compliance:frameworks/nist-csf/2.0

Exigences

RS.AN-07

Incident data and metadata are collected, and their integrity and provenance are preserved

arcate:compliance:requirements/nist-csf/2.0/RS.AN-07 · row 199 of sheet 'CSF 2.0'

RS.AN-08

An incident's magnitude is estimated and validated

arcate:compliance:requirements/nist-csf/2.0/RS.AN-08 · row 200 of sheet 'CSF 2.0'

RS.CO — Incident Response Reporting and Communication

Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies

arcate:compliance:requirements/nist-csf/2.0/RS.CO · row 201 of sheet 'CSF 2.0'

RS.CO-01

[Withdrawn: Incorporated into PR.AT-01]

arcate:compliance:requirements/nist-csf/2.0/RS.CO-01 · row 202 of sheet 'CSF 2.0'

RS.CO-02

Internal and external stakeholders are notified of incidents

arcate:compliance:requirements/nist-csf/2.0/RS.CO-02 · row 203 of sheet 'CSF 2.0'

RS.CO-03

Information is shared with designated internal and external stakeholders

arcate:compliance:requirements/nist-csf/2.0/RS.CO-03 · row 204 of sheet 'CSF 2.0'

RS.CO-04

[Withdrawn: Incorporated into RS.MA-01, RS.MA-04]

arcate:compliance:requirements/nist-csf/2.0/RS.CO-04 · row 205 of sheet 'CSF 2.0'

RS.CO-05

[Withdrawn: Incorporated into RS.CO-03]

arcate:compliance:requirements/nist-csf/2.0/RS.CO-05 · row 206 of sheet 'CSF 2.0'

RS.MI — Incident Mitigation

Activities are performed to prevent expansion of an event and mitigate its effects

arcate:compliance:requirements/nist-csf/2.0/RS.MI · row 207 of sheet 'CSF 2.0'

RS.MI-01

Incidents are contained

arcate:compliance:requirements/nist-csf/2.0/RS.MI-01 · row 208 of sheet 'CSF 2.0'

RS.MI-02

Incidents are eradicated

arcate:compliance:requirements/nist-csf/2.0/RS.MI-02 · row 209 of sheet 'CSF 2.0'

RS.MI-03

[Withdrawn: Incorporated into ID.RA-06]

arcate:compliance:requirements/nist-csf/2.0/RS.MI-03 · row 210 of sheet 'CSF 2.0'

RS.RP — Response Planning

[Withdrawn: Incorporated into RS.MA]

arcate:compliance:requirements/nist-csf/2.0/RS.RP · row 211 of sheet 'CSF 2.0'

RS.RP-01

[Withdrawn: Incorporated into RS.MA-01]

arcate:compliance:requirements/nist-csf/2.0/RS.RP-01 · row 212 of sheet 'CSF 2.0'

RS.IM — Improvements

[Withdrawn: Incorporated into ID.IM]

arcate:compliance:requirements/nist-csf/2.0/RS.IM · row 213 of sheet 'CSF 2.0'

RS.IM-01

[Withdrawn: Incorporated into ID.IM-03, ID.IM-04]

arcate:compliance:requirements/nist-csf/2.0/RS.IM-01 · row 214 of sheet 'CSF 2.0'

RS.IM-02

[Withdrawn: Incorporated into ID.IM-03]

arcate:compliance:requirements/nist-csf/2.0/RS.IM-02 · row 215 of sheet 'CSF 2.0'

RC — RECOVER

Assets and operations affected by a cybersecurity incident are restored

arcate:compliance:requirements/nist-csf/2.0/RC · row 217 of sheet 'CSF 2.0'

RC.RP — Incident Recovery Plan Execution

Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents

arcate:compliance:requirements/nist-csf/2.0/RC.RP · row 218 of sheet 'CSF 2.0'

RC.RP-01

The recovery portion of the incident response plan is executed once initiated from the incident response process

arcate:compliance:requirements/nist-csf/2.0/RC.RP-01 · row 219 of sheet 'CSF 2.0'

RC.RP-02

Recovery actions are selected, scoped, prioritized, and performed

arcate:compliance:requirements/nist-csf/2.0/RC.RP-02 · row 220 of sheet 'CSF 2.0'

RC.RP-03

The integrity of backups and other restoration assets is verified before using them for restoration

arcate:compliance:requirements/nist-csf/2.0/RC.RP-03 · row 221 of sheet 'CSF 2.0'

RC.RP-04

Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms

arcate:compliance:requirements/nist-csf/2.0/RC.RP-04 · row 222 of sheet 'CSF 2.0'

RC.RP-05

The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

arcate:compliance:requirements/nist-csf/2.0/RC.RP-05 · row 223 of sheet 'CSF 2.0'