FintastIQTrust Center
LoginBook a Consultation
Framework

NIST Cybersecurity Framework 2.0

Version: 2.0 (February 2024)

A voluntary NIST framework of cybersecurity outcomes organized into six Functions (Govern, Identify, Protect, Detect, Respond, Recover) that any organization, regardless of size or sector, can use to understand, assess and prioritize its cybersecurity risk.

Official source

Summary

Where we stand

Controls
75%
Evidence
9%
Policies
10%

92 of 106 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
GV.OC Organizational Context
GV.OC-01Mission informs risk management
Controls: BIZ-04
PassingNot currentNot approvedNot yet
GV.OC-02Stakeholder expectations understood
Controls: CUST-02
PassingNot currentApprovedNot yet
GV.OC-03Legal and contractual obligations managed
Controls: CUST-02
PassingNot currentApprovedNot yet
GV.OC-04Critical services to others identified
Controls: BIZ-01, IT-05
PassingNot currentNot approved(3 mo ago)
GV.OC-05Dependencies of the organization identified
Controls: BIZ-01, VEND-01
PassingNot currentNot approved(3 mo ago)
GV.RM Risk Management Strategy
GV.RM-01Risk management objectives agreed
Controls: BIZ-04
PassingNot currentNot approvedNot yet
GV.RM-02Risk appetite and tolerance stated
Controls: BIZ-04
PassingNot currentNot approvedNot yet
GV.RM-03Cyber risk in enterprise risk management
Controls: BIZ-04, BIZ-05, BIZ-12
PassingNot currentNot approved(4 mo ago)
GV.RM-04Risk response direction set
Controls: BIZ-04, BIZ-07
PassingNot currentNot approvedNot yet
GV.RM-05Risk communication lines established
Controls: BIZ-12
PassingNot currentApprovedNot yet
GV.RM-06Standard risk calculation method
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
GV.RM-07Positive risks consideredUnmappedUnmappedUnmappedNot yet
GV.RR Roles, Responsibilities, and Authorities
GV.RR-01Leadership accountable for cyber risk
Controls: BIZ-11, BIZ-12, BIZ-14
PassingNot currentNot approvedNot yet
GV.RR-02Cyber roles defined and enforced
Controls: BIZ-15, PEOPLE-08, PEOPLE-09
Not passingNot currentNot approvedNot yet
GV.RR-03Adequate resources allocatedUnmappedUnmappedUnmappedNot yet
GV.RR-04Cybersecurity in HR practices
Controls: PEOPLE-01, PEOPLE-02, PEOPLE-03, PEOPLE-05, PEOPLE-07
Not passingNot currentNot approved(8 h ago)
GV.PO Policy
GV.PO-01Cybersecurity policy established
Controls: BIZ-14, IT-01, PEOPLE-04
PassingNot currentNot approved(4 mo ago)
GV.PO-02Policy reviewed and updated
Controls: BIZ-14
PassingNot currentNot approvedNot yet
GV.OV Oversight
GV.OV-01Strategy outcomes reviewed
Controls: BIZ-12
PassingNot currentApprovedNot yet
GV.OV-02Strategy coverage reviewedUnmappedUnmappedUnmappedNot yet
GV.OV-03Risk management performance evaluated
Controls: BIZ-08
PassingNot currentApprovedNot yet
GV.SC Cybersecurity Supply Chain Risk Management
GV.SC-01Supply chain risk program established
Controls: VEND-03
PassingNot currentNot approvedNot yet
GV.SC-02Third-party cyber roles defined
Controls: BIZ-15
PassingNot currentNot approvedNot yet
GV.SC-03Supply chain risk integrated
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
GV.SC-04Suppliers known and prioritized
Controls: VEND-01, VEND-03
PassingNot currentNot approvedNot yet
GV.SC-05Security requirements in supplier contracts
Controls: VEND-02
PassingNot currentNot approvedNot yet
GV.SC-06Supplier due diligence before engagement
Controls: VEND-03
PassingNot currentNot approvedNot yet
GV.SC-07Supplier risk managed through relationship
Controls: VEND-04
Not passingCurrentNot approved(8 h ago)
GV.SC-08Suppliers in incident activities
Controls: BIZ-02, VEND-02
PassingNot currentNot approved(3 mo ago)
GV.SC-09Supply chain practices monitored
Controls: VEND-04
Not passingCurrentNot approved(8 h ago)
GV.SC-10Post-relationship provisions plannedUnmappedUnmappedUnmappedNot yet
ID.AM Asset Management
ID.AM-01Hardware inventory maintained
Controls: IT-04
PassingNot currentNot approvedNot yet
ID.AM-02Software and services inventory maintained
Controls: IT-05
PassingNot currentNot approvedNot yet
ID.AM-03Network and data flows documentedUnmappedUnmappedUnmappedNot yet
ID.AM-04Supplier services inventory maintained
Controls: VEND-01
PassingNot currentNot approvedNot yet
ID.AM-05Assets prioritized
Controls: BIZ-01, DATA-01, IT-05
PassingNot currentNot approved(3 mo ago)
ID.AM-07Data inventory maintained
Controls: DATA-01
PassingNot currentNot approvedNot yet
ID.AM-08Asset life cycle managed
Controls: IT-04, PEOPLE-03
PassingNot currentNot approved(8 h ago)
ID.RA Risk Assessment
ID.RA-01Vulnerabilities identified
Controls: APP-02, MON-04, MON-05
Not passingNot currentNot approved(8 h ago)
ID.RA-02Threat intelligence receivedUnmappedUnmappedUnmappedNot yet
ID.RA-03Threats identified
Controls: BIZ-04, BIZ-06
PassingNot currentNot approved(4 mo ago)
ID.RA-04Impact and likelihood assessed
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
ID.RA-05Inherent risk determined
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
ID.RA-06Risk responses planned and tracked
Controls: BIZ-05, BIZ-09, MON-06
Not passingNot currentNot approved(3 mo ago)
ID.RA-07Changes and exceptions risk-assessed
Controls: BIZ-05, PDP-02, PDP-14
PassingNot currentNot approved(23 d ago)
ID.RA-08Vulnerability disclosure process
Controls: CUST-01, MON-06
Not passingNot currentNot approved(3 mo ago)
ID.RA-09Hardware and software integrity checkedUnmappedUnmappedUnmappedNot yet
ID.RA-10Critical suppliers assessed
Controls: VEND-03
PassingNot currentNot approvedNot yet
ID.IM Improvement
ID.IM-01Improvements from evaluations
Controls: BIZ-08, BIZ-09
PassingNot currentApprovedNot yet
ID.IM-02Improvements from tests and exercises
Controls: BIZ-09, BIZ-20, BIZ-21, MON-04
Not passingNot currentNot approved(8 h ago)
ID.IM-03Improvements from operations
Controls: BIZ-03, BIZ-09
PassingNot currentNot approved(8 h ago)
ID.IM-04Incident response plans maintained
Controls: BIZ-01, BIZ-02, BIZ-21
PassingNot currentNot approved(3 mo ago)
PR.AA Identity Management, Authentication, and Access Control
PR.AA-01Identities and credentials managed
Controls: IAM-01, IAM-03, IAM-07
Not passingCurrentNot approved(29 d ago)
PR.AA-02Identity proofing
Controls: PEOPLE-01
Not passingCurrentNot approved(4 mo ago)
PR.AA-03Authentication enforced
Controls: IAM-02, IAM-08
Not passingNot currentNot approved(8 h ago)
PR.AA-04Identity assertions protected
Controls: IAM-01
PassingCurrentNot approved(29 d ago)
PR.AA-05Least privilege access managed
Controls: IAM-04, IAM-05, IAM-06, IAM-09
PassingNot currentNot approved(29 d ago)
PR.AA-06Physical access managed
Controls: PHYS-01
PassingNot currentNot approvedNot yet
PR.AT Awareness and Training
PR.AT-01General awareness training
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
PR.AT-02Specialized role training
Controls: APP-01
PassingCurrentApproved(4 mo ago)
PR.DS Data Security
PR.DS-01Data at rest protected
Controls: DATA-02, DATA-06, IT-02
Not passingNot currentNot approvedNot yet
PR.DS-02Data in transit protected
Controls: CLOUD-01, DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
PR.DS-10Data in use protectedUnmappedUnmappedUnmappedNot yet
PR.DS-11Backups created and tested
Controls: DATA-12, DATA-13, DATA-14, DATA-15
PassingNot currentNot approved(29 d ago)
PR.PS Platform Security
PR.PS-01Configuration management applied
Controls: CLOUD-02, CLOUD-04
PassingNot currentApproved(29 d ago)
PR.PS-02Software maintained and retired
Controls: CLOUD-05, IT-03, MON-06
Not passingNot currentNot approved(8 h ago)
PR.PS-03Hardware maintained and retiredUnmappedUnmappedUnmappedNot yet
PR.PS-04Logs generated for monitoring
Controls: MON-01, MON-02
Not passingNot currentNot approved(3 mo ago)
PR.PS-05Unauthorized software preventedUnmappedUnmappedUnmappedNot yet
PR.PS-06Secure software development
Controls: APP-01, APP-02, PDP-03, PDP-04
Not passingNot currentNot approved(8 h ago)
PR.IR Technology Infrastructure Resilience
PR.IR-01Networks protected from unauthorized access
Controls: CLOUD-03
PassingNot currentApprovedNot yet
PR.IR-02Protection from environmental threats
Controls: PHYS-01
PassingNot currentNot approvedNot yet
PR.IR-03Resilience mechanisms implemented
Controls: BIZ-01, DATA-13
PassingNot currentNot approved(29 d ago)
PR.IR-04Adequate capacity maintainedUnmappedUnmappedUnmappedNot yet
DE.CM Continuous Monitoring
DE.CM-01Networks monitored
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
DE.CM-02Physical environment monitored
Controls: PHYS-01
PassingNot currentNot approvedNot yet
DE.CM-03Personnel and technology use monitored
Controls: MON-02, MON-03
Not passingNot currentNot approved(3 mo ago)
DE.CM-06External providers monitored
Controls: MON-03, VEND-04
Not passingNot currentNot approved(8 h ago)
DE.CM-09Systems and runtime monitoredUnmappedUnmappedUnmappedNot yet
DE.AE Adverse Event Analysis
DE.AE-02Adverse events analyzed
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
DE.AE-03Information correlated
Controls: MON-01
Not passingNot currentNot approved(3 mo ago)
DE.AE-04Impact and scope estimated
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
DE.AE-06Event information shared internally
Controls: BIZ-02, BIZ-13, MON-03
Not passingNot currentNot approved(29 d ago)
DE.AE-07Threat intelligence used in analysisUnmappedUnmappedUnmappedNot yet
DE.AE-08Incidents declared by criteria
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
RS.MA Incident Management
RS.MA-01Incident response plan executed
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
RS.MA-02Incident reports triaged
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
RS.MA-03Incidents categorized and prioritized
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
RS.MA-04Incidents escalated
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
RS.MA-05Recovery initiation criteria applied
Controls: BIZ-01, BIZ-02
PassingNot currentNot approved(3 mo ago)
RS.AN Incident Analysis
RS.AN-03Root cause analysis
Controls: BIZ-03, BIZ-09
PassingNot currentNot approved(8 h ago)
RS.AN-06Investigation actions recorded
Controls: BIZ-03
PassingCurrentNot approved(8 h ago)
RS.AN-07Incident data preserved
Controls: BIZ-03
PassingCurrentNot approved(8 h ago)
RS.AN-08Incident magnitude estimated
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
RS.CO Incident Response Reporting and Communication
RS.CO-02Stakeholders notified of incidents
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
RS.CO-03Incident information shared
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
RS.MI Incident Mitigation
RS.MI-01Incidents contained
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
RS.MI-02Incidents eradicated
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
RC.RP Incident Recovery Plan Execution
RC.RP-01Recovery plan executed
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
RC.RP-02Recovery actions prioritized
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
RC.RP-03Backup integrity verified
Controls: DATA-15
PassingNot currentNot approvedNot yet
RC.RP-04Post-incident operating norms set
Controls: BIZ-01, BIZ-02
PassingNot currentNot approved(3 mo ago)
RC.RP-05Restored assets verified
Controls: BIZ-01, DATA-15
PassingNot currentNot approved(3 mo ago)
RC.RP-06Recovery end declared
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
RC.CO Incident Recovery Communication
RC.CO-03Recovery progress communicated
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
RC.CO-04Public recovery updatesUnmappedUnmappedUnmappedNot yet