NIST Cybersecurity Framework 2.0
Version: 2.0 (February 2024)
A voluntary NIST framework of cybersecurity outcomes organized into six Functions (Govern, Identify, Protect, Detect, Respond, Recover) that any organization, regardless of size or sector, can use to understand, assess and prioritize its cybersecurity risk.
Where we stand
Controls
75%
Evidence
9%
Policies
10%
92 of 106 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| GV.OC Organizational Context | |||||
| GV.OC-01 | Mission informs risk management Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| GV.OC-02 | Stakeholder expectations understood Controls: CUST-02 | Passing | Not current | Approved | Not yet |
| GV.OC-03 | Legal and contractual obligations managed Controls: CUST-02 | Passing | Not current | Approved | Not yet |
| GV.OC-04 | Critical services to others identified Controls: BIZ-01, IT-05 | Passing | Not current | Not approved | (3 mo ago) |
| GV.OC-05 | Dependencies of the organization identified Controls: BIZ-01, VEND-01 | Passing | Not current | Not approved | (3 mo ago) |
| GV.RM Risk Management Strategy | |||||
| GV.RM-01 | Risk management objectives agreed Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| GV.RM-02 | Risk appetite and tolerance stated Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| GV.RM-03 | Cyber risk in enterprise risk management Controls: BIZ-04, BIZ-05, BIZ-12 | Passing | Not current | Not approved | (4 mo ago) |
| GV.RM-04 | Risk response direction set Controls: BIZ-04, BIZ-07 | Passing | Not current | Not approved | Not yet |
| GV.RM-05 | Risk communication lines established Controls: BIZ-12 | Passing | Not current | Approved | Not yet |
| GV.RM-06 | Standard risk calculation method Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| GV.RM-07 | Positive risks considered | Unmapped | Unmapped | Unmapped | Not yet |
| GV.RR Roles, Responsibilities, and Authorities | |||||
| GV.RR-01 | Leadership accountable for cyber risk Controls: BIZ-11, BIZ-12, BIZ-14 | Passing | Not current | Not approved | Not yet |
| GV.RR-02 | Cyber roles defined and enforced Controls: BIZ-15, PEOPLE-08, PEOPLE-09 | Not passing | Not current | Not approved | Not yet |
| GV.RR-03 | Adequate resources allocated | Unmapped | Unmapped | Unmapped | Not yet |
| GV.RR-04 | Cybersecurity in HR practices Controls: PEOPLE-01, PEOPLE-02, PEOPLE-03, PEOPLE-05, PEOPLE-07 | Not passing | Not current | Not approved | (8 h ago) |
| GV.PO Policy | |||||
| GV.PO-01 | Cybersecurity policy established Controls: BIZ-14, IT-01, PEOPLE-04 | Passing | Not current | Not approved | (4 mo ago) |
| GV.PO-02 | Policy reviewed and updated Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| GV.OV Oversight | |||||
| GV.OV-01 | Strategy outcomes reviewed Controls: BIZ-12 | Passing | Not current | Approved | Not yet |
| GV.OV-02 | Strategy coverage reviewed | Unmapped | Unmapped | Unmapped | Not yet |
| GV.OV-03 | Risk management performance evaluated Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| GV.SC Cybersecurity Supply Chain Risk Management | |||||
| GV.SC-01 | Supply chain risk program established Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| GV.SC-02 | Third-party cyber roles defined Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| GV.SC-03 | Supply chain risk integrated Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| GV.SC-04 | Suppliers known and prioritized Controls: VEND-01, VEND-03 | Passing | Not current | Not approved | Not yet |
| GV.SC-05 | Security requirements in supplier contracts Controls: VEND-02 | Passing | Not current | Not approved | Not yet |
| GV.SC-06 | Supplier due diligence before engagement Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| GV.SC-07 | Supplier risk managed through relationship Controls: VEND-04 | Not passing | Current | Not approved | (8 h ago) |
| GV.SC-08 | Suppliers in incident activities Controls: BIZ-02, VEND-02 | Passing | Not current | Not approved | (3 mo ago) |
| GV.SC-09 | Supply chain practices monitored Controls: VEND-04 | Not passing | Current | Not approved | (8 h ago) |
| GV.SC-10 | Post-relationship provisions planned | Unmapped | Unmapped | Unmapped | Not yet |
| ID.AM Asset Management | |||||
| ID.AM-01 | Hardware inventory maintained Controls: IT-04 | Passing | Not current | Not approved | Not yet |
| ID.AM-02 | Software and services inventory maintained Controls: IT-05 | Passing | Not current | Not approved | Not yet |
| ID.AM-03 | Network and data flows documented | Unmapped | Unmapped | Unmapped | Not yet |
| ID.AM-04 | Supplier services inventory maintained Controls: VEND-01 | Passing | Not current | Not approved | Not yet |
| ID.AM-05 | Assets prioritized Controls: BIZ-01, DATA-01, IT-05 | Passing | Not current | Not approved | (3 mo ago) |
| ID.AM-07 | Data inventory maintained Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| ID.AM-08 | Asset life cycle managed Controls: IT-04, PEOPLE-03 | Passing | Not current | Not approved | (8 h ago) |
| ID.RA Risk Assessment | |||||
| ID.RA-01 | Vulnerabilities identified Controls: APP-02, MON-04, MON-05 | Not passing | Not current | Not approved | (8 h ago) |
| ID.RA-02 | Threat intelligence received | Unmapped | Unmapped | Unmapped | Not yet |
| ID.RA-03 | Threats identified Controls: BIZ-04, BIZ-06 | Passing | Not current | Not approved | (4 mo ago) |
| ID.RA-04 | Impact and likelihood assessed Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| ID.RA-05 | Inherent risk determined Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| ID.RA-06 | Risk responses planned and tracked Controls: BIZ-05, BIZ-09, MON-06 | Not passing | Not current | Not approved | (3 mo ago) |
| ID.RA-07 | Changes and exceptions risk-assessed Controls: BIZ-05, PDP-02, PDP-14 | Passing | Not current | Not approved | (23 d ago) |
| ID.RA-08 | Vulnerability disclosure process Controls: CUST-01, MON-06 | Not passing | Not current | Not approved | (3 mo ago) |
| ID.RA-09 | Hardware and software integrity checked | Unmapped | Unmapped | Unmapped | Not yet |
| ID.RA-10 | Critical suppliers assessed Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| ID.IM Improvement | |||||
| ID.IM-01 | Improvements from evaluations Controls: BIZ-08, BIZ-09 | Passing | Not current | Approved | Not yet |
| ID.IM-02 | Improvements from tests and exercises Controls: BIZ-09, BIZ-20, BIZ-21, MON-04 | Not passing | Not current | Not approved | (8 h ago) |
| ID.IM-03 | Improvements from operations Controls: BIZ-03, BIZ-09 | Passing | Not current | Not approved | (8 h ago) |
| ID.IM-04 | Incident response plans maintained Controls: BIZ-01, BIZ-02, BIZ-21 | Passing | Not current | Not approved | (3 mo ago) |
| PR.AA Identity Management, Authentication, and Access Control | |||||
| PR.AA-01 | Identities and credentials managed Controls: IAM-01, IAM-03, IAM-07 | Not passing | Current | Not approved | (29 d ago) |
| PR.AA-02 | Identity proofing Controls: PEOPLE-01 | Not passing | Current | Not approved | (4 mo ago) |
| PR.AA-03 | Authentication enforced Controls: IAM-02, IAM-08 | Not passing | Not current | Not approved | (8 h ago) |
| PR.AA-04 | Identity assertions protected Controls: IAM-01 | Passing | Current | Not approved | (29 d ago) |
| PR.AA-05 | Least privilege access managed Controls: IAM-04, IAM-05, IAM-06, IAM-09 | Passing | Not current | Not approved | (29 d ago) |
| PR.AA-06 | Physical access managed Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| PR.AT Awareness and Training | |||||
| PR.AT-01 | General awareness training Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| PR.AT-02 | Specialized role training Controls: APP-01 | Passing | Current | Approved | (4 mo ago) |
| PR.DS Data Security | |||||
| PR.DS-01 | Data at rest protected Controls: DATA-02, DATA-06, IT-02 | Not passing | Not current | Not approved | Not yet |
| PR.DS-02 | Data in transit protected Controls: CLOUD-01, DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| PR.DS-10 | Data in use protected | Unmapped | Unmapped | Unmapped | Not yet |
| PR.DS-11 | Backups created and tested Controls: DATA-12, DATA-13, DATA-14, DATA-15 | Passing | Not current | Not approved | (29 d ago) |
| PR.PS Platform Security | |||||
| PR.PS-01 | Configuration management applied Controls: CLOUD-02, CLOUD-04 | Passing | Not current | Approved | (29 d ago) |
| PR.PS-02 | Software maintained and retired Controls: CLOUD-05, IT-03, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| PR.PS-03 | Hardware maintained and retired | Unmapped | Unmapped | Unmapped | Not yet |
| PR.PS-04 | Logs generated for monitoring Controls: MON-01, MON-02 | Not passing | Not current | Not approved | (3 mo ago) |
| PR.PS-05 | Unauthorized software prevented | Unmapped | Unmapped | Unmapped | Not yet |
| PR.PS-06 | Secure software development Controls: APP-01, APP-02, PDP-03, PDP-04 | Not passing | Not current | Not approved | (8 h ago) |
| PR.IR Technology Infrastructure Resilience | |||||
| PR.IR-01 | Networks protected from unauthorized access Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| PR.IR-02 | Protection from environmental threats Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| PR.IR-03 | Resilience mechanisms implemented Controls: BIZ-01, DATA-13 | Passing | Not current | Not approved | (29 d ago) |
| PR.IR-04 | Adequate capacity maintained | Unmapped | Unmapped | Unmapped | Not yet |
| DE.CM Continuous Monitoring | |||||
| DE.CM-01 | Networks monitored Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| DE.CM-02 | Physical environment monitored Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| DE.CM-03 | Personnel and technology use monitored Controls: MON-02, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| DE.CM-06 | External providers monitored Controls: MON-03, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
| DE.CM-09 | Systems and runtime monitored | Unmapped | Unmapped | Unmapped | Not yet |
| DE.AE Adverse Event Analysis | |||||
| DE.AE-02 | Adverse events analyzed Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| DE.AE-03 | Information correlated Controls: MON-01 | Not passing | Not current | Not approved | (3 mo ago) |
| DE.AE-04 | Impact and scope estimated Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| DE.AE-06 | Event information shared internally Controls: BIZ-02, BIZ-13, MON-03 | Not passing | Not current | Not approved | (29 d ago) |
| DE.AE-07 | Threat intelligence used in analysis | Unmapped | Unmapped | Unmapped | Not yet |
| DE.AE-08 | Incidents declared by criteria Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RS.MA Incident Management | |||||
| RS.MA-01 | Incident response plan executed Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RS.MA-02 | Incident reports triaged Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| RS.MA-03 | Incidents categorized and prioritized Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| RS.MA-04 | Incidents escalated Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RS.MA-05 | Recovery initiation criteria applied Controls: BIZ-01, BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RS.AN Incident Analysis | |||||
| RS.AN-03 | Root cause analysis Controls: BIZ-03, BIZ-09 | Passing | Not current | Not approved | (8 h ago) |
| RS.AN-06 | Investigation actions recorded Controls: BIZ-03 | Passing | Current | Not approved | (8 h ago) |
| RS.AN-07 | Incident data preserved Controls: BIZ-03 | Passing | Current | Not approved | (8 h ago) |
| RS.AN-08 | Incident magnitude estimated Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| RS.CO Incident Response Reporting and Communication | |||||
| RS.CO-02 | Stakeholders notified of incidents Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RS.CO-03 | Incident information shared Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RS.MI Incident Mitigation | |||||
| RS.MI-01 | Incidents contained Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RS.MI-02 | Incidents eradicated Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RC.RP Incident Recovery Plan Execution | |||||
| RC.RP-01 | Recovery plan executed Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| RC.RP-02 | Recovery actions prioritized Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| RC.RP-03 | Backup integrity verified Controls: DATA-15 | Passing | Not current | Not approved | Not yet |
| RC.RP-04 | Post-incident operating norms set Controls: BIZ-01, BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| RC.RP-05 | Restored assets verified Controls: BIZ-01, DATA-15 | Passing | Not current | Not approved | (3 mo ago) |
| RC.RP-06 | Recovery end declared Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| RC.CO Incident Recovery Communication | |||||
| RC.CO-03 | Recovery progress communicated Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| RC.CO-04 | Public recovery updates | Unmapped | Unmapped | Unmapped | Not yet |
