NIST Cybersecurity Framework 2.0
Voluntary guidance for managing and reducing cybersecurity risk. Organized around five core functions: Identify, Protect, Detect, Respond, Recover.
AC (17) AT (5) AU (11) CA (8) CM (14) CP (8) IA (13) IR (8) MA (3) MP (5) PE (18) PL (5) PM (24) PS (9) PT (1) RA (8) SA (13) SC (22) SI (11) SR (11)
AC Access Control
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| AC-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03PR.AA-01PR.AA-05 |
| AC-02 | Account Management | DE.CM-01DE.CM-03PR.AA-01PR.AA-05PR.DS-10 |
| AC-03 | Access Enforcement | PR.AA-05PR.DS-01PR.DS-10PR.IR-01 |
| AC-04 | Information Flow Enforcement | DE.CM-09ID.AM-03PR.DS-10PR.IR-01 |
| AC-05 | Separation of Duties | PR.AA-05 |
| AC-06 | Least Privilege | PR.AA-05 |
| AC-07 | Unsuccessful Logon Attempts | PR.AA-03 |
| AC-09 | Previous Logon Notification | DE.CM-09 |
| AC-10 | Concurrent Session Control | PR.AA-05 |
| AC-12 | Session Termination | PR.AA-03 |
| AC-14 | Permitted Actions Without Identification or Authentication | PR.AA-01 |
| AC-16 | Security and Privacy Attributes | PR.AA-05 |
| AC-17 | Remote Access | PR.AA-05PR.DS-02PR.IR-01 |
| AC-18 | Wireless Access | PR.AA-05 |
| AC-19 | Access Control for Mobile Devices | PR.AA-05 |
| AC-20 | Use of External Systems | ID.AM-02ID.AM-04 |
| AC-24 | Access Control Decisions | PR.AA-05 |
AT Awareness and Training
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| AT-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.RR-04GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| AT-02 | Literacy Training and Awareness | GV.RR-01GV.RR-04PR.AT-01 |
| AT-03 | Role-based Training | GV.RR-04PR.AT-01PR.AT-02 |
| AT-04 | Training Records | GV.RR-04 |
| AT-06 | Training Feedback | ID.IM-03PR.AT-01PR.AT-02 |
AU Audit and Accountability
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| AU-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| AU-02 | Event Logging | PR.PS-04 |
| AU-03 | Content of Audit Records | PR.PS-04RS.AN-07 |
| AU-04 | Audit Log Storage Capacity | PR.IR-04 |
| AU-06 | Audit Record Review, Analysis, and Reporting | DE.AE-02DE.AE-03DE.AE-04DE.AE-06DE.CM-01DE.CM-03DE.CM-09PR.PS-04RS.AN-03 |
| AU-07 | Audit Record Reduction and Report Generation | PR.PS-04RS.AN-03RS.AN-06RS.AN-07 |
| AU-09 | Protection of Audit Information | PR.DS-10RS.AN-06RS.AN-07 |
| AU-11 | Audit Record Retention | PR.PS-04RS.AN-06RS.AN-07 |
| AU-12 | Audit Record Generation | DE.CM-01DE.CM-03DE.CM-09PR.PS-04 |
| AU-13 | Monitoring for Information Disclosure | DE.CM-03PR.DS-10 |
| AU-16 | Cross-organizational Audit Logging | PR.DS-02 |
CA Security Assessment and Authorization
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| CA-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| CA-02 | Control Assessments | GV.OV-02GV.OV-03ID.IM-01ID.IM-02ID.IM-03ID.RA-01 |
| CA-03 | Information Exchange | ID.AM-03PR.DS-01PR.DS-02PR.DS-10 |
| CA-05 | Plan of Action and Milestones | GV.RM-04ID.IM-01ID.IM-02ID.IM-03ID.RA-05ID.RA-06 |
| CA-06 | Authorization | ID.RA-07 |
| CA-07 | Continuous Monitoring | DE.AE-02DE.AE-03DE.CM-01DE.CM-02DE.CM-03DE.CM-06DE.CM-09GV.OV-01GV.OV-03GV.PO-02ID.IM-01ID.IM-02ID.IM-03ID.RA-01ID.RA-07PR.PS-04RC.RP-05 |
| CA-08 | Penetration Testing | ID.IM-01ID.IM-02ID.IM-03ID.RA-01 |
| CA-09 | Internal System Connections | ID.AM-03 |
CM Configuration Management
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| CM-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03PR.PS-01 |
| CM-02 | Baseline Configuration | PR.PS-01 |
| CM-03 | Configuration Change Control | DE.CM-01DE.CM-09ID.RA-07PR.PS-01 |
| CM-04 | Impact Analyses | ID.RA-07PR.PS-01 |
| CM-05 | Access Restrictions for Change | PR.PS-01 |
| CM-06 | Configuration Settings | DE.CM-09PR.PS-01 |
| CM-07 | Least Functionality | PR.PS-01PR.PS-02PR.PS-05 |
| CM-08 | System Component Inventory | ID.AM-01ID.AM-02ID.AM-07ID.AM-08PR.PS-01PR.PS-03 |
| CM-09 | Configuration Management Plan | ID.AM-08PR.PS-01 |
| CM-10 | Software Usage Restrictions | DE.CM-03DE.CM-09ID.AM-02PR.PS-01 |
| CM-11 | User-installed Software | DE.CM-03DE.CM-09PR.PS-01PR.PS-02PR.PS-05 |
| CM-12 | Information Location | ID.AM-03ID.AM-07 |
| CM-13 | Data Action Mapping | ID.AM-07ID.AM-08 |
| CM-14 | Signed Components | PR.PS-05 |
CP Contingency Planning
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| CP-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03GV.SC-08ID.IM-01ID.IM-02ID.IM-03 |
| CP-02 | Contingency Plan | GV.OC-04GV.OC-05GV.SC-08ID.AM-05ID.IM-01ID.IM-02ID.IM-03ID.IM-04PR.IR-02PR.IR-03PR.IR-04RC.CO-03RC.CO-04RC.RP-01RC.RP-02RC.RP-03 |
| CP-04 | Contingency Plan Testing | ID.IM-02ID.IM-04RC.RP-03 |
| CP-06 | Alternate Storage Site | PR.DS-11PR.IR-04 |
| CP-07 | Alternate Processing Site | PR.IR-03PR.IR-04 |
| CP-08 | Telecommunications Services | PR.IR-03PR.IR-04 |
| CP-09 | System Backup | PR.DS-01PR.DS-10PR.DS-11PR.IR-03RC.RP-03 |
| CP-10 | System Recovery and Reconstitution | PR.IR-03RC.RP-01RC.RP-02RC.RP-04RC.RP-05RS.MA-05 |
IA Identification and Authentication
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| IA-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03PR.AA-01 |
| IA-02 | Identification and Authentication (Organizational Users) | PR.AA-01PR.AA-03PR.AA-04 |
| IA-03 | Device Identification and Authentication | PR.AA-01PR.AA-03 |
| IA-04 | Identifier Management | PR.AA-01PR.AA-02 |
| IA-05 | Authenticator Management | PR.AA-01PR.AA-02PR.AA-03PR.AA-04 |
| IA-06 | Authentication Feedback | PR.AA-01 |
| IA-07 | Cryptographic Module Authentication | PR.AA-01PR.AA-03 |
| IA-08 | Identification and Authentication (Non-organizational Users) | PR.AA-01PR.AA-03PR.AA-04 |
| IA-09 | Service Identification and Authentication | PR.AA-01PR.AA-03 |
| IA-10 | Adaptive Authentication | PR.AA-01PR.AA-03 |
| IA-11 | Re-authentication | PR.AA-01PR.AA-03 |
| IA-12 | Identity Proofing | PR.AA-01PR.AA-02 |
| IA-13 | Identity Providers and Authorization Servers | PR.AA-04PR.AA-05 |
IR Incident Response
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| IR-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03GV.SC-08ID.IM-01ID.IM-02ID.IM-03RC.RP-04 |
| IR-02 | Incident Response Training | PR.AT-02 |
| IR-03 | Incident Response Testing | ID.IM-02ID.IM-04RC.RP-06 |
| IR-04 | Incident Handling | DE.AE-02DE.AE-03DE.AE-04DE.AE-06DE.AE-08GV.SC-08ID.IM-01ID.IM-02ID.IM-03RC.CO-03RC.CO-04RC.RP-01RC.RP-02RC.RP-04RC.RP-06RS.AN-03RS.AN-06RS.AN-07RS.AN-08RS.CO-02RS.CO-03RS.MA-01RS.MA-02RS.MA-03RS.MA-04RS.MA-05RS.MI-01RS.MI-02 |
| IR-05 | Incident Monitoring | DE.AE-03DE.AE-08RS.AN-08RS.MA-02RS.MA-03RS.MA-04 |
| IR-06 | Incident Reporting | DE.AE-06DE.AE-08GV.RM-05RC.CO-03RC.CO-04RS.AN-06RS.AN-07RS.CO-02RS.CO-03RS.MA-01RS.MA-02RS.MA-03RS.MA-04 |
| IR-07 | Incident Response Assistance | GV.RM-05RC.CO-03RC.CO-04RS.CO-02RS.CO-03RS.MA-01RS.MA-04 |
| IR-08 | Incident Response Plan | DE.AE-03DE.AE-08GV.SC-08ID.IM-01ID.IM-02ID.IM-03ID.IM-04RC.RP-01RC.RP-02RC.RP-04RC.RP-06RS.AN-08RS.MA-01RS.MA-05 |
MA Maintenance
MP Media Protection
PE Physical and Environmental Protection
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| PE-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| PE-02 | Physical Access Authorizations | PR.AA-06 |
| PE-03 | Physical Access Control | DE.CM-02PR.AA-06 |
| PE-04 | Access Control for Transmission | PR.AA-06 |
| PE-05 | Access Control for Output Devices | PR.AA-06 |
| PE-06 | Monitoring Physical Access | DE.CM-02PR.AA-06 |
| PE-08 | Visitor Access Records | PR.AA-06 |
| PE-09 | Power Equipment and Cabling | PR.IR-02 |
| PE-10 | Emergency Shutoff | PR.IR-02 |
| PE-11 | Emergency Power | PR.IR-02PR.IR-04 |
| PE-12 | Emergency Lighting | PR.IR-02 |
| PE-13 | Fire Protection | PR.IR-02 |
| PE-14 | Environmental Controls | PR.IR-02 |
| PE-15 | Water Damage Protection | PR.IR-02 |
| PE-18 | Location of System Components | PR.AA-06PR.IR-02 |
| PE-19 | Information Leakage | PR.AA-06 |
| PE-20 | Asset Monitoring and Tracking | DE.CM-02PR.AA-06 |
| PE-23 | Facility Location | PR.IR-02 |
PL Planning
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| PL-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.RR-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| PL-02 | System Security and Privacy Plans | GV.PO-01ID.AM-03ID.AM-08ID.IM-01ID.IM-02ID.IM-03ID.IM-04 |
| PL-04 | Rules of Behavior | GV.OC-03 |
| PL-08 | Security and Privacy Architectures | ID.AM-03 |
| PL-09 | Central Management | DE.AE-03PR.PS-01 |
PM Program Management
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| PM-01 | Information Security Program Plan | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.RM-03GV.RR-01GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| PM-02 | Information Security Program Leadership Role | GV.RR-01GV.RR-02 |
| PM-03 | Information Security and Privacy Resources | GV.RM-03GV.RR-03PR.IR-04 |
| PM-04 | Plan of Action and Milestones Process | GV.OV-03GV.PO-02ID.IM-01ID.IM-02ID.IM-03ID.RA-06 |
| PM-05 | System Inventory | ID.AM-01ID.AM-02ID.AM-04 |
| PM-06 | Measures of Performance | GV.OV-01GV.OV-03ID.IM-01ID.IM-03 |
| PM-07 | Enterprise Architecture | GV.OC-01ID.AM-03ID.AM-05 |
| PM-08 | Critical Infrastructure Plan | GV.OC-01GV.OC-02GV.OC-04GV.OC-05RC.RP-04 |
| PM-09 | Risk Management Strategy | DE.AE-04GV.OC-02GV.OV-01GV.OV-02GV.PO-01GV.RM-01GV.RM-02GV.RM-03GV.RM-04GV.RM-05GV.RM-06GV.RM-07GV.SC-03GV.SC-09ID.RA-04ID.RA-05ID.RA-06ID.RA-07PR.IR-04RC.RP-04 |
| PM-11 | Mission and Business Process Definition | DE.AE-04GV.OC-01GV.OC-02GV.OC-04GV.OC-05ID.AM-05ID.RA-04RC.RP-04 |
| PM-12 | Insider Threat Program | ID.RA-03 |
| PM-13 | Security and Privacy Workforce | GV.RR-01GV.RR-02GV.RR-03GV.RR-04PR.AT-01PR.AT-02 |
| PM-14 | Testing, Training, and Monitoring | GV.OV-03ID.IM-02 |
| PM-15 | Security and Privacy Groups and Associations | DE.AE-06GV.OC-02GV.RM-05ID.RA-02ID.RA-08RS.CO-03 |
| PM-16 | Threat Awareness Program | DE.AE-03DE.AE-06DE.AE-07GV.RM-05ID.RA-02ID.RA-03ID.RA-05RS.CO-03 |
| PM-18 | Privacy Program Plan | DE.AE-04GV.OC-02GV.OV-01GV.RM-06GV.RM-07GV.SC-03ID.RA-06 |
| PM-19 | Privacy Program Leadership Role | GV.OV-02GV.RR-01GV.RR-02GV.SC-09 |
| PM-22 | Personally Identifiable Information Quality Management | ID.AM-08 |
| PM-23 | Data Governance Body | GV.RR-01GV.RR-02ID.AM-08 |
| PM-24 | Data Integrity Board | GV.RR-01GV.RR-02 |
| PM-28 | Risk Framing | DE.AE-04GV.OC-03GV.OV-02GV.RM-01GV.RM-02GV.RM-03GV.RM-04GV.RM-06GV.RM-07GV.SC-09 |
| PM-29 | Risk Management Program Leadership Roles | GV.RR-01GV.RR-02 |
| PM-30 | Supply Chain Risk Management Strategy | DE.AE-04GV.OC-02GV.OC-05GV.OV-01GV.OV-02GV.RM-03GV.RM-04GV.RM-05GV.RM-06GV.RM-07GV.SC-01GV.SC-03GV.SC-09ID.RA-06 |
| PM-31 | Continuous Monitoring Strategy | GV.OV-01GV.OV-02GV.SC-03GV.SC-09GV.SC-10ID.IM-02ID.IM-03 |
PS Personnel Security
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| PS-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.RR-02GV.RR-04GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| PS-02 | Position Risk Designation | GV.RR-02GV.RR-04 |
| PS-03 | Personnel Screening | GV.RR-04 |
| PS-04 | Personnel Termination | GV.RR-04 |
| PS-05 | Personnel Transfer | GV.RR-04 |
| PS-06 | Access Agreements | GV.RR-04 |
| PS-07 | External Personnel Security | DE.CM-06GV.RR-04 |
| PS-08 | Personnel Sanctions | GV.RR-04 |
| PS-09 | Position Descriptions | GV.RR-02GV.RR-04 |
PT Personally Identifiable Information Processing and Transparency
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| PT-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
RA Risk Assessment
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| RA-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.RM-01GV.RM-06GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| RA-02 | Security Categorization | GV.RM-06ID.AM-05ID.AM-07ID.RA-04ID.RA-05 |
| RA-03 | Risk Assessment | DE.AE-04DE.AE-07GV.OV-02GV.RM-04GV.RM-06GV.RM-07GV.SC-03GV.SC-07GV.SC-09GV.SC-10ID.AM-05ID.IM-01ID.IM-02ID.IM-03ID.RA-01ID.RA-03ID.RA-04ID.RA-05ID.RA-06RS.AN-08 |
| RA-05 | Vulnerability Monitoring and Scanning | GV.SC-10ID.IM-01ID.IM-02ID.IM-03ID.RA-01ID.RA-08 |
| RA-07 | Risk Response | GV.OC-05GV.OV-01GV.OV-02GV.OV-03GV.RM-01GV.RM-03GV.RM-04GV.SC-03GV.SC-07GV.SC-09GV.SC-10ID.IM-01ID.IM-02ID.IM-03ID.RA-05ID.RA-06ID.RA-07RS.AN-08 |
| RA-08 | Privacy Impact Assessments | ID.RA-04 |
| RA-09 | Criticality Analysis | GV.OC-04GV.SC-04GV.SC-07ID.AM-05ID.RA-04 |
| RA-10 | Threat Hunting | DE.AE-06DE.AE-07ID.RA-03 |
SA System and Services Acquisition
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| SA-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| SA-02 | Allocation of Resources | GV.RR-03 |
| SA-03 | System Development Life Cycle | GV.SC-09ID.AM-08PR.PS-06 |
| SA-04 | Acquisition Process | DE.CM-06GV.OC-03GV.SC-02GV.SC-04GV.SC-05GV.SC-06GV.SC-07GV.SC-08GV.SC-09GV.SC-10ID.AM-08ID.IM-03ID.RA-09ID.RA-10 |
| SA-05 | System Documentation | ID.AM-02ID.RA-09 |
| SA-08 | Security and Privacy Engineering Principles | ID.AM-08ID.IM-01ID.IM-02ID.IM-03PR.DS-10PR.IR-03PR.PS-06 |
| SA-09 | External System Services | DE.CM-06GV.OC-05GV.SC-02GV.SC-04GV.SC-05GV.SC-06GV.SC-07GV.SC-08GV.SC-09GV.SC-10ID.AM-02ID.AM-04 |
| SA-10 | Developer Configuration Management | ID.RA-09PR.PS-06 |
| SA-11 | Developer Testing and Evaluation | ID.IM-01ID.IM-02ID.IM-03ID.RA-09PR.PS-06 |
| SA-15 | Development Process, Standards, and Tools | ID.RA-09PR.PS-06 |
| SA-17 | Developer Security and Privacy Architecture and Design | ID.RA-09PR.PS-06 |
| SA-22 | Unsupported System Components | ID.AM-08PR.PS-02PR.PS-03 |
| SA-24 | Design For Cyber Resiliency | GV.RM-03PR.IR-03PR.PS-06 |
SC System and Communications Protection
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| SC-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| SC-04 | Information in Shared System Resources | PR.DS-01PR.DS-02PR.DS-10PR.IR-01 |
| SC-05 | Denial-of-service Protection | DE.CM-01PR.IR-01PR.IR-03PR.IR-04 |
| SC-06 | Resource Availability | PR.IR-03 |
| SC-07 | Boundary Protection | DE.CM-01ID.AM-03PR.DS-01PR.DS-02PR.DS-10PR.IR-01RS.MI-01 |
| SC-08 | Transmission Confidentiality and Integrity | PR.DS-02 |
| SC-11 | Trusted Path | PR.DS-02PR.DS-10 |
| SC-12 | Cryptographic Key Establishment and Management | PR.DS-01PR.DS-02 |
| SC-13 | Cryptographic Protection | PR.DS-01PR.DS-02PR.DS-10 |
| SC-16 | Transmission of Security and Privacy Attributes | PR.DS-02 |
| SC-23 | Session Authenticity | PR.AA-04 |
| SC-24 | Fail in Known State | PR.DS-10PR.IR-03 |
| SC-28 | Protection of Information at Rest | PR.DS-01 |
| SC-32 | System Partitioning | PR.DS-01PR.DS-10PR.IR-01 |
| SC-34 | Non-modifiable Executable Programs | DE.CM-09PR.PS-05 |
| SC-35 | External Malicious Code Identification | DE.CM-09 |
| SC-36 | Distributed Processing and Storage | PR.IR-03 |
| SC-39 | Process Isolation | PR.DS-01PR.DS-10PR.IR-03 |
| SC-40 | Wireless Link Protection | PR.DS-02PR.DS-10 |
| SC-43 | Usage Restrictions | PR.DS-01PR.DS-02PR.DS-10 |
| SC-49 | Hardware-enforced Separation and Policy Enforcement | PR.PS-03 |
| SC-51 | Hardware-based Protection | PR.PS-03 |
SI System and Information Integrity
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| SI-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.SC-03ID.IM-01ID.IM-02ID.IM-03 |
| SI-02 | Flaw Remediation | ID.IM-01ID.IM-02ID.IM-03ID.RA-01ID.RA-08PR.PS-02 |
| SI-03 | Malicious Code Protection | PR.DS-01PR.DS-02PR.DS-10RS.MI-02 |
| SI-04 | System Monitoring | DE.AE-02DE.AE-03DE.AE-04DE.AE-06DE.CM-01DE.CM-03DE.CM-06DE.CM-09ID.IM-01ID.IM-02ID.IM-03ID.RA-01PR.DS-01PR.DS-02PR.DS-10RS.AN-03 |
| SI-05 | Security Alerts, Advisories, and Directives | DE.AE-07ID.RA-01ID.RA-02ID.RA-03ID.RA-08 |
| SI-07 | Software, Firmware, and Information Integrity | DE.CM-09ID.RA-09PR.DS-01PR.DS-02PR.DS-10PR.PS-02RC.RP-03RC.RP-05 |
| SI-10 | Information Input Validation | PR.DS-10 |
| SI-12 | Information Management and Retention | ID.AM-07ID.AM-08 |
| SI-13 | Predictable Failure Prevention | PR.IR-03 |
| SI-16 | Memory Protection | PR.DS-10 |
| SI-18 | Personally Identifiable Information Quality Operations | ID.AM-08 |
SR Supply Chain Risk Management
| Control | Name | NIST CSF 2.0 References |
|---|---|---|
| SR-01 | Policy and Procedures | GV.OC-03GV.OV-01GV.PO-01GV.PO-02GV.RM-05GV.SC-01GV.SC-02GV.SC-03GV.SC-05GV.SC-09GV.SC-10ID.IM-01ID.IM-02ID.IM-03 |
| SR-02 | Supply Chain Risk Management Plan | GV.RM-01GV.RM-03GV.RM-04GV.SC-01GV.SC-02GV.SC-03GV.SC-04GV.SC-05GV.SC-07GV.SC-08GV.SC-09GV.SC-10ID.AM-04ID.IM-04 |
| SR-03 | Supply Chain Controls and Processes | GV.OC-02GV.SC-01GV.SC-02GV.SC-03GV.SC-04GV.SC-05GV.SC-06GV.SC-07GV.SC-08GV.SC-09GV.SC-10ID.RA-10RS.CO-02RS.CO-03RS.MA-01 |
| SR-04 | Provenance | ID.RA-09 |
| SR-05 | Acquisition Strategies, Tools, and Methods | GV.OC-02GV.OC-05GV.SC-02GV.SC-05GV.SC-06GV.SC-09GV.SC-10ID.AM-08ID.IM-01ID.IM-02ID.IM-03ID.RA-09ID.RA-10 |
| SR-06 | Supplier Assessments and Reviews | DE.CM-06GV.OC-02GV.OV-01GV.OV-02GV.OV-03GV.SC-04GV.SC-05GV.SC-06GV.SC-07GV.SC-09GV.SC-10ID.AM-04ID.RA-09ID.RA-10 |
| SR-08 | Notification Agreements | GV.OC-02GV.SC-08RC.CO-03RS.CO-02RS.CO-03RS.MA-01 |
| SR-09 | Tamper Resistance and Detection | ID.RA-09 |
| SR-10 | Inspection of Systems or Components | GV.SC-05ID.RA-09 |
| SR-11 | Component Authenticity | ID.RA-09 |
| SR-12 | Component Disposal | GV.SC-10ID.AM-08 |