ActiveOfficial documentationPrimary sourceSource ID nist-csf-2-0

The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29)

Published by National Institute of Standards and Technology, U.S. Department of Commerce. Jurisdiction US.

Open the original record

Exactly what this source supports

These are the only claims this record is used to carry anywhere in the library.

  • The current edition is CSF 2.0, published February 26, 2024, available free of charge at https://doi.org/10.6028/NIST.CSWP.29.

    claim nist-csf-2-0#c1
  • CSF 2.0 organizes outcomes under six Functions: GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), RESPOND (RS), RECOVER (RC).

    claim nist-csf-2-0#c2
  • PR.AA-03: Users, services, and hardware are authenticated.

    claim nist-csf-2-0#c3
  • PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.

    claim nist-csf-2-0#c4
  • PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.

    claim nist-csf-2-0#c5
  • PR.DS-11: Backups of data are created, protected, maintained, and tested.

    claim nist-csf-2-0#c6
  • PR.PS-02: Software is maintained, replaced, and removed commensurate with risk.

    claim nist-csf-2-0#c7
  • DE.CM-01: Networks and network services are monitored to find potentially adverse events.

    claim nist-csf-2-0#c8
  • RS.MA-01: The incident response plan is executed in coordination with relevant third parties once an incident is declared.

    claim nist-csf-2-0#c9
  • RC.RP-03: The integrity of backups and other restoration assets is verified before using them for restoration.

    claim nist-csf-2-0#c10
  • GV.PO-01: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities, and is communicated and enforced.

    claim nist-csf-2-0#c11
  • ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties.

    claim nist-csf-2-0#c12
  • The CSF does not prescribe how outcomes should be achieved; it offers a taxonomy of high-level cybersecurity outcomes usable by any organization regardless of size, sector, or maturity.

    claim nist-csf-2-0#c13
  • PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected. PR.DS-02: The confidentiality, integrity, and availability of data-in-transit are protected.

    claim nist-csf-2-0#c14
  • Cybersecurity Supply Chain Risk Management (GV.SC) is a category within the GOVERN function, covering cyber supply chain risk management processes identified, established, managed, monitored, and improved by organizational stakeholders.

    claim nist-csf-2-0#c15

Each claim above has its own address. Link to a single claim with/sources/nist-csf-2-0#c1, and read the same list with its identifiers, checksums and dates at nist-csf-2-0.json. A checksum lets you tell whether a claim you cited still says what it said.

Pages that cite this source

Report an error on this pageCorrections are checked against the original record. Material changes are logged on the corrections page.