NIST Cybersecurity Framework 2.0
Part of the core list for the United States. A voluntary framework of outcomes, cited at subcategory level.
edition NIST Cybersecurity Framework 2.0 (CSWP 29). 12 requirements cited here. Every NIST CSF 2.0 clause we hold.
Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.AA-03 NIST CSF 2.0 | Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review |
Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.AA-03 NIST CSF 2.0 | Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review |
Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.AA-03 NIST CSF 2.0 | Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review |
Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.DS-11 NIST CSF 2.0 | Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs |
Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.DS-11 NIST CSF 2.0 | Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs |
Restoring from backup is tested as part of a disaster recovery exercise
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.DS-11 NIST CSF 2.0 | Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs |
Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ID.RA-01 NIST CSF 2.0 | Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify. evidence an assessor asks for Vulnerability scanning coverage report; Vulnerability triage workflow with severity SLAs; Validated findings with proof and remediation status; Asset coverage exceptions register; Trend analysis on vulnerability backlog |
| PR.PS-02 NIST CSF 2.0 | Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records |
Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.PS-02 NIST CSF 2.0 | Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records |
Other business applications are patched within the timeframe in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.PS-02 NIST CSF 2.0 | Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records |
Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ID.RA-01 NIST CSF 2.0 | Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify. evidence an assessor asks for Vulnerability scanning coverage report; Vulnerability triage workflow with severity SLAs; Validated findings with proof and remediation status; Asset coverage exceptions register; Trend analysis on vulnerability backlog |
Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.PS-02 NIST CSF 2.0 | Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records |
Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.AA-05 NIST CSF 2.0 | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties evidence an assessor asks for Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records |
Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.AA-05 NIST CSF 2.0 | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties evidence an assessor asks for Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records |
Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.AA-05 NIST CSF 2.0 | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties evidence an assessor asks for Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records |
Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.AA-01 NIST CSF 2.0 | Identities and credentials for authorized users, services, and hardware are managed by the organization evidence an assessor asks for Identity management platform configuration baseline; Joiner mover leaver workflow with timing SLAs; Service account inventory with owners; Hardware credential inventory and reconciliation; Quarterly identity hygiene reports |
Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.PS-01 NIST CSF 2.0 | Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation |
Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.PS-01 NIST CSF 2.0 | Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation |
Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.PS-01 NIST CSF 2.0 | Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation |
Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.PS-01 NIST CSF 2.0 | Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation |
Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| DE.CM-09 NIST CSF 2.0 | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events evidence an assessor asks for EDR coverage report by asset class; File integrity monitoring baseline and drift alerts; Software inventory reconciliation with allowlist; Hardware tamper detection telemetry; Patch and configuration drift dashboard |
There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| RS.MA-01 NIST CSF 2.0 | The incident response plan is executed in coordination with relevant third parties once an incident is declared evidence an assessor asks for Incident response plan with third party invocation; Retainer contract evidence for IR vendor; Joint exercise records with the IR vendor; Coordination procedure with law enforcement; Vendor activation log during real incidents |
Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| DE.CM-09 NIST CSF 2.0 | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events evidence an assessor asks for EDR coverage report by asset class; File integrity monitoring baseline and drift alerts; Software inventory reconciliation with allowlist; Hardware tamper detection telemetry; Patch and configuration drift dashboard |
Inbound email is scanned for malware and phishing with unneeded attachment types blocked, and the domain publishes DMARC
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| DE.CM-09 NIST CSF 2.0 | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events evidence an assessor asks for EDR coverage report by asset class; File integrity monitoring baseline and drift alerts; Software inventory reconciliation with allowlist; Hardware tamper detection telemetry; Patch and configuration drift dashboard |
Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.AT-01 NIST CSF 2.0 | Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind evidence an assessor asks for Security awareness program curriculum; Completion records by population; Phishing simulation results and trends; Awareness campaign artefacts (posters, emails); Annual program effectiveness review |
Laptops, phones and removable media that hold sensitive data are encrypted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PR.DS-01 NIST CSF 2.0 | The confidentiality, integrity, and availability of data-at-rest are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Data at rest encryption inventory by store type; Key management standards and rotation evidence; Storage configuration baselines with attestation; Sensitive data discovery findings remediated; Audit findings on data at rest protection |
IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| GV.SC-05 NIST CSF 2.0 | Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties evidence an assessor asks for Standard supplier security requirements catalog; Contract clause library with cyber obligations; Requirements tailoring guide by supplier tier; Negotiation log capturing accepted deviations; Contract management workflow with security review gate |
Questions
- When does NIST CSF 2.0 apply here?
- Part of the core list for the United States. A voluntary framework of outcomes, cited at subcategory level.
- Which edition is held?
- NIST Cybersecurity Framework 2.0 (CSWP 29)
- Is a gap against it a finding about the business?
- No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.