Cyber Insurance Subjectivity Tracker

Rules

Core list: United States

NIST Cybersecurity Framework 2.0

Part of the core list for the United States. A voluntary framework of outcomes, cited at subcategory level.

edition NIST Cybersecurity Framework 2.0 (CSWP 29). 12 requirements cited here. Every NIST CSF 2.0 clause we hold.

Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
PR.AA-03
NIST CSF 2.0

Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review

Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
PR.AA-03
NIST CSF 2.0

Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review

Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
PR.AA-03
NIST CSF 2.0

Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review

Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time

ClauseThe held text, and the evidence an assessor asks for
PR.DS-11
NIST CSF 2.0

Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs

Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them

ClauseThe held text, and the evidence an assessor asks for
PR.DS-11
NIST CSF 2.0

Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs

Restoring from backup is tested as part of a disaster recovery exercise

ClauseThe held text, and the evidence an assessor asks for
PR.DS-11
NIST CSF 2.0

Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs

Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement

ClauseThe held text, and the evidence an assessor asks for
ID.RA-01
NIST CSF 2.0

Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

evidence an assessor asks for Vulnerability scanning coverage report; Vulnerability triage workflow with severity SLAs; Validated findings with proof and remediation status; Asset coverage exceptions register; Trend analysis on vulnerability backlog

PR.PS-02
NIST CSF 2.0

Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records

Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement

ClauseThe held text, and the evidence an assessor asks for
PR.PS-02
NIST CSF 2.0

Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records

Other business applications are patched within the timeframe in the requirement

ClauseThe held text, and the evidence an assessor asks for
PR.PS-02
NIST CSF 2.0

Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records

Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements

ClauseThe held text, and the evidence an assessor asks for
ID.RA-01
NIST CSF 2.0

Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

evidence an assessor asks for Vulnerability scanning coverage report; Vulnerability triage workflow with severity SLAs; Validated findings with proof and remediation status; Asset coverage exceptions register; Trend analysis on vulnerability backlog

Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed

ClauseThe held text, and the evidence an assessor asks for
PR.PS-02
NIST CSF 2.0

Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records

Administrators use a separate privileged account and environment for admin work only, with no internet or email on it

ClauseThe held text, and the evidence an assessor asks for
PR.AA-05
NIST CSF 2.0

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

evidence an assessor asks for Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records

Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked

ClauseThe held text, and the evidence an assessor asks for
PR.AA-05
NIST CSF 2.0

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

evidence an assessor asks for Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records

Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated

ClauseThe held text, and the evidence an assessor asks for
PR.AA-05
NIST CSF 2.0

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

evidence an assessor asks for Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records

Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed

ClauseThe held text, and the evidence an assessor asks for
PR.AA-01
NIST CSF 2.0

Identities and credentials for authorized users, services, and hardware are managed by the organization

evidence an assessor asks for Identity management platform configuration baseline; Joiner mover leaver workflow with timing SLAs; Service account inventory with owners; Hardware credential inventory and reconciliation; Quarterly identity hygiene reports

Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders

ClauseThe held text, and the evidence an assessor asks for
PR.PS-01
NIST CSF 2.0

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation

Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review

ClauseThe held text, and the evidence an assessor asks for
PR.PS-01
NIST CSF 2.0

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation

Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed

ClauseThe held text, and the evidence an assessor asks for
PR.PS-01
NIST CSF 2.0

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation

Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted

ClauseThe held text, and the evidence an assessor asks for
PR.PS-01
NIST CSF 2.0

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation

Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner

ClauseThe held text, and the evidence an assessor asks for
DE.CM-09
NIST CSF 2.0

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

evidence an assessor asks for EDR coverage report by asset class; File integrity monitoring baseline and drift alerts; Software inventory reconciliation with allowlist; Hardware tamper detection telemetry; Patch and configuration drift dashboard

There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names

ClauseThe held text, and the evidence an assessor asks for
RS.MA-01
NIST CSF 2.0

The incident response plan is executed in coordination with relevant third parties once an incident is declared

evidence an assessor asks for Incident response plan with third party invocation; Retainer contract evidence for IR vendor; Joint exercise records with the IR vendor; Coordination procedure with law enforcement; Vendor activation log during real incidents

Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)

ClauseThe held text, and the evidence an assessor asks for
DE.CM-09
NIST CSF 2.0

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

evidence an assessor asks for EDR coverage report by asset class; File integrity monitoring baseline and drift alerts; Software inventory reconciliation with allowlist; Hardware tamper detection telemetry; Patch and configuration drift dashboard

Inbound email is scanned for malware and phishing with unneeded attachment types blocked, and the domain publishes DMARC

ClauseThe held text, and the evidence an assessor asks for
DE.CM-09
NIST CSF 2.0

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

evidence an assessor asks for EDR coverage report by asset class; File integrity monitoring baseline and drift alerts; Software inventory reconciliation with allowlist; Hardware tamper detection telemetry; Patch and configuration drift dashboard

Staff are trained to recognise phishing and other social engineering, and to report a suspected incident

ClauseThe held text, and the evidence an assessor asks for
PR.AT-01
NIST CSF 2.0

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

evidence an assessor asks for Security awareness program curriculum; Completion records by population; Phishing simulation results and trends; Awareness campaign artefacts (posters, emails); Annual program effectiveness review

Laptops, phones and removable media that hold sensitive data are encrypted

ClauseThe held text, and the evidence an assessor asks for
PR.DS-01
NIST CSF 2.0

The confidentiality, integrity, and availability of data-at-rest are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Data at rest encryption inventory by store type; Key management standards and rotation evidence; Storage configuration baselines with attestation; Sensitive data discovery findings remediated; Audit findings on data at rest protection

IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements

ClauseThe held text, and the evidence an assessor asks for
GV.SC-05
NIST CSF 2.0

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

evidence an assessor asks for Standard supplier security requirements catalog; Contract clause library with cyber obligations; Requirements tailoring guide by supplier tier; Negotiation log capturing accepted deviations; Contract management workflow with security review gate

Questions

When does NIST CSF 2.0 apply here?
Part of the core list for the United States. A voluntary framework of outcomes, cited at subcategory level.
Which edition is held?
NIST Cybersecurity Framework 2.0 (CSWP 29)
Is a gap against it a finding about the business?
No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.