EvidenceSheet

NIST CSF 2.0: the evidence behind every control

106 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.

DE - Detect

DE.AE-02Potentially adverse events are analyzed to better understand associated activities hardDE.AE-03Information is correlated from multiple sources moderateDE.AE-04The estimated impact and scope of adverse events are understood hardDE.AE-06Information on adverse events is provided to authorized staff and tools hardDE.AE-07Cyber threat intelligence and other contextual information are integrated into the analysis hardDE.AE-08Incidents are declared when adverse events meet the defined incident criteria hardDE.CM-01Networks and network services are monitored to find potentially adverse events easyDE.CM-02The physical environment is monitored to find potentially adverse events moderateDE.CM-03Personnel activity and technology usage are monitored to find potentially adverse events moderateDE.CM-06External service provider activities and services are monitored to find potentially adverse events easyDE.CM-09Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events easy

GV - Govern

GV.OC-01The organizational mission is understood and informs cybersecurity risk management hardGV.OC-02Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered hardGV.OC-03Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed hardGV.OC-04Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated hardGV.OC-05Outcomes, capabilities, and services that the organization depends on are understood and communicated hardGV.PO-01Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced hardGV.PO-02Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission hardGV.RM-01Risk management objectives are established and agreed to by organizational stakeholders hardGV.RM-02Risk appetite and risk tolerance statements are established, communicated, and maintained hardGV.RM-03Cybersecurity risk management activities and outcomes are included in enterprise risk management processes hardGV.RM-04Strategic direction that describes appropriate risk response options is established and communicated hardGV.RM-05Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties hardGV.RM-06A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated hardGV.RM-07Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions hardGV.RR-01Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving hardGV.RR-02Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced hardGV.RR-03Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies hardGV.RR-04Cybersecurity is included in human resources practices hardGV.SC-01A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders hardGV.SC-02Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally hardGV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes hardGV.SC-04Suppliers are known and prioritized by criticality hardGV.SC-05Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties hardGV.SC-06Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships hardGV.SC-07The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship hardGV.SC-08Relevant suppliers and other third parties are included in incident planning, response, and recovery activities hardGV.SC-09Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle hardGV.SC-10Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement hard

Govern

GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction hardGV.OV-02The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks hardGV.OV-03Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed hard

ID - Identify

ID.AM-01Inventories of hardware managed by the organization are maintained hardID.AM-02Inventories of software, services, and systems managed by the organization are maintained hardID.AM-03Representations of the organization's authorized network communication and internal and external network data flows are maintained hardID.AM-04Inventories of services provided by suppliers are maintained hardID.AM-05Assets are prioritized based on classification, criticality, resources, and impact on the mission hardID.AM-07Inventories of data and corresponding metadata for designated data types are maintained hardID.AM-08Systems, hardware, software, services, and data are managed throughout their life cycles hardID.IM-01Improvements are identified from evaluations hardID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties hardID.IM-03Improvements are identified from execution of operational processes, procedures, and activities hardID.IM-04Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved hardID.RA-01Vulnerabilities in assets are identified, validated, and recorded hardID.RA-02Cyber threat intelligence is received from information sharing forums and sources hardID.RA-03Internal and external threats to the organization are identified and recorded hardID.RA-04Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded hardID.RA-05Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization hardID.RA-06Risk responses are chosen, prioritized, planned, tracked, and communicated hardID.RA-07Changes and exceptions are managed, assessed for risk impact, recorded, and tracked hardID.RA-08Processes for receiving, analyzing, and responding to vulnerability disclosures are established hardID.RA-09The authenticity and integrity of hardware and software are assessed prior to acquisition and use hardID.RA-10Critical suppliers are assessed prior to acquisition hard

PR - Protect

PR.AA-01Identities and credentials for authorized users, services, and hardware are managed by the organization moderatePR.AA-02Identities are proofed and bound to credentials based on the context of interactions hardPR.AA-03Users, services, and hardware are authenticated hardPR.AA-04Identity assertions are protected, conveyed, and verified hardPR.AA-05Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties hardPR.AA-06Physical access to assets is managed, monitored, and enforced commensurate with risk hardPR.AT-01Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind hardPR.AT-02Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind hardPR.DS-01The confidentiality, integrity, and availability of data-at-rest are protected hardPR.DS-02The confidentiality, integrity, and availability of data-in-transit are protected hardPR.DS-10The confidentiality, integrity, and availability of data-in-use are protected hardPR.DS-11Backups of data are created, protected, maintained, and tested moderatePR.IR-01Networks and environments are protected from unauthorized logical access and usage hardPR.IR-02The organization's technology assets are protected from environmental threats hardPR.IR-03Mechanisms are implemented to achieve resilience requirements in normal and adverse situations hardPR.IR-04Adequate resource capacity to ensure availability is maintained moderatePR.PS-01Configuration management practices are established and applied moderatePR.PS-02Software is maintained, replaced, and removed commensurate with risk hardPR.PS-03Hardware is maintained, replaced, and removed commensurate with risk hardPR.PS-04Log records are generated and made available for continuous monitoring easyPR.PS-05Installation and execution of unauthorized software are prevented hardPR.PS-06Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle hard

RC - Recover

RC.CO-03Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders hardRC.CO-04Public updates on incident recovery are shared using approved methods and messaging hardRC.RP-01The recovery portion of the incident response plan is executed once initiated from the incident response process hardRC.RP-02Recovery actions are selected, scoped, prioritized, and performed hardRC.RP-03The integrity of backups and other restoration assets is verified before using them for restoration hardRC.RP-04Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms moderateRC.RP-05The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed hardRC.RP-06The end of incident recovery is declared based on criteria, and incident-related documentation is completed hard

RS - Respond

RS.AN-03Analysis is performed to establish what has taken place during an incident and the root cause of the incident hardRS.AN-06Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved easyRS.AN-07Incident data and metadata are collected, and their integrity and provenance are preserved hardRS.AN-08An incident's magnitude is estimated and validated hardRS.CO-02Internal and external stakeholders are notified of incidents hardRS.CO-03Information is shared with designated internal and external stakeholders hardRS.MA-01The incident response plan is executed in coordination with relevant third parties once an incident is declared hardRS.MA-02Incident reports are triaged and validated hardRS.MA-03Incidents are categorized and prioritized moderateRS.MA-04Incidents are escalated or elevated as needed hardRS.MA-05The criteria for initiating incident recovery are applied hardRS.MI-01Incidents are contained hardRS.MI-02Incidents are eradicated hard